Page 2 of 2

png, jpg bypass, for injection shell that can be used from rfi injection's

Posted: Fri Apr 08, 2011 11:12 pm
by geone

what i am uploading is a file.txt with extension file.txt.jpg, and it gets accepted, if you download the image in the url, you will get c100 shell in plain text.
in this url http://s3.amazonaws.com/satisfaction-...

it's were all your images get uploaded.


png, jpg bypass, for injection shell that can be used from rfi injection's

Posted: Fri Apr 08, 2011 11:15 pm
by maxkatz

Just upload the image to http://imageshack.us/ and paste a link here.