I'm stuck too. I think that I'll use either (1) r**dp**m.php and SQL injection or (2) sub***p**m*.php and SSI injection...
(1) r**dp**m.php and SQL injection
===============================
No matter what I submit, it always just says "Your poem was successfully added. Thank you for your contributions"
(2) sub***p**m*.php and SSI injection
===============================
No matter what I submit, it always just says "That isn't allowed weirdo"
Is that right?
momumin wrote:So i'm guessing you've found the old page right?
Well first of all you need to find out how the system works , trying making a page, what is the file named as?
*hint* You have to overwrite the homepage using directory transversal.
$filename = $_POST['list'];
$file = "/files/lists/products/" . $filename;
.....
Return to (Real 3) Peace Poetry: HACKED
Users browsing this forum: No registered users and 0 guests