![]() |
|
Shell bypass - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Shell bypass (/Thread-Shell-bypass) Pages:
1
2
|
Shell bypass - Bikodino - 03-09-2013 hello all ![]() What is the way to bypass the control of extensions, for a shell in php? I mean ...... the method .gif thanks:wink: RE: Shell bypass - 1llusion - 03-10-2013 What do you mean? You mean the method where you can upload a PHP file by changing its extension? RE: Shell bypass - Bikodino - 03-11-2013 (03-10-2013, 04:11 PM)1llusion Wrote: What do you mean? does not work as you say. if you change the extension appears: "The image can not be displayed because it contains errors." while using "tamperdata" does not allow you upload, because changing from. php.gif a. php system does not accept the extension. works well for all sites. there must be a way to bypass. help me! RE: Shell bypass - 1llusion - 03-11-2013 (03-11-2013, 04:54 PM)Bikodino Wrote: does not work as you say. I was asking, not telling. Have you tried "binding" the php file to the end of the picture? RE: Shell bypass - Bikodino - 03-12-2013 (03-11-2013, 07:49 PM)1llusion Wrote:(03-11-2013, 04:54 PM)Bikodino Wrote: does not work as you say. nothing. does not work. He says: "The image can not be displayed because it contains errors." Can anyone help me? It does so with all sites.:headbash: RE: Shell bypass - 1llusion - 03-12-2013 (03-12-2013, 12:32 AM)Bikodino Wrote:(03-11-2013, 07:49 PM)1llusion Wrote:(03-11-2013, 04:54 PM)Bikodino Wrote: does not work as you say. Probably there is a protection against this kind attack? It is quite known and there are pretty simple ways of checking the files. RE: Shell bypass - Bikodino - 03-12-2013 (03-12-2013, 12:38 AM)1llusion Wrote:(03-12-2013, 12:32 AM)Bikodino Wrote:(03-11-2013, 07:49 PM)1llusion Wrote:(03-11-2013, 04:54 PM)Bikodino Wrote: does not work as you say. you're right. But the sites are defaced. So a way to bypass it should be! RE: Shell bypass - 1llusion - 03-12-2013 (03-12-2013, 01:18 AM)Bikodino Wrote: you're right. You know there isn't just one hacking method. Think out of the box, that is the way to do it. Go ahead and try my hacking challenge: http://www.hackcommunity.com/Thread-Contest-TEST-P-HackMeIfYouCan and you will see what I mean
RE: Shell bypass - Bikodino - 03-12-2013 (03-12-2013, 01:40 AM)1llusion Wrote:(03-12-2013, 01:18 AM)Bikodino Wrote: you're right. 1llusion, if I do not learn the first to upload and bypass a shell in php, How can I participate in this challenge? It 'possible that nobody knows? RE: Shell bypass - 1llusion - 03-12-2013 (03-12-2013, 10:50 AM)Bikodino Wrote:(03-12-2013, 01:40 AM)1llusion Wrote:(03-12-2013, 01:18 AM)Bikodino Wrote: you're right. Because this challenge is not about uploading. It doesn't require any technical skills. 2 members found the correct solution. As I say, it is just a matter of thinking out of the box. |