Skip to content

Instantly share code, notes, and snippets.

@QGB
Created May 17, 2019 09:02
Show Gist options
  • Save QGB/2c561a681d50b9ab723e1fd3cc6a455e to your computer and use it in GitHub Desktop.
Save QGB/2c561a681d50b9ab723e1fd3cc6a455e to your computer and use it in GitHub Desktop.
http://192.168.1.111:23571/response.headers['Content-Type']='text/html';
response.headers['X-XSS-Protection']=0;
r='''
<form method="post" action="http://192.168.1.111:23571/r=request.get_data">
<input type="text" name="t">
<input type="file" name="f">
<input type="submit" />
</form>
'''
@QGB
Copy link
Author

QGB commented Sep 12, 2019

url=rf"""http://{ip}:23571/sys.a=r=T.json_loads(request.get_data());r=len(r)"""
import ast,requests
r=requests.post(url,json=duxa)
print(r.text)

@QGB
Copy link
Author

QGB commented Nov 16, 2019

app=_2[1]
execLocals=U.getDictItem( app._error_handlers[404] ) [1].closure[0].cell_contents.closure[3].cell_contents

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment