Jump to content

Backdoor Entry? Direct to booking form?


Guest newagehippie
 Share

Recommended Posts

  • Replies 198
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

I already had my tickets before I saw this, but I can confirm that the IP address Neil gave is a valid see tcikets address...


$ dig glastonbury.seetickets.com

; <<>> DiG 9.9.1-P3 <<>> glastonbury.seetickets.com

;; global options: +cmd

;; Got answer:

;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47543

;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:

; EDNS: version: 0, flags:; udp: 4000

;; QUESTION SECTION:

;glastonbury.seetickets.com.    IN      A

;; ANSWER SECTION:

glastonbury.seetickets.com. 47  IN      A       194.168.202.202

glastonbury.seetickets.com. 47  IN      A       194.168.202.201

;; Query time: 16 msec

;; SERVER: 194.168.4.100#53(194.168.4.100)

;; WHEN: Sun Oct  7 10:11:59 2012

;; MSG SIZE  rcvd: 87

You can see in the ANSWER section there are two IP addresses that glastonbury.seetickets.com can resolve to. The first one is 194.168.202.202, which is the one that most people will end up using as it is the first one returned by the DNS lookup. Hacking your hostfile to use 194.168.202.201 instead means you end up using the quieter server as most people will end up on the first one.

Edited by windy_miller
Link to comment
Share on other sites

Neil, I flippin' love you.

I managed to get tickets for my group using this but it no longer seems to be working so I don't think people trying it now will be so lucky.

That guy that mentioned the reverse IP lookup was correct thou. I wanted to check it wasn't a scam before I entered all my details onto somebody's dodgy server and it did seem to be owned by a junior school in manchester on virgin media. However, the reverse IP lookup did say that 8 sites were hosted on that IP, including seetickets.co.uk which is registered to See Group so I figured it was legit.

Link to comment
Share on other sites

Great stuff thanks neil and the others. Had tried it but was saying I wasnt admin but I am had to change permissions! It worked and took me straight to booking page and I have a ticket sarcastic.gif

Before that I couldnt even get on the holding page! Passed tip onto a friend but it didnt work for him dash1.gif

Link to comment
Share on other sites

Cheers, worked a treat...

Just wanted to add to wha others said, that ordinarily changing you hosts file because of what someone told you in a forum would be a BAD thing to do! Opening yourself up to a big old scam but desperate times eh?

I got confirmation through and it would have had to been a bleeding elaborate scam to have copied the entire registrations database over!

Good luck all

Link to comment
Share on other sites

@windy_miller

The reason this worked is that seetickets admins had typoed their DNS entries initially,

The had put in a bogus ip address 192.168.202.201 into their DNS instead of 194.168.202.201

When fixing the issue they inadvertantly had removed the working 194 address ->


dig +trace glastonbury.seetickets.com

[snip]

seetickets.com.  172800 IN NS ns1.ststat.com.

seetickets.com.  172800 IN NS ns2.ststat.com.

;; Received 119 bytes from 2001:503:a83e::2:30#53(2001:503:a83e::2:30) in 45 ms

glastonbury.seetickets.com. 60 IN A 192.168.202.201

;; Received 60 bytes from 194.168.202.197#53(194.168.202.197) in 22 ms

Now they have put both entries in again.. so theres no point


glastonbury.seetickets.com. 60 IN A 194.168.202.202

glastonbury.seetickets.com. 60 IN A 194.168.202.201

;; Received 76 bytes from 194.168.202.197#53(194.168.202.197) in 15 ms

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.



×
×
  • Create New...