Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!

cracked.io | Best Forum Around | Free Premium Accounts




 17310

Ez SHELL UPLOADS FOR ALL GAYS( EXTENDING XSS TO SHELL UPLOAD)

by Pentester708 - 25 November, 2019 - 04:50 PM
This post is by a banned member (Pentester708) - Unhide
653
Posts
482
Threads
4 Years of service
#1
**Extending XSS to upload Shell in a Website By** @Pentester708
 
Been wandering around couple sites(Sunday be like). Found one, vulnerable to XSS.
XSS is much like SQL Injection , it is Javascript Injection(Pretty much straight eh)
 
Now instead of uploading some Phishing , CSRF payloads . I Injected an uploader payload.
The site was not having any upload feature but after i injected my payload, Anyone can upload anything(exe,php,bat,what not) to it, which will be stored and executed on the Server Level.
 
**I wonder what would you guys have uploaded ?**
Well I did the harder part for yal. Play around uploading your shells 
You can get to your uploaded shells by adding its name in the URL after uploading
 
Site Fuzzed:
Hidden Content
You must register or login to view this content.

[Image: Udpc9Lb.gif]
Telegram: https://t.me/candycainlobbies
Ad by brocain
This post is by a banned member (s1gn0) - Unhide
s1gn0  
Registered
3
Posts
0
Threads
4 Years of service
#2
thanks for share
This post is by a banned member (blackstroomma) - Unhide
This post is by a banned member (SynnX) - Unhide
SynnX  
Registered
32
Posts
0
Threads
4 Years of service
#4
(This post was last modified: 26 November, 2019 - 01:28 AM by SynnX.)
444444444444444444444444444

9999999999999999999999999
This post is by a banned member (MrAltai) - Unhide
MrAltai  
Registered
1
Posts
0
Threads
4 Years of service
#5
thanks
This post is by a banned member (macraf55) - Unhide
This post is by a banned member (xtrangemaster) - Unhide
10
Posts
0
Threads
4 Years of service
#7
(This post was last modified: 29 November, 2019 - 12:04 PM by xtrangemaster.)
Nice one keeeep it upp

Thanks for the this really appreciated. Thanks
This post is by a banned member (Jasonpin14) - Unhide

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)