geone
Posts: 0
Joined: Fri Apr 08, 2011 5:44 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

what i am uploading is a file.txt with extension file.txt.jpg, and it gets accepted, if you download the image in the url, you will get c100 shell in plain text.
in this url http://s3.amazonaws.com/satisfaction-...

it's were all your images get uploaded.

maxkatz
Posts: 0
Joined: Fri Aug 13, 2010 3:24 pm

png, jpg bypass, for injection shell that can be used from rfi injection's

Just upload the image to http://imageshack.us/ and paste a link here.

Return to “Issues”