This post is by a banned member (Pentester708) - Unhide
OP 04 March, 2020 - 03:52 AM
Reply
XSS is much like SQL Injection , it is Javascript Injection(Pretty much straight eh for the newbies)
Now instead of uploading some Phishing , CSRF payloads . I Injected an uploader.php in here.
The site was not having any upload feature previously but after i injected the payload, Anyone can upload anything(exe,php,bat,what not) to it, which will be stored and executed on the Server Level.
I wonder what would you guys have uploaded ?
Well I did the harder part for yal. Play around uploading your shells
You can get to your uploaded shells by adding its name in the URL after uploading
Site:
Hidden Content
You must register or login to view this content.
This post is by a banned member (goodglob) - Unhide
04 March, 2020 - 05:21 AM
Reply
(04 March, 2020 - 03:52 AM)Pentester708 Wrote: Show MoreXSS is much like SQL Injection , it is Javascript Injection(Pretty much straight eh for the newbies)
Now instead of uploading some Phishing , CSRF payloads . I Injected an uploader.php in here.
The site was not having any upload feature previously but after i injected the payload, Anyone can upload anything(exe,php,bat,what not) to it, which will be stored and executed on the Server Level.
I wonder what would you guys have uploaded ?
Well I did the harder part for yal. Play around uploading your shells
You can get to your uploaded shells by adding its name in the URL after uploading
Site:
she sucked on some
This post is by a banned member (thek5m) - Unhide
05 March, 2020 - 04:14 PM
Reply
This post is by a banned member (lurkesastu) - Unhide
03 April, 2020 - 03:31 AM
Reply
This post is by a banned member (copricorn) - Unhide
03 April, 2020 - 06:16 AM
Reply
This post is by a banned member (lollies) - Unhide
05 April, 2020 - 12:18 PM
Reply
This post is by a banned member (donquishoot) - Unhide
05 April, 2020 - 08:44 PM
Reply
(04 March, 2020 - 03:52 AM)Pentester708 Wrote: Show MoreXSS is much like SQL Injection , it is Javascript Injection(Pretty much straight eh for the newbies)
Now instead of uploading some Phishing , CSRF payloads . I Injected an uploader.php in here.
The site was not having any upload feature previously but after i injected the payload, Anyone can upload anything(exe,php,bat,what not) to it, which will be stored and executed on the Server Level.
I wonder what would you guys have uploaded ?
Well I did the harder part for yal. Play around uploading your shells
You can get to your uploaded shells by adding its name in the URL after uploading
Site:
thanks
This post is by a banned member (warsoft) - Unhide
10 April, 2020 - 10:59 AM
Reply
|