Hey guys,
had my first success on trying to crack our school network:
Our IT-Teacher gave us the pass for a user on the mainserver so we can upload our homepages to the server. I persuaded our teacher to allow PHP sites for executing and uploaded an php file wich i can use to run sh-commands on the server.
There are no special limits for commands running via php set, so i made it to get the full tree of the server and walk into almost every folder (except some special,no whole user).
But now I'm trying to write this php file into the admins public_html folder (so i can run it on the internet as the admin), but I get always an "Permission denied".
Btw,I tried it with "echo SOURCECODE > runit.php".
So, is there a way how i could bypass this "Permission denied" ?
some additional info: access to 6 normal users,all rights set to "rwxr-xr-x",the server is Ubuntu/Apache, the automatically used shell is sh
Node: Linux
Release: www
Version: 2.6.32-33-386
Machine: #72-Ubuntu SMP
Processor: i686
Hostname: www