banner
[面包]MrTwoC

[面包]MrTwoC

你好,欢迎来到这个基于区块链的个人博客 名字:面包 / MrTwoc 爱好:跑步(5/10KM)、咖啡、游戏(MMORPG、FPS、Minecraft、Warframe) 兴趣方向:Rust、区块链、网络安全、量子信息(量子计算)、游戏设计与开发
bilibili
steam
email
github

File Upload && BrupSuite

Difficulty: medium

image.png
When I saw the source code, it restricted the upload type.
image.png
So I opened brupSuite
Enabled interception, and then uploaded a webshell:

Copy the code into a txt file, then change the extension to php, and you will have a webshell file.

Here it is intercepted
image.png
Change Content-Type to:
image/png
Then allow it, and the upload is successful
image.png
Then follow the upload address and enter the link:
http://192.168.1.2/dvwa/hackable/uploads/111.php
It shows a blank screen, indicating successful exploitation
Open AntSword, enter the address, password: pass
image.png
image.png
Double-click to see the website structure and the files it contains
image.png

Loading...
Ownership of this post data is guaranteed by blockchain and smart contracts to the creator alone.