Skip to main content

How i found web shell on and Awarded Gold Coin And SWAG

Hay guys,

How i found Web Shell on and Awarded Gold Coin And SWAG

It's a short Write up

While i am recon using i notice a thing in URLs Like bellow image:

Virustotal URLs Section

Shell Name: Mysql interface v1.0.php

Then i visit to the URL and it redirect to me 404 Error Page, When the URL redirect me to 404 Error Page i can able to seen that page and then it redirect me to 404 Error Page. So, it's possible to visit URL using intercept the request, Then i intercept the request and i can able to view the shell page then i report to They offer me Gold Coin And SWAG.


Thank you


Post a Comment

Popular posts from this blog

How i found Stored xss on


Today i am going to show how i found XSS on site who provide Help Desk & Live Chat Software.

Now in the signup page i am trying to create a account with the payload in Full name but it showing error "Invalid name on name"

then i filled it with my name and i finished signup. It redirect me to;

Without checking other staffs i go to Edit profile 

and here i can able add XSS Payload in Name field also in Alias field ( image bellow )

After save this Setting when i back to my Dashboard nothing happen i mean no PopUp

Then i am start looking into source code what actually happening.After scrolling source code suddenly my eyes stuck into a JS code

Oh boy! </script> blocking the <script> here so again i get my ass back into Edit Setting then i filled Name with xss payload

Payload: </script><script>alert(document.domain);</script>

 Then i save it, and back to m…

How i found open redirect and rewarded 0$


Today i am going to show you How i found open redirect and rewarded 0$ LoL 😆😆

Let's start


I am start finding subdomain using Sublist3r  then i found
And i thought that let's find Open Redirect today.

Then i just add a payload like this but it not redirect to 😑 then again i start with like nah again i failed 😑

after failed 2nd time i thought , let's try it again and it's the last time if i failed i will give up with this shit.

then i come up with this and tada! Redirect Success 😌😌

Payload: http:/
Final URL with payload:

Thanks for reading 😉