:: vBspiders Professional Network ::

:: vBspiders Professional Network :: (http://www.vbspiders.com/vb/index.php)
-   قـسـم إخـتـراق الـمـواقـع والـسـيرفـرات (http://www.vbspiders.com/vb/f38.html)
-   -   Fun with IIS (http://www.vbspiders.com/vb/t49392.html)

nullbyte 06-14-2011 07:31 PM

Fun with IIS
 
Hiya all :-)

Few days back i had post an article on how to bypass upload validation in php......

But the same i encountered with IIS.....It is quite old bug but thought of sharing with you as it was very helpful to me also......

Let's say there is a website and it allows only image file upload such as jpg, gif, png etc, than all you need to do is as follow

Step 1: Choose any of your shell, does not matter whether asp, aspx or php

step 2: Rename it to something.asp;.gif and upload it

Note: Check semicolon (;) after .asp

Take the direct link to your image and open it, instead of sending it to image handler IIS will treat it as asp script and it will get executed on the server.... ;-)

Countermeasure : Do not give execute permission to the folder where images are being uploaded....That's it....Quite simple yet effective way.....

maxema 06-14-2011 07:33 PM

يشرفني اكون اول من يرد عليك بس مافهمت شيء

nullbyte 06-14-2011 07:38 PM

Thanks mate....Your welcome..........:-)

bleu moon 06-20-2011 06:12 AM

thx men :D

ZrIqE ViRuS 06-21-2011 07:37 PM

thank's man

keep up bro

"it a good way " :P


الساعة الآن 10:26 AM


[ vBspiders.Com Network ]


SEO by vBSEO 3.6.0