PHP Exploitation



Hi experts, i need your ideas,

By now, i am able to upload php files to a Windows 2003 Server, so i
can execute php code like phpinfo, but i cant execute passthru command
because of lack of IUSR_MACHINE privileges.
I have run some local php bof's without success.

Do you have another idea to break into the server through php code uploaded?

Cheers!!!!!

--
Danux, CISSP
Chief Information Security Officer
Macula Security Consulting Group
www.macula-group.com

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: [PHP] PHP Performance and System Load
    ... reasonably simple mod_rewrite is the difference that is killing your server ... to the time taken to parse code, hit the database, hit the disk, etc. ... Opcode cache is good, but if you can give it less to cache that ... PHP code itself is not the bottleneck but the server configuration, ...
    (php.general)
  • Re: redirect / new website how to redirect old (google) links to new site ?
    ... Configure your server to parse .html files for PHP. ... It's unnecessary overhead to parse static html files for PHP code. ...
    (comp.lang.php)
  • Re: PHP Driven Site responding slow on different networks.
    ... > would say there's something in the PHP code. ... IIS nor PHP but a network issue. ... >>server is about 20 times slower. ... >>except for the IIS server and I still get the same results. ...
    (comp.lang.php)
  • Re: SSL php code
    ... but the server HTTPS variable ... >2) You might consider logging a protocol failure whenever the redirect ... an error message) is output before the ... I want some standardized php code on every page to verify with every hit that it is being accessed ...
    (comp.lang.php)
  • Re: permission denied - PHP code
    ... >>I write a short PHP code that works fine on my own apache server, ... >> doesn't work after I upload it to the university server. ... also write PHP code to access MySQL database successfully. ... same code works well on my own apache server. ...
    (alt.os.linux)