RE: LFI in CGI file help 08-05-2016, 09:13 PM
#10
(08-05-2016, 08:58 PM)Axari Wrote:(08-05-2016, 08:52 PM)meow Wrote:(08-05-2016, 08:44 PM)Axari Wrote: Loud and clear.
Sorry lol, was trying something out.
Anyways, here's an update:
I was able to log into the admin panel of the device. There was an upload form but didn't allow anything except VALID jpeg files (couldn't bypass it, I tried everything I knew). Then after looking around some more I found a page that lets you import/export the system's configuration. I exported it to see if I could put a Perl reverse shell in there and then include it after importing it, however I'm faced with two problems 1. I don't know where the file is located on the fs, so I wouldn't know the path when including the file and 2. I've tried opening the exported configuration file with 2 different programs and its just unreadable shit. I need something that will give it to me in plaintext.
I'm pretty familiar with finding vulns directly in firmware tars, so I could take a look if you have a system firmware image, can extract the binaries and throw them in IDA for a quick looksee.
Nevermind, I fucking finally found a way to execute commands. Thanks for trying to help.

![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)