Feb. 25, 2024, 6:52 a.m. | dollarboysushil

InfoSec Write-ups - Medium infosecwriteups.com

PortSwigger — LAB-6 Remote code execution via polyglot web shell upload (Bug Bounty Prep)[by dollarboysushil]

Link to lab: https://portswigger.net/web-security/file-upload/lab-file-upload-remote-code-execution-via-polyglot-web-shell-upload

For any correction / query /suggestion contact on
Instagram dollarboysushil
Twitter (X) dollarboysushil
Youtube dollarboysushil
Linkedin dollarboysushil
Discord https://discord.gg/5jpkdeVLevel : Intermediate ++ . Highly recommended to solve previous labs

Login with given credentials.

Our Aim is to read content of /home/carlos/secret

Lets upload a random image, intercept the request to understand how webserver is working.

Make sure to check images …

bug bounty cybersecurity ethical hacking portswigger web app security

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Network Security Engineer

@ Meta | Menlo Park, CA | Remote, US

Security Engineer, Investigations - i3

@ Meta | Washington, DC

Threat Investigator- Security Analyst

@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC

Security Operations Engineer II

@ Microsoft | Redmond, Washington, United States

Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas

@ Goldman Sachs | Dallas, Texas, United States