Waraxe IT Security Portal  
  Login or Register
::  Home  ::  Search  ::  Your Account  ::  Forums  ::   Waraxe Advisories  ::  Tools  ::
May 22, 2024
 Members List
 IRC chat
 Base64 coder
 MD5 hash
 CRC32 checksum
 ROT13 coder
 SHA-1 hash
 Sql Char Encoder
 y3dips ITsec
 Md5 Cracker
 User Manuals
 Recommend Us
 Your Account

User Info
Welcome, Anonymous

Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9145

People Online:
Visitors: 374
Members: 0
Total: 374
PacketStorm News
·301 Moved Permanently

Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Remote file inclusion -> RFI on phpBB 2.0.6 image uploader
Post new topic  Reply to topic View previous topic :: View next topic 
RFI on phpBB 2.0.6 image uploader
PostPosted: Tue Sep 16, 2008 10:32 pm Reply with quote
Joined: Sep 17, 2008
Posts: 3

Hi there Very Happy

am relatively new to this game so be easy on me.

Ok i've found a phpbb board running v2.0.6
tried all the old exploits on them an none work, admin must has patched them.

i did come across ht*p://www.thesite.com/uploader.php which lets you upload jpg's only, which changes the image names to eg: 85624ed2a8a00d466b365efad157c5f9.jpg

i binded a jpg and c99shell using the windows cmd copy /b with the output of c99shell.php.jpg and it uploaded successfully locally on my box and displayed the image but the php within the image didn't parse until i removed the .jpg extension and then it spawned the shell locally.

i know the image i uploaded remotely has the php inside it but can't get it to parse when displayed because i can change the extension and also it randomizes a new name for the image, can you tell me what i should looking up on.
or if even am on the right tracks! or am way over my head on this

View user's profile Send private message
PostPosted: Wed Nov 19, 2008 7:04 pm Reply with quote
Joined: Nov 19, 2008
Posts: 1

Yep i works fine
View user's profile Send private message Visit poster's website
RFI on phpBB 2.0.6 image uploader
  www.waraxe.us Forum Index -> Remote file inclusion
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

 Post new topic  Reply to topic  

Powered by phpBB 2001-2008 phpBB Group

Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2020 Janek Vind "waraxe"
Page Generation: 0.182 Seconds