Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow Web app attacks and using web shells
EH-Net
May 18, 2013, 07:03:13 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: Web app attacks and using web shells  (Read 20684 times)
0 Members and 1 Guest are viewing this topic.
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« on: August 31, 2009, 10:47:37 AM »

Awesome paper:

http://www.phx2600.org/archive/2009/08/13/new-paper-by-evil1/

Quote
Yessir, I busted my ass hump to pump out another paper. 40 pages of ownage, awesome, and win.
Download it here.

The paper covers web shells in PHP, ASP, JSP, Coldfusion, and Perl as well as hacking techniques for auditing each language (brief, but to the point).

If you have any questions about the paper, email me. Contact info on the site / in the paper.
Logged

chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #1 on: August 31, 2009, 11:53:50 AM »

Does he ever release in PDF format? Call me paranoid, but I don't like downloading .doc files from the interwebs. Smiley
Logged

OSWP, Sec+
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #2 on: August 31, 2009, 12:55:48 PM »

And PDFs don't make you paranoid?  Wink

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #3 on: August 31, 2009, 05:53:31 PM »

And PDFs don't make you paranoid?  Wink

Don

Not as paranoid, I know about word macros and the easiness of having the word doc do other things. The pdf as an entry vector I don't know about. Doesn't mean it doesn't exist, just that I have more to learn.
Logged

OSWP, Sec+
Evil1
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #4 on: August 31, 2009, 06:27:25 PM »

You're right don. Here it is in PDF form. http://www.wtfchan.org/~evil1/Web-Shells-rev2.pdf
Logged
UNIX
Hero Member
*****
Offline Offline

Posts: 1234


View Profile
« Reply #5 on: September 01, 2009, 12:27:54 AM »

[...] The pdf as an entry vector I don't know about. Doesn't mean it doesn't exist, just that I have more to learn.

In the past there were several vulnerabilities found in pdf, often also critical ones. I too would say that doc offers more space for malicious actions though. But anyway, it would be naive to think that nothing malicious can happen when opening a pdf-file.

Thanks for the paper, looks interesting.
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #6 on: September 01, 2009, 02:48:42 AM »

Paranoia aside, the paper is good reading. Web apps aren't my area of expertise but found the information very easy to understand, and with a quick play in my lab over the weekend, very easy to put into practice.

Nice work Evil1

<edited> (bold) to stop me lying (typo)</edit>
« Last Edit: January 20, 2011, 04:46:56 PM by Andrew Waite » Logged

Agoonie
Full Member
***
Offline Offline

Posts: 176



View Profile WWW
« Reply #7 on: January 20, 2011, 10:41:50 AM »

Does anyone have a copy of that pdf?  The link is down: http://www.wtfchan.org/~evil1/Web-Shells-rev2.pdf
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
Data_Raid
Full Member
***
Offline Offline

Posts: 165



View Profile
« Reply #8 on: January 20, 2011, 10:50:30 AM »

Here you go KillJ0y:

http://hotfile.com/dl/98403978/f9fa519/Web-Shells-rev2.pdf.html

and http://www.megaupload.com/?d=MU3D86F9

and http://www.fileserve.com/file/6bu3QwV
« Last Edit: January 21, 2011, 04:40:41 AM by Data_Raid » Logged

All men by nature desire knowledge.

Aristotle
Agoonie
Full Member
***
Offline Offline

Posts: 176



View Profile WWW
« Reply #9 on: January 20, 2011, 11:58:13 AM »

Thanks!! Just doing some research on some web exploits.   I saw that Jhaddix provided some info but the link didn't work.  Thanks again. Hopefully it is something else I can use in the OSCP course.  =-)
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
Data_Raid
Full Member
***
Offline Offline

Posts: 165



View Profile
« Reply #10 on: January 20, 2011, 12:35:51 PM »

No worries, the PDF will definitely come in handy for the OSCP  Wink
Logged

All men by nature desire knowledge.

Aristotle
T_Bone
Full Member
***
Offline Offline

Posts: 199


View Profile
« Reply #11 on: January 20, 2011, 03:36:41 PM »

This paper sounds cool but don't seem to be able to download it?
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #12 on: January 20, 2011, 04:49:07 PM »

This paper sounds cool but don't seem to be able to download it?

Really? Data_Raid's rapidshare link worked for me. I can mirror elsewhere if you're still having problems...
Logged

T_Bone
Full Member
***
Offline Offline

Posts: 199


View Profile
« Reply #13 on: January 21, 2011, 03:59:51 AM »

@ Andrew

Yeah it appears to no longer be available for download on the rapidshare site...  Sad
Logged
Data_Raid
Full Member
***
Offline Offline

Posts: 165



View Profile
« Reply #14 on: January 21, 2011, 04:42:32 AM »

I've removed the rapidshare link (max of 10 download limit reached) and I have added some additional links in my post above: http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,4571.msg35138/#msg35138.

Hopefully those links will suffice  Smiley
« Last Edit: January 21, 2011, 04:44:12 AM by Data_Raid » Logged

All men by nature desire knowledge.

Aristotle
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.095 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.