Results 1 to 10 of 70
Threaded View
-
25th Sep 2009, 11:03 AM #11
BannedWebsite's:
Dev-Security.netWell darn
Ok @ deviance on some servers i have it compiled with php4 + php5 and enhanced the security on both of them
The reason as to why i think it is blocking it is because of mycrypt i dont fully understand it yet but by the looks of it it looks like its checking bytes by 29 and 36 or 30 if you run a script and it doesnt compare to those it does not execute
by using ../../../../ it will block it but if we encode you can try and use
%20/% followed by the /etc/passwd
Thats just a theory if we take a look at how the transversial is even executing we can look here
If we tried to inject this code onto ?wwwRoot it would not work why? beacuse wwwRoot is basically a addon to the variables to config.php killthread.php and basedir so if executing a load o f include functions of config / killthread was not found
But in the variable baseDir it connects all the variables together making it the big guy
Code:$baseDir = substr($wwwRoot, 0, ##BASEDIR##); require($baseDir . 'funcs.inc'); require($baseDir . 'config.php');
Any other ideas can be great i will be testing this script for javascript injection and other stuff later on today
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Help with DDLCMS
By Darkstar in forum Forum and DDL DiscussionReplies: 11Last Post: 23rd May 2011, 07:54 AM -
DDLCMS 3.2 help
By FuBu in forum Forum and DDL DiscussionReplies: 2Last Post: 16th Apr 2011, 02:52 PM -
help with ddlcms!
By cyber-cliff in forum Technical Help Desk SupportReplies: 5Last Post: 18th Feb 2011, 04:14 PM -
DDLCMS Someone help?
By lonerunner in forum Forum and DDL DiscussionReplies: 18Last Post: 18th Nov 2009, 01:20 AM










Register To Reply

Staff Online
themaCreator - create posts from...
Version 3.55 released. Open older version (or...