14.4.2
Earlier, we used the escape variable to detect if the target is running EJS. We can also use this variable to obtain RCE with some additional payload modifications. Find how to obtain RCE by pollut...
Read More
14.2.3 (P)
Find a value (other than toString) that will crash the application when it is set in the prototype.
Read More
13.7.1
The current reverse shell isn't fully interactive and can cause the gateway to hang. Upgrade to a fully interactive shell.
Read More
13.6.2
Create a web server in your choice of programming language to handle the JavaScript callbacks and automatically URL-decode the data.
Read More
13.6.1
Modify the JavaScript function to avoid data truncation by sending the data in multiple requests if the data is longer than 1024 characters.
Read More
13.4.5 (Incomplete)
Create a second script that enumerates based on host name. Try using the script to identify the live hosts.
Read More