Upload Multiple Files With a Single File Element
#1
baru saja saya menemukan ini Angry

Code:
# Title            : Upload Multiple Files With a Single File Element
# Download         : http://the-stickman.com/files/multiple-file-element.zip
# Date             : 28 July 2012
# Author           : h3ll0s
# Home             : http://www.facebook.com/groups/3rr0rc0de/
# Dork             : Think it :p
# Greatz           : Gato Lucy, Starkey, Cimay, phiA, haning32.dll
# Big Thank's      : 3rr0r c0de | PasuruanCyber
                     BinusHacker
                     r00tw0rm
# email            : [email protected]
# Tested           : Debian Lenny

-=-=-=-=-=-=-=-
Description

You can upload an attachment file on the server,
example jpg, png, gif.
used tamper data to change the shell.php

=-=-=-=-=-=-=-=
Vulnerable Code

(move_uploaded_file($_FILES['file']['tmp_name'][$i], $destination . '/' .$nm_file)) {
        echo $_FILES['file']['name'][$i] . " uploaded sucessfully!<br>";
        $attach .= '<br/><a href="attachment/'. $nm_file .'" >'.$nm_file.'</a>';
        }
        
-=-=-=-=-=-=-=-
Destination

You can preview your shell at folder /attacement/yourshell

# Demo Shell :
http://tts-lpse.lkpp.go.id/tts/attachment/181061011404_V1.jpg.php
http://tts-lpse.lkpp.go.id/tts2/tes_.php

Press TAB Keyboard, you can found login shell.
password shell : ask me #LOL

download

#2
(07-31-2012, 03:28 AM)h3ll0s Wrote: baru saja saya menemukan ini Angry

Code:
# Title            : Upload Multiple Files With a Single File Element
# Download         : http://the-stickman.com/files/multiple-file-element.zip
# Date             : 28 July 2012
# Author           : h3ll0s
# Home             : http://www.facebook.com/groups/3rr0rc0de/
# Dork             : Think it :p
# Greatz           : Gato Lucy, Starkey, Cimay, phiA, haning32.dll
# Big Thank's      : 3rr0r c0de | PasuruanCyber
                     BinusHacker
                     r00tw0rm
# email            : [email protected]
# Tested           : Debian Lenny

-=-=-=-=-=-=-=-
Description

You can upload an attachment file on the server,
example jpg, png, gif.
used tamper data to change the shell.php

=-=-=-=-=-=-=-=
Vulnerable Code

(move_uploaded_file($_FILES['file']['tmp_name'][$i], $destination . '/' .$nm_file)) {
        echo $_FILES['file']['name'][$i] . " uploaded sucessfully!<br>";
        $attach .= '<br/><a href="attachment/'. $nm_file .'" >'.$nm_file.'</a>';
        }
        
-=-=-=-=-=-=-=-
Destination

You can preview your shell at folder /attacement/yourshell

# Demo Shell :
http://tts-lpse.lkpp.go.id/tts/attachment/181061011404_V1.jpg.php
http://tts-lpse.lkpp.go.id/tts2/tes_.php

Press TAB Keyboard, you can found login shell.
password shell : ask me #LOL

download

apaan tu om Angry cek TKP malah bingung:apn: pencerahannya dongSmile
Spoiler! :
<<Back|Track
☆‍‍‍‍☆‍‍‍‍☆‍‍‍‍☆☆


#3
Quote:apaan tu om Angry cek TKP malah bingung:apn: pencerahannya dongSmile


itu bugs yg saya temukan, developper web tdk tahu akan bugs tersebut

saya lupa memberi tag untuk thread ini

#4
ow jadi upload shell.jpg.php
tapi kok systemnya ngak nolak file nya :-?

#5
Tongue 
bngung bro ngg ngerti mksutnya ntuu.... =D
Quote:
  • [spoiler=SS Guild 21 April 2012]Uploading . . . [/spoiler]
  • [spoiler=CW Faction Terbesar][Image: r02yjn.jpg][/spoiler]
  • Grup Facebook :► [St-Unlimited™[Image: Ib5EQZQAWZ2.png]]
  • Website :► [Website]
Copyright © 2011-2012. All Right Reserved.
The Owner of G4MEZONE™ ® Company & HDS Designer

#6
maksudnya kagak ngrt ane om
mohon pencerahannya

#7
(11-18-2012, 04:29 PM)abdilahrf Wrote: ow jadi upload shell.jpg.php
tapi kok systemnya ngak nolak file nya :-?

temper data om..
cmiiwConfused:-

#8
masih kurang jelas ane om ... -_-..

#9
apaan tuh om? bingung 7 kelilingin

#10
demo dan penampakan nya ga bisa bro Big Grin






Users browsing this thread: 1 Guest(s)