Http://itsecuritylab.eu/index.php/2010/07/05/hide-shell-in-a-target-system/
It seems that you like shell very much. It's cute and happy. Next we will introduce a method to hide shell. htaccess attack.
This must be an Apache server.
Click it to edit the Apache configuration file. The target system is centos5.6 apache2.
[root@localhost ~] # vi /etc/httpd/conf/httpd.conf |
Make Apache support for. htaccess
< Directory
/var/www/> Options Indexes FollowSymLinks MultiViews
AllowOverride All
Order allow,deny
allow from all
</ Directory > |
Restart the apache service, upload the file to the Web server and directory, and download the file:
Sorry, you can only read the hidden content if you have commented on this article.
After the download, the upload name will be:. htaccess
Then run the following command:
Of course, you can modify the code and create a reverse shell.
More here: https://github.com/wireghoul/htshells