This forum is in archive mode. You will not be able to post new content.

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - nmabhinandan

Pages: [1]
1
Hacking and Security / How do i get into this one?
« on: November 30, 2013, 04:00:24 PM »
Okay guys first thing first.. i'm a noob and i'm not a hacker. My college ERP software is made up of JSP and runs on apache tomcat server. The admin login page form has not validated. So I successfully bypassed it by using XPATH injection (sql injection for xml databases). Wait theres more.. the servers ssh port is open!!  ;D 


If I can do the  xpath injectoin i.e.
[size=78%] [/size]
Code: [Select]
user: admin' and 1=1 or ''='
pass: somestring



it means I can run this one too.. 
Code: [Select]
user: admin' and Runtime.getRuntime().exec("useradd hawkeye; passwd hawkeye password") or 1=1 or ''='
pass: somestring



My plan is to add a new user and connecting the server through ssh.. and the problem is it is not working..  :-\


Thanks in advance




Pages: [1]


Want to be here? Contact Ande, Factionwars or Kulverstukas on the forum or at IRC.