RE: Upload Shell via LFI exploit 12-09-2015, 01:31 AM
#11
Due to being hopeful of finding some idiots RAT, checked files. Spoiler: Clean, but a waste of bytes.
Contains 3 files, a "Thumbs.db" thumbnail file he forgot to remove, "LFI.avi" (previously named "Tut.avi" according to the thumbs.db file), and a text document containing basically his post and some other crap.
The video is potato quality (shit resolution, bad encoding/compression), just shows the usual "proc / self / environ"* trick being used against some random Arabic website.
* Also, Cloudflare WAF seems to think this string is an injection attempt and blocks it. Stupid false positive prone piece of shit.
Contains 3 files, a "Thumbs.db" thumbnail file he forgot to remove, "LFI.avi" (previously named "Tut.avi" according to the thumbs.db file), and a text document containing basically his post and some other crap.
The video is potato quality (shit resolution, bad encoding/compression), just shows the usual "proc / self / environ"* trick being used against some random Arabic website.
* Also, Cloudflare WAF seems to think this string is an injection attempt and blocks it. Stupid false positive prone piece of shit.


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)













![[Image: 9JVyFsC.png]](http://i.imgur.com/9JVyFsC.png)
No, just kidding.