Re: This dude needs to be banned
Reply #11 - December 23, 2010, 10:46 PM
Seems like an SQL injection, to get access to the database, from mysql etc and maybe even to the server (though doubtful) basically, if he did mange he would have had some access to the forum, and possible the admin control panel. Although trying an exploit without actually have full-control of the server is something only a script kiddie would do.
Although in many cases if you are smart enough you can just, get into the mysql database get the admin password get admin email from view profile, and decode the password hash and hope the admin is dumb enough to use the same password on his email account, log into his email account find out the password for the virtual server, and log into the server account. Then you pretty much own, since you have r00t.