03.12.2015 Views

lab writeup

TL8_WU_en

TL8_WU_en

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Sending the request, and:<br />

That does give us a hope. If the PHP file was indeed uploaded, the code<br />

probably failed to use it to generate a profile picture thumbnail and ended<br />

up with an error. According to IMG src attribute, the files end up in /<br />

uploads subfolder. Let’s try https://192.168.101.6/uploads/shell.php:<br />

Page<br />

20 of 22

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!