|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
I really need help on this, Plz |
|
Posted: Sun Apr 02, 2006 11:36 pm |
|
|
naragorn |
Regular user |
|
|
Joined: Apr 03, 2006 |
Posts: 10 |
|
|
|
|
|
|
|
Well after lots of efforts i managed to hack into the account of the admin of a phpbb forum, when i was done with it, i started lookin for a way to upload a shell, then i run into this
http://spiderz.netsons.org/6.txt
I tried that and it worked, it does display the html, but as u know, html is useless when trying to upload anything(As ive been told, i still have my doubts)
Ive tried to put some php code, but it wont run, just display the source.
Well, my question is, now that i know uploading html code is possible, what can i do to either run some php code, upload a phpshell or download the config files (config.php)???
Plz, is there a way this can be accomplished, id really aprecciate any help,
Thx |
|
|
|
|
Posted: Mon Apr 03, 2006 4:05 pm |
|
|
Aryan-Husky |
Active user |
|
|
Joined: Apr 03, 2006 |
Posts: 37 |
|
|
|
|
|
|
|
Hi naragon,
Do you have an english translation of that exploit?
Thanks. |
|
|
|
|
Posted: Mon Apr 03, 2006 4:20 pm |
|
|
naragorn |
Regular user |
|
|
Joined: Apr 03, 2006 |
Posts: 10 |
|
|
|
|
|
|
|
You Open the notepad put in some html code, then you save it as .gif, .png or .jpg.Then you open ur phpbb forum on firefox(Opera works too), then you go to your profile and upload the gif with html code in it, it should upload it succesfully.Then u open the forum on Internet Explorer, goto ur profile and copy the addres of ur avatar, then paste it on address bar and you should see whatever code u put in that jpg with html code, that would be the trick.
PLZ any help will be aprreciated |
|
|
|
|
www.waraxe.us Forum Index -> PhpBB
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|