Conditions:
————–
777 Directory

What Is This:
————–
You Uploaded Shell With With “NoBody” Permission
Let’s Say You Browse To Another Folder Which Is 777 But All Files Are 755 And Belongs To Some User There
To Change Those Files We Do Like This

How To Do It:
—————
Upload Your Own File/Index To That Folder Let’s Say Your Page Called

Evil.php

And The File You Want To Change Is

Index.html

So Execute This:

MV Evil.php Index.html

Explore More

Blind SQL Injection and XSS Vulnerability in MyRingTune

PlanetCreator reported another critical SQL injection (vulnerability) on MyRingTune  URL : http://www.myringtuneonline.com SQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of

Yahoo password recovery method

A friend of ours asked us “is it possible to retrieve yahoo password”. On further discussion we found out that he was waiting to get the password from an old

CRLF Injection

CRLF Injection Overview CRLF Injection is typically used in HTTP Response Splitting. In the HTTP specification there is a spec stating that the HTTP header is to be split from