• caglararli@hotmail.com
  • 05386281520

PHP embedded within PNG is not executing rather randering in IIS but executes in Apache

Çağlar Arlı      -    40 Views

PHP embedded within PNG is not executing rather randering in IIS but executes in Apache

I am pentesting a site with all permissions. I have been able to upload a PHP shell embedded within a png image. I have also been able to change the extension of the file like something.php. So my question is when I run this file in my xamp local server. It renders some gibberish text and then executes the PHP code. But when I upload the same file to the remote IIS server I'm pentesting, It just renders some gibberish text? rather than executing the PHP code. Why is that and how can I bypass it?

N.B I can upload any file extension I want. I have exploited that part. Now I need to run the code I uploaded which is where I'm struggling...

After I upload and hit the uploaded file path. The output: enter image description here

The request it is sending intercepted by the burp: enter image description here