Author Topic: HLP Technical Information  (Read 362 times)

0 Members and 1 Guest are viewing this topic.

Offline an0n

  • Banned again
  • 211
  • Emo Hunter
    • http://nodewar.penguinbomb.com/forum
HLP Technical Information
Got any?

PHP version, MySQL version, bandwidth usage, space usage?

There used to be a phpinfo file some fool left on from the forum installation, but that's apparently been removed.
"I.....don't.....CARE!!!!!" ---- an0n
"an0n's right. He's crazy, an asshole, not to be trusted, rarely to be taken seriously, and never to be allowed near your mother. But, he's got a knack for being right. In the worst possible way he can find." ---- Yuppygoat
~-=~!@!~=-~ : Nodewar.com

 

Offline Styxx

  • 211
    • Hard Light Productions
Ha ha.
Probably away. Contact through email.

 

Offline an0n

  • Banned again
  • 211
  • Emo Hunter
    • http://nodewar.penguinbomb.com/forum
Yes, yes - it's all fun and games till I have to poke out somebody's eye.

It's not like I can't find out. It's just a pain in the ass for me to do so and thus infintely more likely to make me Hulk-angry.
"I.....don't.....CARE!!!!!" ---- an0n
"an0n's right. He's crazy, an asshole, not to be trusted, rarely to be taken seriously, and never to be allowed near your mother. But, he's got a knack for being right. In the worst possible way he can find." ---- Yuppygoat
~-=~!@!~=-~ : Nodewar.com

 

Offline Fury

  • The Curmudgeon
  • 213
At least this time we know who's behind next downtime...

 

Offline an0n

  • Banned again
  • 211
  • Emo Hunter
    • http://nodewar.penguinbomb.com/forum
Thanks to a small bug in ProFTPd 1.2.10 (upon which GS operates) it's possible to determine valid and invalid usernames.

Now, the fix that's out is described as a "band aid" and, being professionals, I doubt the GS admins would be inclined to slap a half-assed patch onto the server.

So, knowing valid usernames, it may be possible to simply brute-force into the FTP using a dictionary list of popular gamer words and phrases and a sequential number inserter.

And given the general ignorance of site-admins like Virtu, it wouldn't take long to get a bite and onto the server even using a relatively slow attempt frequency across the various valid usernames (IE, without sending up red flags).

From there it's just a case of uploading the server info php file that comes with vBulletin and going to the URL with a browser.


This is all based on a glance at the bug info, mind.
« Last Edit: November 05, 2004, 10:04:12 am by 397 »
"I.....don't.....CARE!!!!!" ---- an0n
"an0n's right. He's crazy, an asshole, not to be trusted, rarely to be taken seriously, and never to be allowed near your mother. But, he's got a knack for being right. In the worst possible way he can find." ---- Yuppygoat
~-=~!@!~=-~ : Nodewar.com