A basic tool for exploiting vulnerable file uploads WIP. main functionality is complete but need to add options such as passing cookies and other form data
Go to file
witchdocsec e827a58aa5
Update README.md
2024-09-24 20:36:02 +01:00
exploadlib Update parse.py 2024-09-24 20:34:54 +01:00
README.md Update README.md 2024-09-24 20:36:02 +01:00
expload.py Update expload.py 2024-09-24 20:34:36 +01:00
r.txt Create r.txt 2024-09-21 12:02:46 +01:00

README.md

Expload

image

what is expload

A tool for injecting magic bytes of allowed files, and spoofing the mime type. In order to exploit vulnerable file upload forms that use these as the sole validation mechanism

useage

expload.py [-h] -u URL -p PAYLOAD -e EXT -n NAME -f FILENAME [-d] [-h2] [-he HEADERS [HEADERS ...]] [-c COOKIES] [-r]

expload args

options:
  -h, --help            show this help message and exit
  -u URL, --url URL     url to upload to
  -p PAYLOAD, --payload PAYLOAD
                        path to file to upload
  -e EXT, --ext EXT     extension to spoof
  -n NAME, --name NAME  field name for file upload
  -f FILENAME, --filename FILENAME
                        file name to upload with
  -d, --doubleextend    spoofed extension inserted into filename
  -h2, --http2          use http2 if supported
  -he HEADERS [HEADERS ...], --headers HEADERS [HEADERS ...]
                        headers and keys colon seperated
  -c COOKIES, --cookies COOKIES
                        cookies seperated by ; and wrapped in quotes
  -r, --response        display the response from the target webapp