Dump
Last updated
Last updated
Checking the webpage on port 80:
Now when we download captures and check response on burp suite:
This output is similar to zip command in linux. Now trying command injection with zip
We need to upload these files to get command injection: s.sh:
Now when we hit download capture we get a shell:
Now enumerating /var/www/database we find database.sqlite3
And it has passwords