|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
help me ,phpbb2.0.18 upload shell? |
|
Posted: Wed Jan 13, 2010 8:36 am |
|
|
roooot |
Beginner |
|
|
Joined: Jan 13, 2010 |
Posts: 3 |
|
|
|
|
|
|
|
Me in this installation phpbb2.0.18, restored in the background, the author system ($ _GET [cmd]), successful, but the target server Shique failed. They can execute phpinfo () can be displayed! Target PHP settings are as follows:
register_globals = Off
safe_mode = On
safe_mode_exec_dir = / usr / local / php_safebin
safe_mode_gid = On
safe_mode_include_dir = no value
disable_functions = popen, fsockopen, pfsockopen, syslog, openlog
Sorry, my English is not good! |
|
|
|
|
Posted: Wed Jan 13, 2010 10:55 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Safe mode can be bad thing. What php version it is by the way? |
|
|
|
|
Posted: Wed Jan 13, 2010 11:11 am |
|
|
roooot |
Beginner |
|
|
Joined: Jan 13, 2010 |
Posts: 3 |
|
|
|
|
|
|
|
PHP Version 5.2.10!Have any solution?site path:/www/ |
|
|
|
|
Posted: Wed Jan 13, 2010 11:21 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
What's your intentions? You can manipulate with database from php level. It means fetching all possible data from database or defacement of the target. And without the need for linux shell access. So - what's your ultimate goal? |
|
|
|
|
Posted: Wed Jan 13, 2010 11:43 am |
|
|
roooot |
Beginner |
|
|
Joined: Jan 13, 2010 |
Posts: 3 |
|
|
|
|
|
|
|
I would like to get webshell!do you help me?what's your MSN,my msn is blackmask@live.cn |
|
|
|
|
Posted: Wed Jan 13, 2010 12:31 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
I'm avoiding instant messengers, so no msn
By webshell you mean r57,c99 or similar, right? Those are lamer tools. They are bloated, ineffective, will trigger IPS, stuff logs, etc. I suggest writing custom script with functionality you need.
Still, if you need c99 or similar, then:
1. make sure, that you have directory, which is accesible via http and is writable by php.
2. with couple of lines of php code you are able to upload any file to the target server via http POST method, using standard webbrowser.
No need for fopen, file_get_contents or include via http. Just google for simple php upload scripts. |
|
|
|
|
www.waraxe.us Forum Index -> PhpBB
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|