geone
Posts: 0
Joined: Fri Apr 08, 2011 5:44 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

Hi, found a bug the message system, the place were you guys can had a image, supposelly, you can only had png, jpg, but well, i bypassed that with somefile.php.jpg
meaning the file can be used has an injection for php shells, in other website's.
example url: http://s3.amazonaws.com/satisfaction-...

Best regards

geone
Posts: 0
Joined: Fri Apr 08, 2011 5:44 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

a href="http://" rel="nofollow""[img]http://[/img]" alt="" /a

geone
Posts: 0
Joined: Fri Apr 08, 2011 5:44 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

a href="http://" rel="nofollow""[img]http://[/img]" alt="" /a

geone
Posts: 0
Joined: Fri Apr 08, 2011 5:44 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

a href="alert(1);" rel="nofollow"fdsfsfdsImage/a

geone
Posts: 0
Joined: Fri Apr 08, 2011 5:44 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

a href="" rel="nofollow" oho

"Image /a

maxkatz
Posts: 0
Joined: Fri Aug 13, 2010 3:24 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

Where are you trying to upload an image? In Tiggr or in GetSatisfaction.com?

geone
Posts: 0
Joined: Fri Apr 08, 2011 5:44 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

the image does not appear, but its upload to your could server in amazon
http://s3.amazonaws.com/satisfaction-...

maxkatz
Posts: 0
Joined: Fri Aug 13, 2010 3:24 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

Just link the image via a free image hosting service. I'd contact getsatisfaction.com why the upload is not working. There is not much we can do.

Return to “Issues”