Penetration Testing mailing list archives
Re: How to get a reverse Shell / VNC from a writable directory on a remote web server.
From: "Maarten Hartsuijker" <subscriptions () hartsuijker com>
Date: Sat, 6 Aug 2005 12:09:11 +0200
HI Astrixs,This kind of depends. Are you able to upload scripts to this directory? Are the directories in the executable paths of of the webserver? If you are able to upload PhP/AsP to the directory, and the engine is willing to execute from these directories, you could simply upload the required binaries, write a small asp/php page that runs your binary, and request the page from your webbrowser....
Maarten----- Original Message ----- From: "AsTriXs" <astrixs () gmail com>
To: <pen-test () securityfocus com> Sent: Friday, August 05, 2005 1:02 PMSubject: How to get a reverse Shell / VNC from a writable directory on a remote web server.
Hi, I have found a few writable directories on a remote web server on which I am doing a Pen-Test. How do I setup a reversell of a VNC from this stage? What tools can I use? Does Metasploit provide an option? What would be the procedure to achieve the same? Thanks, -- [AsTriXs] ------------------------------------------------------------------------------ FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't Learn the hacker's secrets that compromise wireless LANs. Secure your WLAN by understanding these threats, available hacking tools and proven countermeasures. Defend your WLAN against man-in-the-Middle attacks and session hijacking, denial-of-service, rogue access points, identity thefts and MAC spoofing. Request your complimentary white paper at: http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801 ------------------------------------------------------------------------------- ------------------------------------------------------------------------------ FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't Learn the hacker's secrets that compromise wireless LANs. Secure your WLAN by understanding these threats, available hacking tools and proven countermeasures. Defend your WLAN against man-in-the-Middle attacks and session hijacking, denial-of-service, rogue access points, identity thefts and MAC spoofing. Request your complimentary white paper at: http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801 -------------------------------------------------------------------------------
Current thread:
- How to get a reverse Shell / VNC from a writable directory on a remote web server. AsTriXs (Aug 05)
- Re: How to get a reverse Shell / VNC from a writable directory on a remote web server. Ricardo Mourato (Aug 06)
- RE: How to get a reverse Shell / VNC from a writable directory on a remote web server. Irene Abezgauz (Aug 06)
- Re: How to get a reverse Shell / VNC from a writable directory on a remote web server. H D Moore (Aug 06)
- Re: How to get a reverse Shell / VNC from a writable directory on a remote web server. Maarten Hartsuijker (Aug 06)