Remote Code Execution via Polyglot Web Shell Upload | PortSwigger (Video solution)

Опубликовано: 31 Октябрь 2024
на канале: Bnke
1,789
7

This Video Shows the Lab Solution of a vulnerable image upload function. Although it checks the contents of the file to verify that it is a genuine image, it is still possible to upload and execute server-side code.

To solve the lab, upload a basic PHP web shell, then use it to exfiltrate the contents of the file /home/carlos/secret. Submit this secret using the button provided in the lab banner.

You can log in to your own account using the following credentials: wiener:peter