[CHALLENGE] HELP ME UPLOAD WEBSHELL!
#1

#2
if(isset($_FILES['upload']['name'])){
pake isset biar indexnya gk langsung keluar

tapi ane upload file php kok gak gagal :v
pas ane cek type nya gak kedetect php
malah kedetek octet-stream
padahal file yang ane upload .php Big Grin

#3
(06-13-2013, 09:16 AM)abdilahrf Wrote: if(isset($_FILES['upload']['name'])){
pake isset biar indexnya gk langsung keluar

tapi ane upload file php kok gak gagal :v
pas ane cek type nya gak kedetect php
malah kedetek octet-stream
padahal file yang ane upload .php Big Grin

waduh masternya datang. hehe. maap nih kemarin agak ngantuk n mikirnya asal asalan. kebalik pula Big Grin. nih yang bener. ngga pake encode aja lah kelamaan Big Grin
PHP Code:
<?    
    if(isset($_FILES['upload']['name'])){
        $mime = $_FILES['upload']['type'];
        if($mime == "image/jpeg" || $mime == "image/png"){
            if(move_uploaded_file($_FILES['upload']['tmp_name'],basename($_FILES['upload']['name']))){
                echo "Upload succes, filename : ".basename($_FILES['upload']['name']);
            }
            else {
                echo "Upload failed, maybe you forget to chmod your folder to 777 so i can upload this file directory directory :'(";
            }
        }
        else {
            echo "Sorry dude, but that filetype not allowed :ROFL:";
        }
    }
    else {
        echo "
        Jpg Png Only!<br>
        <form method=post enctype=multipart/form-data>
        <input type=file name=upload>
        <input type=submit value=upload>
        </form>";
    }
?>

#4
modif aja header nya
sukses lah hasil uploadnya Smile

eh kok headers, maksudku modif paramerter nya -_-

#5
pake tamper data mungkin :-? :-?
PHP Code:
_/_/_/_/_/                                      
   
_/      _/_/_/  _/_/    _/_/_/    _/    _/   
  
_/      _/    _/    _/  _/    _/    _/_/      
 
_/      _/    _/    _/  _/    _/  _/    _/     
_/      _/    _/    _/  _/_/_/    _/    _/      
                       
_/                       
                      
_

#6
(06-14-2013, 03:55 PM)TMPX Wrote: pake tamper data mungkin :-? :-?

yups, bener pak

tested : Windows OS
WebServ : Apache

#7
(06-14-2013, 03:34 PM)areoid Wrote: modif aja header nya
sukses lah hasil uploadnya Smile

eh kok headers, maksudku modif paramerter nya -_-

=))=))
wah kok terlalu mudah y kynya, wkwkwk gpp lah. nambah ilmu dikit. Big Grin

#8
(06-14-2013, 05:01 PM)alkaaf Wrote:
(06-14-2013, 03:34 PM)areoid Wrote: modif aja header nya
sukses lah hasil uploadnya Smile

eh kok headers, maksudku modif paramerter nya -_-

=))=))
wah kok terlalu mudah y kynya, wkwkwk gpp lah. nambah ilmu dikit. Big Grin

Big Grin






Users browsing this thread: 1 Guest(s)