Ranter
Join devRant
Do all the things like
				++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
				Sign Up
			Pipeless API
 
				From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
				Learn More
			Comments
		- 
				
				 rozzzly16689yc99.php? (or one of its siblings) I remember finding that whilst doing a freelance audit for a image hosting site vulnerable to LFI & RFI (basically you could upload any php script if you rename it `my-legit-photo-nothing-suspicious.png` and the server would just run the script. rozzzly16689yc99.php? (or one of its siblings) I remember finding that whilst doing a freelance audit for a image hosting site vulnerable to LFI & RFI (basically you could upload any php script if you rename it `my-legit-photo-nothing-suspicious.png` and the server would just run the script.
- 
				
				 rozzzly16689yDamn that was years ago.. I wonder what the equivalent is today. I'd bet you good money someone out the has a nice box-decimating dashboard with a pretty minimalistic, responsive material design powered by react, redux, and of course developer's tears. rozzzly16689yDamn that was years ago.. I wonder what the equivalent is today. I'd bet you good money someone out the has a nice box-decimating dashboard with a pretty minimalistic, responsive material design powered by react, redux, and of course developer's tears.
 
 I knew of a guy who supposedly made several grand selling script kiddies a mod of c99 (which src was public) tht had jQuery plugins inlined.
 "use a file browser on their victim!" It even had a progress bar animation!
 
 Totally worth 30$, right?
Related Rants
- 
						
							 Nullfrog17When I was in my second semester of college I was tasked with creating a file encrypt/decrypt program. Take in... Nullfrog17When I was in my second semester of college I was tasked with creating a file encrypt/decrypt program. Take in...
- 
						
							terrabyte6First day at my first workplace as a dev. waiting for my laptop to load up, nothing happens, black screen. wai...
- 
						
							 linuxaddict21 linuxaddict21 The Perfect Storm:
My worst coding mistake? Yeah, let me tell you about that. I pushed a simple JavaScript/HT... The Perfect Storm:
My worst coding mistake? Yeah, let me tell you about that. I pushed a simple JavaScript/HT...


My biggest mistake was that I didn't check the file extension of a uploaded file. Or more correctly forgot that I turned it off for debugging and pushed the app to production.
Somebody noticed an uploaded a hacker php script and got access to all the files on the server. Including some semi sensetive clients information.
A talk with the client that followed was not a pleasant one
undefined
wk8