Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 40 guests online
You are here:
Home
Resources
Tutorials
How to hack through port 80
EH-Net
May 19, 2013, 03:16:43 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Tutorials
(Moderator:
don
) >
How to hack through port 80
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: How to hack through port 80 (Read 63397 times)
0 Members and 1 Guest are viewing this topic.
Thangvt
Newbie
Offline
Posts: 13
How to hack through port 80
«
on:
June 05, 2008, 09:17:30 AM »
Hi all,
Script is
- from outside hack inside network through port 80.
Outside ----> FW( CheckPoint or ISA ) -------> Server (Web Server or Mail Server)
Any body here can help me this case?. If you have study guide or relate info please message to me.
Thanks!
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: How to hack through port 80
«
Reply #1 on:
June 05, 2008, 09:30:36 AM »
format C: /Q /X
on Windows
rm -rf /
on linux
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: How to hack through port 80
«
Reply #2 on:
June 05, 2008, 09:46:16 AM »
BillV?...... tut tut
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
oneeyedcarmen
Full Member
Offline
Posts: 233
Klaatu, Borada,Necktie?
Re: How to hack through port 80
«
Reply #3 on:
June 05, 2008, 09:58:38 AM »
Logged
Reluctant CISSP, Certified ASS
BillV
Hero Member
Offline
Posts: 1892
Re: How to hack through port 80
«
Reply #4 on:
June 05, 2008, 10:08:36 AM »
Quote from: RoleReversal on June 05, 2008, 09:46:16 AM
BillV?...... tut tut
As the saying goes... "Ask a stupid question....."
Logged
Thangvt
Newbie
Offline
Posts: 13
Re: How to hack through port 80
«
Reply #5 on:
June 05, 2008, 10:37:13 AM »
Quote from: BillV on June 05, 2008, 10:08:36 AM
Quote from: RoleReversal on June 05, 2008, 09:46:16 AM
BillV?...... tut tut
As the saying goes... "Ask a stupid question....."
What's for stupid? U ar crazy??
It's real for a company. They already have FW and preparing buy IPS appliance. If you don't have comments, don't reply !
Logged
oneeyedcarmen
Full Member
Offline
Posts: 233
Klaatu, Borada,Necktie?
Re: How to hack through port 80
«
Reply #6 on:
June 05, 2008, 10:54:40 AM »
Quote from: Thangvt
It's real for a company. They already have FW and preparing buy IPS appliance. If you don't have comments, don't reply !
Could you describe for us what the scope of your test is, and the ROE you've set up with the target company?
And please be more specific with your question. The original is incredibly generic.
Thanks.
Logged
Reluctant CISSP, Certified ASS
BillV
Hero Member
Offline
Posts: 1892
Re: How to hack through port 80
«
Reply #7 on:
June 05, 2008, 10:55:25 AM »
Quote from: Thangvt on June 05, 2008, 10:37:13 AM
What's for stupid? U ar crazy??
It's real for a company. They already have FW and preparing buy IPS appliance.
If you don't have comments, don't reply !
Oh believe me, I have comments... I just hold back most of them
"It's real for a company" .... what does this mean?
If you have a
real
question, than feel free to elaborate and you might get a more thoughtful response.
Logged
Dengar13
Sr. Member
Offline
Posts: 380
Re: How to hack through port 80
«
Reply #8 on:
June 05, 2008, 11:33:03 AM »
Whew...it is getting hot in this thread...lol!
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
g00d_4sh
Sr. Member
Offline
Posts: 394
Re: How to hack through port 80
«
Reply #9 on:
June 05, 2008, 01:47:47 PM »
Heh... Bill, you just made my day. I haven't seen a format C: comment in too long... Even with switches, good man.
Logged
"Bad.. Good? I'm the guy with the gun"
BillV
Hero Member
Offline
Posts: 1892
Re: How to hack through port 80
«
Reply #10 on:
June 05, 2008, 03:14:28 PM »
Quote from: Thangvt
What's for stupid? U ar crazy?? If you don't have comments, don't reply !
Quote from: g00d_4sh on June 05, 2008, 01:47:47 PM
Heh... Bill, you just made my day. I haven't seen a format C: comment in too long... Even with switches, good man.
Irritating to some, joyful to others
That's my personal motto for the day
Logged
oneeyedcarmen
Full Member
Offline
Posts: 233
Klaatu, Borada,Necktie?
Re: How to hack through port 80
«
Reply #11 on:
June 05, 2008, 03:21:54 PM »
Quote from: BillV
Irritating to some, joyful to others
I think you've just put into words how I've lived these last 30 years!
Logged
Reluctant CISSP, Certified ASS
g00d_4sh
Sr. Member
Offline
Posts: 394
Re: How to hack through port 80
«
Reply #12 on:
June 05, 2008, 03:45:43 PM »
Hahaha... life is too short not to flip a little shit around. And giving advice like that helps to instruct people in the fine art of RTFM... and double checking advice you see online.
Logged
"Bad.. Good? I'm the guy with the gun"
phn1x
Newbie
Offline
Posts: 26
Re: How to hack through port 80
«
Reply #13 on:
June 05, 2008, 05:20:40 PM »
Aside from the overwhelmingly insightful advice everyone gave previous to this comment, Ethics, legality, ROE and "Do you have permission" bs replies aside. Let me start by stating your vague question draws no mercy from everyone fievershly fighting for the chance to up their post/reply count.
In theory the target is a web server that you are attacking with a firewall placed between the cloud and it. Your objective should first be to obtain as much information as possible about what is running on port 80. You will want to perform banner grabs, fingerprinting the Web Server and seeing what else it supports. These day's apache is the majority, and it's pretty solid. However, if your lucky enough to find extension/plugins there may be hope yet. After you figure out the server you want to start looking at the actual webpage/web application. If it's a webpage what is the content? Ideally though you hope for a web application of some sorts that you can then determine the logic and start attacking it from there. From your question I can only guess you are knew at penetration testing and web assessments. Ergo, I recommend you read the following libro's:
http://www.amazon.com/Professional-Pen-Testing-Applications-Programmer/dp/0471789666/ref=sr_1_1?ie=UTF8&s=books&qid=1212704329&sr=8-1
http://www.amazon.com/Web-Application-Hackers-Handbook-Discovering/dp/0470170778/ref=sr_1_1?ie=UTF8&s=books&qid=1212704355&sr=8-1
You can also look into the Hacking Exposed Version 1 and 2 for web applications. Although I stray away from them they are decent introductory material and usually outline an excellent flow chart in which you can base your methodology.
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: How to hack through port 80
«
Reply #14 on:
June 05, 2008, 07:23:21 PM »
Quote from: phn1x on June 05, 2008, 05:20:40 PM
Aside from the overwhelmingly insightful advice everyone gave previous to this comment, Ethics, legality, ROE and "Do you have permission" bs replies aside. Let me start by stating your vague question draws no mercy from everyone fievershly fighting for the chance to up their post/reply count.
Yes, and in addition to that we're able to pick up on sarcasm too. Shocker!
I had this typed up once but my session timed out (damn SMF) so I'll keep it short and simple this time.
The bottom line is:
if you want a real answer, ask a real question.
There is a difference between "asking a question" and "asking a question properly." For the former, most communities will flame you to death and shun you from ever returning.
If you're going to pose a question to a community focused on being professional, there are much better ways to make an introduction or post your question that will yield far greater results:
Link 1
Link 2
Link 3
Quite simply, I find comments like "how do I hack through port 80" and "it's real for a company," in a word, stupid. Despite your disregard for ethics as stated in your post, that's what this community is focused on. You'll get a much better response for posting a question that makes you look more serious about what you're doing. Otherwise, it just begs the return question of "what the hell are you doing?"
Don't mess with someone's website/network if that's not what you should be doing. No one here is going to encourage that. I believe it was asked plenty enough for the poster to elaborate on his question. At this point however, I'm not sure who would be willing to respond.
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(6) by
Grendel
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.