Symlink (PHP) Exploit
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Tutorial Name: Symlink (PHP) Exploit [Private (PhP Code)For Sometimes]
Author: dREviL
*Dont Share without credits*
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
First of all we use symlink to read config file of other sites hosted in the same servers . Symlinkung can be done in many methods , and today i will show a new one that was private for sometimes and now its shared . In this tuto we will excecute a php(Eval Code) to symlink in a shared hosting . Let'Begin .We need a shell that allwows php eval code excecuting. First we get the full path of root /home/r00tb0x/public_html .And now the php code
Now lets Edit Some Lines Of The Code.In the $filepath='/home/username/public_html/txtfile'; replace username with the username of the target website hosted in the same server...Then replace the txtfile with the txt file.txt u created for reading config..$writeblefilepath here u must enter ur writable path..From here u will be able to explore other sites hosted in the same server ..
Hope u Understand me !!!
Tutorial Name: Symlink (PHP) Exploit [Private (PhP Code)For Sometimes]
Author: dREviL
*Dont Share without credits*
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
First of all we use symlink to read config file of other sites hosted in the same servers . Symlinkung can be done in many methods , and today i will show a new one that was private for sometimes and now its shared . In this tuto we will excecute a php(Eval Code) to symlink in a shared hosting . Let'Begin .We need a shell that allwows php eval code excecuting. First we get the full path of root /home/r00tb0x/public_html .And now the php code
Code:
$filepath='/home/username/public_html/txtfile';
$sitepath='/home/edit/public_html/';
$writeblefilepath='myfile.txt';$flib=$sitepath.$wr iteblefilepath;
@unlink($flib);
symlink($filepath, $flib);
echo readlink($flib) . "\n";
echo "
Hope u Understand me !!!