07-04-2008, 02:34 PM
This has to be my biggest exploit for the web. If you get a website that you can upload this to, then view it(the file you uploaded), you are the new owner of the website. Create, edit, delete, edit SQL, download entire web pages, edit .htaccess files, and more. Like an FTP, but in php, and without a pesky password to get around. Just save the .txt file as .php, and upload. Fairly simple. Oh, and one more thing, you can't upload big files.
edit: The file is also called "c99memory.php". It was a big hit, but it died. The file can no longer be found. As far as I know, this is the ONLY upload on the web. The odd thing is, it was never patched...
edit: The file is also called "c99memory.php". It was a big hit, but it died. The file can no longer be found. As far as I know, this is the ONLY upload on the web. The odd thing is, it was never patched...
cool thanks mate have nice day Cya