Forum     

Go Back   Digit Technology Discussion Forum > Software > Programming
Register FAQ Calendar Mark Forums Read

Programming The destination for developers - C, C++, Java, Python and the lot


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 22-06-2009, 11:02 AM   #1 (permalink)
In The Zone
 
Yoda's Avatar
 
Join Date: Jul 2004
Posts: 211
Default How to create a file 403: Fordibben folder (Ethical Hacking)


Hi Friends,

This is purely Ethical hacking and it is a test for me. so please help me in this issue. its urgent.

I want to create a File / Folder in the Web Server that has got vulnerabilities.

Example host:
Code:
http://101.120.27.21/

Server Type: Microsoft-IIS/6.0
Server Side: PHP/ASP
Application Server: PHP
Web Server: IIS, IIS6


Note: The website / webserver has got lots of vulnerabilities like Blind SQL Injection, Cross-Site Scripting, PHP Remote File Inclusion, SQL Injection, Stored Cross-Site Scripting, Windows File Parameter Alteration, Link Injection (facilitates Cross-Site Request Forgery), Unencrypted Login Request etc....


Now I want to create a Folder and remote upload a File under the gulli_database. The "gulli_database" folder is write protected / 403: Forbidden.

Please help me how to create a Folder and remote upload the file under "gulli_database" directory. Is there any scripts / exploits to bypass the the folder protection and write in the folder.

please guide me how to go about.

Exampel URL:
Code:
http://101.120.27.21/gulli_database/

Thanks and Regards
Yoda
Yoda is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 22-06-2009, 04:32 PM   #2 (permalink)
Addicted to FOSS
 
ManishSinha's Avatar
 
Join Date: Jan 2008
Location: Manipal
Posts: 32
Default Re: How to create a file 403: Fordibben folder (Ethical Hacking)

Write protected for which user? The user under which IIS is runnning?
ManishSinha is offline  
Old 22-06-2009, 07:39 PM   #3 (permalink)
In The Zone
 
Yoda's Avatar
 
Join Date: Jul 2004
Posts: 211
Default Re: How to create a file 403: Fordibben folder (Ethical Hacking)

The File and folder should be uploaded remotely. The gulli_database/ is Forbidden / Write Protected for any users. Only admins can write inside the folder. Anonymously I have to bypass it and write into that folder "gulli_database/"

The "gulli_database" folder is write protected / 403: Forbidden. I tried the http put/mkcol methods but doesnt work. i can view the contents of the directory. there is a guest book "comment" field where scripts can be injected.

i am connecting to my remote server. webdav is enable but put and mkcol method is disabled. there is also a guest book that is vulnerable to injection.
Yoda is offline  
Old 23-06-2009, 11:44 PM   #4 (permalink)
Human Spambot
 
shantanu's Avatar
 
Join Date: Dec 2006
Posts: 2,798
Default Re: How to create a file 403: Fordibben folder (Ethical Hacking)

yoda : try not to press the submit button again & again if your connection goes into a timeout.. doublepost removed..
shantanu is offline  
Old 24-06-2009, 01:00 PM   #5 (permalink)
In The Zone
 
Yoda's Avatar
 
Join Date: Jul 2004
Posts: 211
Default Re: How to create a file 403: Fordibben folder (Ethical Hacking)

Now I have the Admin user name and pass of http://101.120.27.21/

Server Type: Microsoft-IIS/6.0
Server Side: PHP/ASP
Application Server: PHP
Web Server: IIS, IIS6


Now I need to upload a file from my local system C:\test.txt to http://101.120.27.21/gulli_database/

First I need to remotely login as admin to the remote webserver and then copy a text file from the local system (C:\text.txt) to the remote folder http://101.120.27.21/gulli_database/

If I don't login as admin I get "Access Denied" Error Message when I copy a txt file to gulli_database. How to login into remote web server as admin

What type of connection should I use. Will "Net Use" commands help or should I try thru. FTP / Telnet.

which method will be sucessfull Net Use commands / Telnet / FTP

please give me syntax and commands for NET USE commands / FTP / Telnet

Step 1. Login to remote web server as admin from my Local System
Step 2. copy C:\text.txt to http://101.120.27.21/gulli_database/ and create a Folder name "Test" under http://101.120.27.21/gulli_database/

Please guide me in this regard

Thanks and Regards
Rafales
Yoda is offline  
Old 24-06-2009, 01:01 PM   #6 (permalink)
In The Zone
 
Yoda's Avatar
 
Join Date: Jul 2004
Posts: 211
Default Re: How to create a file 403: Fordibben folder (Ethical Hacking)

Now I have the Admin user name and pass of http://101.120.27.21/

Server Type: Microsoft-IIS/6.0
Server Side: PHP/ASP
Application Server: PHP
Web Server: IIS, IIS6


Now I need to upload a file from my local system C:\test.txt to http://101.120.27.21/gulli_database/

First I need to remotely login as admin to the remote webserver and then copy a text file from the local system (C:\text.txt) to the remote folder http://101.120.27.21/gulli_database/

If I don't login as admin I get "Access Denied" Error Message when I copy a txt file to gulli_database. How to login into remote web server as admin

What type of connection should I use. Will "Net Use" commands help or should I try thru. FTP / Telnet.

which method will be sucessfull Net Use commands / Telnet / FTP

please give me syntax and commands for NET USE commands / FTP / Telnet

Step 1. Login to remote web server as admin from my Local System
Step 2. copy C:\text.txt to http://101.120.27.21/gulli_database/ and create a Folder name "Test" under http://101.120.27.21/gulli_database/

Please guide me in this regard

Thanks and Regards
Rafales
Yoda is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Sujeet
- by gforz
- by soumya

Advertisement




All times are GMT +5.5. The time now is 03:14 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2