Uploading a shell to a website through Local File Inclusion [LFI to RCE]

25 12 2009

First of all, this is not my own work, i’m just spreading the word.

Original article can be found here and full credit goes out to the original author.

1 – Introduction

2 – Finding LFI

3 – Checking if proc/self/environ is accessible

4 – Injecting malicious code

5 – Access our shell

6 – Shoutz

Read the rest of this entry »

Advertisements




Discovering and exploiting a remote buffer overflow vulnerability in an FTP server – PART 1

28 11 2009

Hello all, in this tutorial we will learn how to identify a vulnerability in an FTP server through the process of “Fuzzing” which could lead to a DoS or Buffer Overflow vulnerability identification. In this specific part we will use FTPFuzz to crash FileCOPA and identify a vulnerability in the LIST command.

Read the rest of this entry »





SQLmap video tutorial and SQL injection prevention

20 10 2009

Hi all,

I just finished a small video tutorial on using SQLmap to test your web application for SQL injection and automaticly inject it.

It also shortly goes over preventing SQL injection on your website.

Read the rest of this entry »