Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Top Posters

Who's Online (2)

Powered by Vanilla. Made with Bootstrap.
  • Please someone cane explain me this 2 methods because i dont heard about it .. and i want to upload shell to a site where i have admin panel acces but i cane upload only in jpg,jpeg,gif,png,swf.
    I have tried all know methods but dont have anny luck ..


    Another method to bypass some server side checks is to edit the shell code and add at the beginning before the < GIF89;a.
    Also you could use an intercepting proxy like w3af,Burp proxy... and change the data type... works like a charm in many situations ;)
  • Xin
    Posts: 3,251
    Try upload the shell as
    -shell.php.jpg
    -shell.php%00.jpg
    -Try using tamper data to edit the post request
    -Dont upload c99 first, upload zarabytes uploader script 1st as it is FUD
    Xin
  • dR.sqL
    Posts: 23
    said:


    Try upload the shell as
    -shell.php.jpg
    -shell.php%00.jpg
    -Try using tamper data to edit the post request
    -Dont upload c99 first, upload zarabytes uploader script 1st as it is FUD


    Xinapse thanks for these tips ...i heard so much about tamper data...can you explain something about it.. ? And how can we use it to upload a shell. ? :) Thanks !