Log Poisoning
User-Agent
poisoning:
User-Agent
poisoning:allow_url_fopen
needs to beOn
If the
access_log
is exposed and the server is not properly sanitizing or validating theUser-Agent
:
From here, just visit the
URL
Use
ping
to check if it's possible to generate outbound network traffic back to the host:
Catch it with
tcpmdump
Get a reverse shell:
Last updated