Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   17722

Ez SHELL UPLOADS FOR ALL GAYS( EXTENDING XSS TO SHELL UPLOAD)

by Pentester708 - 25 November, 2019 - 04:50 PM
This post is by a banned member (lokomokosss) - Unhide
37
Posts
0
Threads
3 Years of service
#41
nice share
This post is by a banned member (nikcho23432) - Unhide
This post is by a banned member (Anurikax) - Unhide
This post is by a banned member (Erraticcoders) - Unhide
16
Posts
0
Threads
4 Years of service
#44
thanks for share
This post is by a banned member (akenov7) - Unhide
akenov7  
Registered
57
Posts
0
Threads
3 Years of service
#45
easy...
This post is by a banned member (initMainPY) - Unhide
This post is by a banned member (Ash707) - Unhide
Ash707  
Registered
18
Posts
0
Threads
3 Years of service
#47
(25 November, 2019 - 04:50 PM)Pentester708 Wrote: Show More
**Extending XSS to upload Shell in a Website By** @Pentester708
 
Been wandering around couple sites(Sunday be like). Found one, vulnerable to XSS.
XSS is much like SQL Injection , it is Javascript Injection(Pretty much straight eh)
 
Now instead of uploading some Phishing , CSRF payloads . I Injected an uploader payload.
The site was not having any upload feature but after i injected my payload, Anyone can upload anything(exe,php,bat,what not) to it, which will be stored and executed on the Server Level.
 
**I wonder what would you guys have uploaded ?**
Well I did the harder part for yal. Play around uploading your shells 
You can get to your uploaded shells by adding its name in the URL after uploading
 
Site Fuzzed:
oky nice
This post is by a banned member (takeover888) - Unhide
7
Posts
0
Threads
2 Years of service
#48
(25 November, 2019 - 04:50 PM)Pentester708 Wrote: Show More
**Extending XSS to upload Shell in a Website By** @Pentester708
 
Been wandering around couple sites(Sunday be like). Found one, vulnerable to XSS.
XSS is much like SQL Injection , it is Javascript Injection(Pretty much straight eh)
 
Now instead of uploading some Phishing , CSRF payloads . I Injected an uploader payload.
The site was not having any upload feature but after i injected my payload, Anyone can upload anything(exe,php,bat,what not) to it, which will be stored and executed on the Server Level.
 
**I wonder what would you guys have uploaded ?**
Well I did the harder part for yal. Play around uploading your shells 
You can get to your uploaded shells by adding its name in the URL after uploading
 
Site Fuzzed:

thx

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)