Sinisterly
Advanced Exploitation Techniques - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Advanced Exploitation Techniques (/Thread-Advanced-Exploitation-Techniques)

Pages: 1 2 3 4


RE: Advanced Exploitation Techniques - Megamente - 07-06-2013

Great article! Well explained and written. Smile


RE: Advanced Exploitation Techniques - Megamente - 07-06-2013

Great article! Well explained and written. Smile


RE: Advanced Exploitation Techniques - Megamente - 07-06-2013

Great article! Well explained and written. Smile


RE: Advanced Exploitation Techniques - JDKlett - 07-22-2013

I found in this thread a lot of nice information!

Thank you!

Anyway I was expecting something more "Advanced" as promised by the title...

Moreover as you described it the LFI seems to be a kind of magic.

Cheers!


RE: Advanced Exploitation Techniques - JDKlett - 07-22-2013

I found in this thread a lot of nice information!

Thank you!

Anyway I was expecting something more "Advanced" as promised by the title...

Moreover as you described it the LFI seems to be a kind of magic.

Cheers!


RE: Advanced Exploitation Techniques - JDKlett - 07-22-2013

I found in this thread a lot of nice information!

Thank you!

Anyway I was expecting something more "Advanced" as promised by the title...

Moreover as you described it the LFI seems to be a kind of magic.

Cheers!


RE: Advanced Exploitation Techniques - MoE Tain - 08-11-2013

I've never been server side inclusion before... I know more inclusion from u... Thanks u very much


RE: Advanced Exploitation Techniques - MoE Tain - 08-11-2013

I've never been server side inclusion before... I know more inclusion from u... Thanks u very much


RE: Advanced Exploitation Techniques - zomgwtfbbq - 08-11-2013

You could have told why RFI isn't so common these days and why allow_url_include is turned off.
Also your RFI example can't work unless you add a poison null byte to the url which will discard the php extension, otherwise:
http://yourevilsite.com/shell.txt > http://yourevilsite.com/shell.txt.php

I'm sorry to say this tutorial isn't so original, it's like every tutorial you come across nowadays is either xss, sqli, rfi or lfi related, while there are so many other types of vulnerabilities.
Don't want to sound negative but it's just the way I feel.


RE: Advanced Exploitation Techniques - zomgwtfbbq - 08-11-2013

You could have told why RFI isn't so common these days and why allow_url_include is turned off.
Also your RFI example can't work unless you add a poison null byte to the url which will discard the php extension, otherwise:
http://yourevilsite.com/shell.txt > http://yourevilsite.com/shell.txt.php

I'm sorry to say this tutorial isn't so original, it's like every tutorial you come across nowadays is either xss, sqli, rfi or lfi related, while there are so many other types of vulnerabilities.
Don't want to sound negative but it's just the way I feel.