Проблема с инклудом шелла

Discussion in 'Песочница' started by J_thief, 17 Nov 2016.

  1. J_thief

    J_thief New Member

    Joined:
    12 Aug 2013
    Messages:
    16
    Likes Received:
    0
    Reputations:
    0
    Всем привет. Нашел сайт, на котором можно провести удаленный инклуд. На сервер загрузил шел, поставил формат txt, как описано в муналах. Но вместо того, что бы запускался шел, мне выводит исходный код шела, как пофиксить такое?
     
  2. st55

    st55 Level 8

    Joined:
    20 Apr 2016
    Messages:
    195
    Likes Received:
    341
    Reputations:
    47
    Сменить расширение на php?
     
  3. J_thief

    J_thief New Member

    Joined:
    12 Aug 2013
    Messages:
    16
    Likes Received:
    0
    Reputations:
    0
    тогда шелл запускается, но на атакующем сервере, а не на атакуемом.
     
  4. BabaDook

    BabaDook Well-Known Member

    Joined:
    9 May 2015
    Messages:
    1,063
    Likes Received:
    1,559
    Reputations:
    40
    Ты трезв?


    Автор, точно инклуд?
     
  5. J_thief

    J_thief New Member

    Joined:
    12 Aug 2013
    Messages:
    16
    Likes Received:
    0
    Reputations:
    0
    да, могу даже линк сюда скинуть, проверишь
     
  6. BabaDook

    BabaDook Well-Known Member

    Joined:
    9 May 2015
    Messages:
    1,063
    Likes Received:
    1,559
    Reputations:
    40
    ага. давай, вангую не инклуд
     
  7. J_thief

    J_thief New Member

    Joined:
    12 Aug 2013
    Messages:
    16
    Likes Received:
    0
    Reputations:
    0
  8. J_thief

    J_thief New Member

    Joined:
    12 Aug 2013
    Messages:
    16
    Likes Received:
    0
    Reputations:
    0
  9. BabaDook

    BabaDook Well-Known Member

    Joined:
    9 May 2015
    Messages:
    1,063
    Likes Received:
    1,559
    Reputations:
    40
    SSrf.
    Только я пока не понял как заставить читалку работать, может на досуге гляну может быть.
     
  10. t0ma5

    t0ma5 Reservists Of Antichat

    Joined:
    10 Feb 2012
    Messages:
    829
    Likes Received:
    815
    Reputations:
    90
    ёп тс а то что на скрине у тебя один домен, а пишешь в топике ты про другой, это нормально?
     
    _________________________
  11. t0ma5

    t0ma5 Reservists Of Antichat

    Joined:
    10 Feb 2012
    Messages:
    829
    Likes Received:
    815
    Reputations:
    90
    _________________________
  12. BabaDook

    BabaDook Well-Known Member

    Joined:
    9 May 2015
    Messages:
    1,063
    Likes Received:
    1,559
    Reputations:
    40
  13. t0ma5

    t0ma5 Reservists Of Antichat

    Joined:
    10 Feb 2012
    Messages:
    829
    Likes Received:
    815
    Reputations:
    90
    _________________________
  14. J_thief

    J_thief New Member

    Joined:
    12 Aug 2013
    Messages:
    16
    Likes Received:
    0
    Reputations:
    0
    Спасибо ребят, что прояснили моменты)
     
  15. BabaDook

    BabaDook Well-Known Member

    Joined:
    9 May 2015
    Messages:
    1,063
    Likes Received:
    1,559
    Reputations:
    40
    Вообщем я был туп и слеп.

    PHP:
    view-source:http://www.stereoart.ru/pg.php?page=scRiPt
    HTML:
    <frame name="content" src="scRiPt" scrolling="auto" frameborder="no" marginheight="10" marginwidth="10" framespacing="0" border="0">
    
    Эта уязвимость на стороне клиента
     
Loading...