PDA

View Full Version : A shell



GoldenMerc
18-09-2008, 02:39 PM
Whats all this talk of 'Shell's' like Qamp saying he put a Shell on Habbox, & Shell's on Habbos what are they?
+Rep for help
Ross

Agnostic Bear
18-09-2008, 03:51 PM
It's a way to remotely control a PC basically.

GoldenMerc
18-09-2008, 06:12 PM
So by people uploading shell's to websites they can control loads of people?
& they dont have to accept ot anything?

Hitman
18-09-2008, 06:17 PM
So by people uploading shell's to websites they can control loads of people?
& they dont have to accept ot anything?

Lol Ross, I think that's impossible. I don't know much about shells but I guess they can control the server where the site is hosted on, not the people visiting.

Decode
18-09-2008, 06:26 PM
Has anyone got Qamps msn?

GoldenMerc
18-09-2008, 06:31 PM
I do lol.

Dentafrice
19-09-2008, 12:02 AM
It basically uses PHP as a "connection-point" to the server.

It really depends on the settings, and the permissions alloted to the user running PHP, usually behind Apache.

Sometimes you can accomplish quite alot, and sometimes not much.

Most of the time you can at least view /etc/passwd, and if opendir is enabled, modify files outside of the /home/bla/ directory.

Most allow you to edit/delete/upload files, connect to a MySQL server with it's own "built-in phpMyAdmin", and a few other features such as chmod.

HotelUser
19-09-2008, 12:13 AM
It basically uses PHP as a "connection-point" to the server.

It really depends on the settings, and the permissions alloted to the user running PHP, usually behind Apache.

Sometimes you can accomplish quite alot, and sometimes not much.

Most of the time you can at least view /etc/passwd, and if opendir is enabled, modify files outside of the /home/bla/ directory.

Most allow you to edit/delete/upload files, connect to a MySQL server with it's own "built-in phpMyAdmin", and a few other features such as chmod.

but if in PHPMYADMIN auth is set to httpd then they can't gain access to the SQL server, right?

Dentafrice
19-09-2008, 12:18 AM
but if in PHPMYADMIN auth is set to httpd then they can't gain access to the SQL server, right?
Incorrect, it doesn't matter about phpMyAdmin's settings, as it is a seperate program to MySQL.

MySQL is the server, phpMyAdmin is just a program/utility to connect to it.

Just like FTP is the server, and FireFTP/CuteFTP/SmartFTP is the program to connect to it, it still uses your MySQL/FTP details (in each situation).

phpMyAdmin can be set to whatever setting you want, but yet.. it's the MySQL server that the built-in one is connecting to.

J0SH
19-09-2008, 03:46 AM
Lol, I imagine this 'shell' would of been put under a downloads page or something, or he's chatting utter ****. :P

Dentafrice
19-09-2008, 11:15 AM
Lol, I imagine this 'shell' would of been put under a downloads page or something, or he's chatting utter ****. :P
Mis-configured/unsafe upload scripts are a main cause of them being on the server.

Want to hide these adverts? Register an account for free!