You are viewing a single comment's thread.

view the rest of the comments →

16337615? ago

I'm not l337 enough to hack this :(

16350044? ago

The security of that website is laughable. Each file can be easily downloaded:

http://www.teris.ch/download.asp?ogg=&name={filename}

Where {filename} is relative to e:/virtual/www.teris.ch/db/files/

If you want to take a look at page.asp, you just request:

http://www.teris.ch/download.asp?ogg=&name=../../www/page.asp

I haven't been able to find any exploits to enter the admin backend. I can only confirm that the username is definitely admin.

16369267? ago

The SHA-1 password hash of the admin user is 898075c8c74a43dc57280f20f0a7ed9cdb3c35a5. The online databases do not have a match on this one. Throwing it in here if someone wants to brute-force it.

>>12715533

Certainly worth to check out.

16427093? ago

Found another user, and again no matches for the hash:

terissa 525b56d712565c15771b14a4f1dff445fd95718a

Also:

Theresa

From the Spanish and Portuguese name Teresa. It was first recorded as Therasia, being borne by the Spanish wife of Saint Paulinus of Nola in the 4th century. The meaning is uncertain, but it could be derived from Greek θερος (theros) "summer", from Greek θεριζω (therizo) "to harvest", or from the name of the Greek island of Therasia (the western island of Santorini).

from Greek θεριζω (therizo) "to harvest"

to harvest

>>12722825

The database can't be downloaded (or downloads empty) for some reason. Probably has something to do with server permissions. Try it yourself:

http://www.teris.ch/download.asp?ogg=&name=../dsm_teris.mdb