LFI to RCE via access_log injection

LFI Local Upload Form [video]

another video tutorial by AntiSecurity Team
this video still using Tamper Data & /proc/self/environ
but this time we use upload form... :))

big thanks to Vrs-hCk a.k.a ander for the idea ^^



watch the video here
http://pacenoge.org/vid/upload_form.html


download here
http://pacenoge.org/vid/upload_form.swf


upload form script
http://pacenoge.org/tool/upload_form.txt

Comments

Anonymous said…
Where I can find archive "as.php"?
Anonymous said…
thanks gan dari tools ini sa tau banyak tentang lfi :D

its still the best ....
Anonymous said…
by muridmu jimmy :D
evilc0de said…
baguslah kalo video na bermanfaat.. :))
labatterie said…
Thanks gan dari tools ini sa tau banyak tentang ...
Thank you for sharing with us. The content is very good and helpful for me, I learn and know more about it.
Anonymous said…
Page not found, please update the links
Thanks
sohail said…
Assalam-o-alaikum.Thanks Dear.
http://www.equranschool.com/
thanks for sharing these video links contain good and nice videos
Really Great thanks for share this