Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial Upload Shell via LFI exploit filter_list
Author
Message
RE: Upload Shell via LFI exploit #11
Due to being hopeful of finding some idiots RAT, checked files. Spoiler: Clean, but a waste of bytes.

Contains 3 files, a "Thumbs.db" thumbnail file he forgot to remove, "LFI.avi" (previously named "Tut.avi" according to the thumbs.db file), and a text document containing basically his post and some other crap.

The video is potato quality (shit resolution, bad encoding/compression), just shows the usual "proc / self / environ"* trick being used against some random Arabic website.

* Also, Cloudflare WAF seems to think this string is an injection attempt and blocks it. Stupid false positive prone piece of shit.

[+] 2 users Like spjallþráð's post
Reply

RE: Upload Shell via LFI exploit #12
Thanks to those of you who did an analysis of the file content.
---
Click here to get started with Linux!

If I helped you, please +rep me, apparently we've started over on Rep and I'd like to break 100 again...

Inori Wrote: got clickbaited by roger

Reply

RE: Upload Shell via LFI exploit #13
(12-09-2015, 04:47 AM)roger_smith Wrote: Thanks to those of you who did an analysis of the file content.
Perhaps you should close this thread now?
[Image: 9JVyFsC.png]
Sig by @Symadox

XMPP: Mi5@DukGo.com

Reply

RE: Upload Shell via LFI exploit #14
(12-07-2015, 08:25 PM)m0dem Wrote: Hmm... he must have a good crypter... xD No, just kidding.

How is the tutorial @Megan? Useful?

@FoX MaN - did you make this tutorial?

It's a simple method as i said bro
I did it

(12-08-2015, 12:46 AM)meow Wrote: 1. Who would upload a tutorial to dropbox and post the download link to it instead of just posting the actual tutorial here
2. Why is it a .rar
3. Why did he only tag those three members? Targeted RAT'ing attack maybe?
4. He registered yesterday

Fuck was virus total says. Too sketchy.

Those ppl i Tagged them cauzz they welcome me.
That's it
What about ur registerating date bro ?
I'm here to help and educate and learn from other as i said befor.
I forgive u

(12-08-2015, 12:54 AM)roger_smith Wrote: I also find it a bit suspect that he tagged specific users. Proceed with caution.

Look to my answer bro

(12-08-2015, 05:41 AM)Iron Lady Wrote: In my opinion this should be junked. Tutorials should not be downloads.

If you Prof , then ask me about anything in Web App attacks and Test me.

(12-08-2015, 07:15 AM)Sans Wrote: do we really even need a tutorial for this here at all? its kind of a waste, regurgitating knowledge without providing anything new

If u know arabic , i was let u know what do u want or what u want to Know.
But cauzz my English is bad , I Can't explain some Hints with it

It's my turn now my brothers and sisters.
Salam
I'm Arabian guy.
1st HINT
I Don't have more knowledge about PC attacks, just the Basics.
2nd HINT
I'm not SKiddie, Where is the prob when i upload tut to Dropbox, I have'nt Account on Media fire or any trusted sites to you
If you want from me to upload any tuts to another site I'm agree. so Where is the Prob ?
3rd HINT
I Tageed those ppl cauzz they welcome me when i post my Thread.
If all of you want from others to just watching and leaving without any benefit
I'm here to educate and learn from others.
Because my bad English I didn't explain some Hints.
But in Arabic or anyone here know Arabic i can explain anything to him Ensha Allah.
If you want from me only watch and leave It's Ok.
Thx for all , and I Forgive all

Last thing
I'm here to make Friends and know to new Friends and I hope that.
(This post was last modified: 12-09-2015, 08:42 PM by FoX MaN.)

Reply