Rocket Chat
RCE
Ikiwa wewe ni admin ndani ya Rocket Chat unaweza kupata RCE.
Nenda kwenye
Integrations
na uchagueNew Integration
na chagua yoyote:Incoming WebHook
auOutgoing WebHook
./admin/integrations/incoming
Kulingana na docs, zote zinatumia ES2015 / ECMAScript 6 (kimsingi JavaScript) kusindika data. Hivyo hebu tupate rev shell kwa javascript kama:
Sanidi WebHook (kanali na chapisho kama jina la mtumiaji lazima kuwepo):
Sanidi skripti ya WebHook:
Hifadhi mabadiliko
Pata URL ya WebHook iliyoundwa:
Itumie curl na unapaswa kupokea rev shell
Last updated