Waraxe IT Security Portal
Login or Register
November 23, 2024
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 64
Members: 0
Total: 64
Full disclosure
APPLE-SA-11-19-2024-5 macOS Sequoia 15.1.1
Local Privilege Escalations in needrestart
APPLE-SA-11-19-2024-4 iOS 17.7.2 and iPadOS 17.7.2
APPLE-SA-11-19-2024-3 iOS 18.1.1 and iPadOS 18.1.1
APPLE-SA-11-19-2024-2 visionOS 2.1.1
APPLE-SA-11-19-2024-1 Safari 18.1.1
Reflected XSS - fronsetiav1.1
XXE OOB - fronsetiav1.1
St. Poelten UAS | Path Traversal in Korenix JetPort 5601
St. Poelten UAS | Multiple Stored Cross-Site Scripting in SEH utnserver Pro
Apple web content filter bypass allows unrestricted access to blocked content (macOS/iOS/iPadOS/visionO S/watchOS)
SEC Consult SA-20241112-0 :: Multiple vulnerabilities in Siemens Energy Omnivise T3000 (CVE-2024-38876, CVE-2024-38877, CVE-2024-38878, CVE-2024-38879)
Security issue in the TX Text Control .NET Server for ASP.NET.
SEC Consult SA-20241107-0 :: Multiple Vulnerabilities in HASOMED Elefant and Elefant Software Updater
Unsafe eval() in TestRail CLI
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Newbies corner -> Uploaded shell, but...
Post new topicReply to topic View previous topic :: View next topic
Uploaded shell, but...
PostPosted: Wed Jul 23, 2008 9:59 pm Reply with quote
chip
Beginner
Beginner
Joined: Jul 24, 2008
Posts: 4




Hey there.

I'm checking some security vulnerabilities on an SMF 1.1.4 forum, which from what I know has a few notable holes allowing RFI and SQL Injection attacks. However, these attacks require register_globals to be ON, but on the target host, register_globals is OFF.

So, I have a look around the forum to see anything interesting/vulnerable. Amazingly, the forum admin has allowed uploading of attachments OF ANY KIND, which means I can upload php files with ease. So far so good.

Next, I upload a certain php shell!

Normally, any uploaded attachments go to http://example.com/forum/attachments/

And, I know that the admin also has "encrypt filenames" disabled. Now all I need to do is go to: http://example.com/forum/attachments/shell.php and hopefully I can start using my shell... only to come across this:

------------------------

"Forbidden

You don't have permission to access /forums/attachments/ on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request."

------------------------

Huh? Damn. I can't access the folder, so I can't access my shell anymore. Is there a workaround for this? Can I access my shell using another php file on the server?

Any help or hints would be appreciated.

(Note: clicking on the link from the post's attachment only downloads the shell without executing it.)
View user's profile Send private message
PostPosted: Thu Jul 24, 2008 1:50 am Reply with quote
gibbocool
Advanced user
Advanced user
Joined: Jan 22, 2008
Posts: 208




hmm, try and upload shell.php%00

otherwise, you can try overwrite the .htaccess

_________________
http://www.gibbocool.com
View user's profile Send private message Visit poster's website
PostPosted: Thu Jul 24, 2008 11:35 am Reply with quote
chip
Beginner
Beginner
Joined: Jul 24, 2008
Posts: 4




gibbocool wrote:
hmm, try and upload shell.php%00

otherwise, you can try overwrite the .htaccess


Thank you for your post. Here's what happened:

Uploading .htaccess didn't make any change to dir permission, I still got the 403 Forbidden error.

Now for shell.php%00 I got this instead:

------------------------
Not Found

The requested URL /forums/attachments/shell.php was not found on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
------------------------

EDIT: I tried the %00 in another SMF forum that I own with "encrypt filenames" disabled, also didn't work.

Any other suggestions?


Last edited by chip on Thu Jul 24, 2008 12:02 pm; edited 2 times in total
View user's profile Send private message
PostPosted: Thu Jul 24, 2008 11:59 am Reply with quote
gibbocool
Advanced user
Advanced user
Joined: Jan 22, 2008
Posts: 208




I'm not too sure what's going on, perhaps some other members can elaborate.

Have you tried uploading .html files or any other files to see if they are forbidden?

_________________
http://www.gibbocool.com
View user's profile Send private message Visit poster's website
PostPosted: Thu Jul 24, 2008 12:19 pm Reply with quote
chip
Beginner
Beginner
Joined: Jul 24, 2008
Posts: 4




Hmm ok.

1. You can upload any type of file you want.

2. The file goes to example.com/forums/attachments/

3. But you can't directly go to /forums/attachments/ in the url because it is forbidden.

To make it simple, it's the same thing as this: http://www.waraxe.us/admin/whatever.php

uploading an .htacess didn't change anything, shell.php%00 didn't work

Any other ideas?
View user's profile Send private message
PostPosted: Thu Jul 24, 2008 2:06 pm Reply with quote
pexli
Valuable expert
Valuable expert
Joined: May 24, 2007
Posts: 665
Location: Bulgaria




You have access to admin panel?
View user's profile Send private message
PostPosted: Thu Jul 24, 2008 2:15 pm Reply with quote
chip
Beginner
Beginner
Joined: Jul 24, 2008
Posts: 4




koko wrote:
You have access to admin panel?


Nope, but you get the same 403 Error as in the SMF forum. Any way to get around this?
View user's profile Send private message
PostPosted: Thu Jul 24, 2008 5:44 pm Reply with quote
pexli
Valuable expert
Valuable expert
Joined: May 24, 2007
Posts: 665
Location: Bulgaria




I think only if you have access to admin panel.Via admin panel you mai change the upload directory and try to upload shell.
View user's profile Send private message
Uploaded shell, but...
www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.035 Seconds