Rating:
data:image/s3,"s3://crabby-images/795f7/795f74caedc3a8daa7750d451c68450cf17beea3" alt=""
# Upload(web)
url : http://198.211.100.125:8080/upload.php
After every hit-end trial method of uploading php code with different extensions. file Upload successfully with different php extensions (`php2, .php3, .php4, .php5, .php6, .php7, .phps, .pht, .phtml, .pgif, .shtml, .htaccess, .phar, .inc`) but code not work.
may be it is due to the **.htaccess protection**.
and this **upload.php** file always **overwrite** the existing file during uploading in directory.
so i decided to change the content **under .htaccess**.
than i make a **.htaccess** file with configuration.
```AddType application/x-httpd-php .png```
The above configuration would instruct the Apache HTTP Server to execute PNG images as though they were PHP scripts
**.htaccess** uploading success(hurray .htaccess file overwrited with our conf)data:image/s3,"s3://crabby-images/7622c/7622c98f63970cd9958df3b7a58172ca6298e518" alt=""
data:image/s3,"s3://crabby-images/289bb/289bb3d7784b3d7169680cc22c8be56349ad57c9" alt=""
----
lets upload the php code with .png extension and donot forgot to change content-type in burpsuite while uploading
```Content-Type: application/x-httpd-php```
data:image/s3,"s3://crabby-images/c3c30/c3c30eee4547706e348bff44e30c60204ddd9cbc" alt=""
data:image/s3,"s3://crabby-images/7d08c/7d08cc7017a1a473b003eb174165c0fe3d0f404b" alt=""
data:image/s3,"s3://crabby-images/e2c5a/e2c5a557d935a462cc40e5352a6bb82a341cdf75" alt=""
# flag : b00t2root{remote_code_execution_vulnerability}