Glad you like it! Try it out and let us know if you had success with it 💪
@asaad0x2 жыл бұрын
I have said before on another video i guess .. but u look things looks so easy and simple even though they are not 😁❤️ everytime i watch your videos i think like wow how i didn't get that idea .. learned a new usage of exiftool today from you . thank you so much for the amazing content ❤️❤️
@intigriti2 жыл бұрын
Thanks so much 😊 We really appreciate your nice words 😍 Keep learning!!
@khaledselim98352 жыл бұрын
b3d el klmten dol mfesh mnak amal brdo 3iel ga7sh :D
@hybridsh4d0w2 жыл бұрын
love the qualitiy of your burpsuite content - my sub is here :)
@intigriti2 жыл бұрын
Awesome, thank you! We are glad to have you around! 😇
@costycrypto5010 Жыл бұрын
Thanks for your effort!
@intigriti Жыл бұрын
🙏🥰
@vilislacis3337 Жыл бұрын
I had trouble with EXIFTOOL, it would complain if there was anything inside . Instead I edited metadata via Windows Explorer > Right click > Details > Title. After I ran uploaded file, the output looked garbled, but inside it there was a 32 string, which is the same length as the codes in previous labs. I tried it and the code was accepted!
@intigriti Жыл бұрын
Nice! exiftool should work as well, maybe try to wrap the payload in single quotes next time, if you didn't already 🤔
@eduardprivat98216 ай бұрын
but for better understanding: it is not possible to let the OS execute that comment in the image.png file if we say that the comment is a compiled c binary who do the same as that php file_gets_content function does?
@eforever2715 күн бұрын
Thanks.
@intigriti15 күн бұрын
Welcome! 💜
@dizonnicolefranza.41812 жыл бұрын
can you make a video about API thank you
@ulrikmagana2 жыл бұрын
Thank you for making such an informative video. I keep having this error on my cmd Error: Error creating file: C:/example.png_exiftool_tmp - C:/example.png 0 image files updated 1 files weren't updated due to errors what could be a good way to fix it?
@intigriti2 жыл бұрын
What is the command that you run?
@njay57742 жыл бұрын
You're trying to upload the file from a secure directory such as the windows, C:, or a root directory on your pc. To fix this , I suggest running command prompt as an administrator or running the command for another sub-directory like C:\Users\\Pictures. It will definitely work.
@novanuke13562 жыл бұрын
I was running into a similar issue. the output file name already existed
@ponyride232 жыл бұрын
My php's MIME type is HTML in Burp Suite, but exiftool shows MIME type as image/png.... what am I doing wrong? :(
@intigriti2 жыл бұрын
Can you share the mm:ss timemark where you are having troubles? Are you following the exact steps we were taking?
@homeboydog2 жыл бұрын
The issue if you're using burp suite community the free edition is that you are using a PNG file in the first place, save an image as jpg and then go through this process with that. This is due to burp's proxy running on Chromium. Took me many hours to get to this point lol
@henrycharriere2 жыл бұрын
Nice video!! if a put um reserve shell, its work? tks...
@intigriti2 жыл бұрын
thanks 💪
@jaitavyamishra81385 ай бұрын
do i need to install exiftool for it's a command any one can help me
@intigriti5 ай бұрын
If you are using an OS like Kali Linux it is probably pre-installed. Otherwise, try and run "sudo apt-get install exiftool"
@SuperTechrobin2 жыл бұрын
Nice video
@intigriti2 жыл бұрын
Thanks 💪
@ravi.dissanayake2 жыл бұрын
😍
@intigriti2 жыл бұрын
Thank you very much ❤️
@rahiislam36362 жыл бұрын
😊😊
@intigriti2 жыл бұрын
😇 Thanks for watching!
@MikelLabouf Жыл бұрын
This example doesn't work in real world applications, it only works on your script kiddy testing platforms, the first thing that real world apps process is the file extension, if the file extension is blacklisted, it won't work, if you change the file extension through burp proxy from php to jpg, the code will be uploaded but not executed.
@intigriti Жыл бұрын
It is indeed rarely seen nowadays, but was a very common vulnerability 10+ years ago. It's still worth testing for it as it comes with no effort and might still work in some apps.
@nishantdalvi947010 ай бұрын
Daam ...! this comment lowered my motivation and willingness to explore further labs : (