Shell Uploading With Live HTTP Headers
For this tutorial you need :
Mozilla Firefox
Live HTTP Headers -> https://addons.mozilla.org/en-US/firefox...p-headers/
Find an website which allows you to upload .jpg , .png or any other extension
So now once you have found a website , we are going to try and upload .php file
For example if i try to upload BCA.php
The server rejects the file and says wrong extension
Now we are going to rename our shell toCode:bca.php.jpg
Now try opening the Image , Right click on it and open in new tab
Now go to the upload spot and click browse
Go to the Live Http Headers and run it
The Capture Box should be checked
Now upload the shell , Wait for it to load completely and our bca.php.jpg should come up on the Live Http Headers
Highlight the shell name and click on the replay button
A new windows should popup , now we have to find our shell name for example bca.php.jpg and rename is to bca.php
Now when you have done that click the replay button again
The page should refresh
Now right click on the picture you upload and open in new Tab
There you go the shell should be there
©2011, copyright BLACK BURN
Hey Black burn Amazing tutorial thank you sooo much , But i tried the method on a web site that is vulnerable to FCKeditior upload , i can upload text so i did the same but with text extinsion and when i reach the point using Live HTTP Header and i press replay after changing the extension the page realoads but nothing work it just reload with blank white screen and , iam sure that my shell is working cuz i tested it ? any ideas Bro :) thank you for your time :D
ReplyDelete