I am auditing an Upload form where the company allows users to upload some PDF books .I was able to upload aspcmd.asp shell but when i am trying to acces the shell the file aspcmd.asp gets downloaded .. the aspcmd.asp is uploaded to /Images/ folder . Is it possible that in the /Images/ folder where the shell gets uploaded have been made some Restrictions that only download/upload s possible. ? are there anny methods to bypass this restrictions ? Web.config file are anny other options ?
Читать полностью…Just cleared my draft. Have a read https://vijetareigns.medium.com/pii-disclosure-worth-750-758b72e7e8ca
Читать полностью…https://securitytrails.com/blog/ip-address-behind-cloudflare
https://blog.christophetd.fr/bypassing-cloudflare-using-internet-wide-scan-data/
bobby.S/how-to-find-origin-ip-1f684f459942" rel="nofollow">https://medium.com/@bobby.S/how-to-find-origin-ip-1f684f459942
Bypassing WAF to find the original ip in brief:✅
→RUN http://shodan.io or http://censys.io
→Search SPF records and TXT records.
→Also can check http://securitytrails.com in field Historical data might have original IP in old records.
#cloudflare
Try this app it is for beginners, you can learn bug hunting
https://play.google.com/store/apps/details?id=com.defensiveinet.bugbountyacademy
Try path traversal in filename like ../shell.asp and make it upload on the site's root or in some other directory where asp execution is configured
Читать полностью…https://aliexpress.ru/store/5362003?spm=a2g2w.orderlist.0.0.30a04aa6twny7Z&newStore=true
Читать полностью…Hello,
I’m looking for an Ubuntu Server Expert who have a deep knowledge of setting up a mail server in Ubuntu.
Drop me a message with your CV in my DM.