A basic tool for exploiting vulnerable file uploads WIP. main functionality is complete but need to add options such as passing cookies and other form data
Go to file
witchdocsec f55c52d43a
Update README.md
2024-09-20 10:56:58 +01:00
lib Add files via upload 2024-09-20 10:53:08 +01:00
README.md Update README.md 2024-09-20 10:56:58 +01:00
expload.py Add files via upload 2024-09-20 10:53:08 +01:00

README.md

Expload

image

what is expload

A tool for injecting magic bytes of allowed files, and spoofing the mime type. In order to exploit vulnerable file upload forms that use these as the sole validation mechanism

useage

expload.py [-h] -u URL -p PAYLOAD -e EXT -n NAME -f FILENAME

expload args

options:
  -h, --help            show this help message and exit
  -u URL, --url URL     url to upload to
  -p PAYLOAD, --payload PAYLOAD
                        path to file to upload
  -e EXT, --ext EXT     extension to spoof
  -n NAME, --name NAME  field name for file upload
  -f FILENAME, --filename FILENAME
                        file name to upload with