|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
safe_mode,how to break |
|
Posted: Sun Mar 23, 2008 5:08 am |
|
|
kieuanh |
Regular user |
|
|
Joined: Mar 22, 2008 |
Posts: 23 |
|
|
|
|
|
|
|
question 1:I can upload php shell via Coppermine Photo Gallery 1.3.0 but why i cant upload anything via my shell ? (r57,c99,nstview ... all)
question 2:server is safe_mode,i cant read file,read my dir via any funtions (imap,readfile,include,curl,sql <-> i dont have account,ini_restore:...)
server is disable some function
Quote: |
system,dl,passthru,exec,shell_exec,popen,proc_close,proc_get_status,proc_nice,proc_open,allow_url_fopen,chown,chgrp,escapeshellcmd,escapeshellarg,show_source,posix_mkfifo,set_time_limit,mysql_list_dbs,get_current_user,getmyuid,posix_setuid,posix_setsid,posix_setpgid,posix_setpgid,posix_kill,apache_child_terminate,leak,pfsockopen
|
Any idea ???
Note:If i have a cgi,maybe i can break this security but i dont have |
|
|
|
|
|
|
|
|
Posted: Sun Mar 23, 2008 5:45 am |
|
|
Frigo |
Regular user |
|
|
Joined: Feb 10, 2008 |
Posts: 13 |
Location: European Union |
|
|
|
|
|
|
1) Probably you don't have access to those directories you want to put tha file in. I don't think you will find a writeable directory in safe mode, though.
2) There's a recent mysql bug that allows you to bypass safe mode, and read anything from the server, if the sql server and the file server is the same. |
|
|
|
|
Posted: Sun Mar 23, 2008 5:54 am |
|
|
kieuanh |
Regular user |
|
|
Joined: Mar 22, 2008 |
Posts: 23 |
|
|
|
|
|
|
|
1) Coppermine can upload so that this directory is writeable
2) yes,i know but i dont have any mysql account in server because i cant view file ,only /etc/passwd via posix_getpwuid
i think when i get passwd,i only have a solution to brute force password
Any idea |
|
|
|
|
Posted: Sun Mar 23, 2008 9:06 am |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
Yeah.Paranoic admin.OK.
Try first phpinfo(); Look full path to the your site.Then use readfile('/home/blabla/file.php'); to read files.Try do upload perl shell into cgi-bin directory. |
|
|
|
|
Posted: Sun Mar 23, 2008 9:36 am |
|
|
kieuanh |
Regular user |
|
|
Joined: Mar 22, 2008 |
Posts: 23 |
|
|
|
|
|
|
|
OK,everything is done,upload cgi successful .Thx everyone |
|
|
|
|
www.waraxe.us Forum Index -> All other security holes
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|