Runescape Phisher Exploit?

Rakeya

Onyx user!
Reputation
0
I think I may know of a phisher vulnerability if the index page is a .php file. If anyone knows of a phisher with that, pm me, i want to test my exploit. It could possibly get the database file, i dont think anyone else knows of this, just discovered it on my own testing website vulnerabilities.
 
Could you explain? Like you might be able to get RuneScape's DB via an exploit you found in the PHP of the new site layout?

Or of phishing websites that have php files for index's? To get their database?
 
the index page that have the php file, i think i know how to get the database for it, meant for like basic phishers, but i want to test if this will work, I'm not sure or not. Anyone have a basic phisher url with index.php?
 
eXero said:
Could you explain? Like you might be able to get RuneScape's DB via an exploit you found in the PHP of the new site layout?

Or of phishing websites that have php files for index's? To get their database?

If he could do it on the runescape page,why he need you for?
no flaming,just saying

OP: If i find 1,ill pm u
 
Pichu said:
If he could do it on the runescape page,why he need you for?
no flaming,just saying

OP: If i find 1,ill pm u
ye, runescape's database is encrypted and doesn't use a simple txt file like phishers use to display character data.
 
I dont see what your getting at, a basic phisher that writes to a file only uses fopen().

If the file where your logins are displayed is named .php then theres a security risk, better to just have your phishes inserted into a database and use mysql_real_escape & add_slashes to escape all dangerous post input.
 
it's not any post input or xss vulnerabilities. it's a very simple way to view php script, many basic phishers have the redirect link in php, if anyone sends me that redirect link i can exploit it to get the character files. What i plan to do is freeze the redirect file and view the source code of it.
 
Opera > disable redirs.

This was an exploit on an old version of iPhish, which is patched now.
 
i don't mean that one lol, its a different one, most likely undiscovered
 
If anyone wants to test if their phisher is vulnerable to this, or if anyone knows of a phisher url you want files to, pm me, I need to know if this method works or not. If so, I may be able to get any phisher's password files.
 
Your in a forum of hackers and phishers and you want us to aid you in whailing our logs. No thanks....
 
^ you obviously didn't take the time to read. Not even going to explain myself to you.
 
i read every post on this page unless their is a misunderstanding your goal is to whale phisher logs. Since this is a runescape hacking forum and alot of people here phish i would consider this pretty straight forward...
 
Back
Top