Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
slow_typist
6mo ago
0 comments
Share
Humans have to put the so called php-file on the server intentionally for any subsequent attack to work. But it is a binary file.
0 comments
default
newest
oldest
h33t-l4x0r
6mo ago
I imagine it's supposed to get onto the server by an exploited vulnerable image upload plugin
slow_typist
OP
6mo ago
Maybe I don’t understand the scenario fully, but under your assumption there is no need to inject the malicious webshell later.
j
/
k
navigate · click thread line to collapse