Results 1 to 5 of 5

Thread: need to know different methods to upload web shell like c99

  1. #1
    Just burned his ISO
    Join Date
    Feb 2010
    Posts
    9

    Default need to know different methods to upload web shell like c99

    Hi, ALL

    i want to know how i could upload web shells like c99 or r57 to a web and if there are more than way plz tell me step by step

  2. #2
    Moderator fancy's Avatar
    Join Date
    Jan 2010
    Posts
    204

    Default

    Ay ay ay......why would you want to do that????
    I cannot find a legal reason in this action..........

  3. #3
    Just burned his ISO
    Join Date
    Feb 2010
    Posts
    9

    Default

    i found a web shell on web server i pen-test it but i could not realize how the attacker has upload this shell specially that even with administrator there is a restriction on uploading things ( it must be .jpg or pdf, or png) so how the attacker runs this php shell so i have taken an image from the system to analyze and i decided to rebuild the same enviro to try act as the attacker and know what are the steps he has taken to by pass extension limitation

  4. #4
    Moderator fancy's Avatar
    Join Date
    Jan 2010
    Posts
    204

    Default

    Obviously he used a flaw in the php application, e.g. a file upload vulnerability e.g. LFI.

  5. #5
    Just burned his ISO
    Join Date
    Feb 2010
    Posts
    9

    Default

    you were right . Thank you Fancy

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •