Based on this Digital Ocean tutorial.
A great article on Ubuntu Community.
Based on this Digital Ocean tutorial.
A great article on Ubuntu Community.
52.197.140.254/are_you_rich/verify.php (maintenant indisponible)
En premier il fallait trouver que le chmap était injectable.
Avec des requêtes du genre:
blahblahblahblah' OR 1 = 1 --| alert("hacked"); |
| # Ruby is our language as asciidoctor is a ruby gem. | |
| lang: ruby | |
| before_install: | |
| - sudo apt-get install pandoc | |
| - gem install asciidoctor | |
| script: | |
| - make | |
| after_success: | |
| - .travis/push.sh | |
| env: |
| export class CanceledError extends Error { | |
| constructor (promise) { | |
| super() | |
| if (Error.captureStackTrace) { | |
| Error.captureStackTrace(this, CanceledError) | |
| } | |
| this.promise = promise | |
| this.isCanceled = true |
I hereby claim:
To claim this, I am signing this object:
| <!-- Unsupported download type. (500 Internal Server Error) --> | |
| <!DOCTYPE html> | |
| <html lang="en"> | |
| <head> | |
| <meta charset="UTF-8" /> | |
| <meta name="robots" content="noindex,nofollow" /> | |
| <meta name="viewport" content="width=device-width,initial-scale=1" /> | |
| <title>Unsupported download type. (500 Internal Server Error)</title> | |
| <link rel="icon" type="image/png" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABwAAAAgCAYAAAABtRhCAAADVUlEQVRIx82XX0jTURTHLYPyqZdefQx66CEo80+aYpoIkqzUikz6Z5klQoWUWYRIJYEUGpQ+lIr9U5dOTLdCtkmWZis3rbnC5fw/neYW002307mX/cZvP3/7o1PwwOdh95x7vnf39zvnd29AgBer2xO6DclAXiMqZAqxIiNIN/IYSUS2BPhjmGATchUxI+ADWiRhpWK7HKuHFVBFdmU5YvnI4grFGCaReF/EBH4KsZlGgj2JBTuCYBWRIYF8YoEOJ6wBt/gEs7mBbyOjQXruPLSdOgPCiEiPSUUHDoL8Ug5IUo9B/d5wrt+G7OAKNrODPuVdB6vRCIzN6SdBlpW9RIgk/1FeAXabzRlrUPVCS/JhbmwudztnGeeH9AyXBIwtmM3wLinZJZHifjHw2V+NBoRh+9ixQrbgbnaSIcl7cGea6hoXQbNe7za241oeO5Z0p42M4BV2EqP2D50wo+6HzvwC6C4sApNOR8cmOrtcnhtj2kYRyC9eBvXzKrBZrXSs72kFd1t3MoKVbMekQkEnSNKOO8fac3LpmK6l1Tl |
Configure ActionController::RequestForgeryProtection for an ApplicationController that does not inherits from ActionController::Base (or any controller that does not include ActionController::RequestForgeryProtection).
This is required since the module is included after the application is loaded, so it does not get configured automatically by the configuration files config/environments/*.rb.