Page 1 of 2
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 10:32 pm
by geone
Hi, found a bug the message system, the place were you guys can had a image, supposelly, you can only had png, jpg, but well, i bypassed that with somefile.php.jpg
meaning the file can be used has an injection for php shells, in other website's.
example url: http://s3.amazonaws.com/satisfaction-...
Best regards
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 10:34 pm
by geone
a href="http://" rel="nofollow""[img]http://[/img]" alt="" /a
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 10:35 pm
by geone
a href="http://" rel="nofollow""[img]http://[/img]" alt="" /a
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 11:01 pm
by geone
a rel="nofollow"
/a
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 11:02 pm
by geone
a href="alert(1);" rel="nofollow"fdsfsfds
/a
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 11:05 pm
by geone
a href="" rel="nofollow" oho
"
/a
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 11:06 pm
by maxkatz
Where are you trying to upload an image? In Tiggr or in GetSatisfaction.com?
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 11:08 pm
by geone
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 11:09 pm
by geone
the image does not appear, but its upload to your could server in amazon
http://s3.amazonaws.com/satisfaction-...
png, jpg bypass, for injection shell that can be used from rfi injection's
Posted: Fri Apr 08, 2011 11:10 pm
by maxkatz
Just link the image via a free image hosting service. I'd contact getsatisfaction.com why the upload is not working. There is not much we can do.