PwnX.py
PwnX.py copied to clipboard
🏴☠️ Pwn misconfigured sites running ShareX custom image uploader API through chained exploit
🏴☠️ PwnX.py
Pwn misconfigured sites running ShareX custom image uploader API through RFI -> RCE.
XAMPP running as SYSTEM kek
🗂️ Requirements
- Python 3
- Git (optional)
⚙️ Installation
- Clone the repository:
$ git clone https://github.com/ecriminal/PwnX.py.gitor manually download it here - Go to the cloned repository:
$ cd PwnX.py - Install the required Python packages:
$ python3 -m pip install -r requirements.txt - Run PwnX.py:
$ python3 PwnX.py
📝 TODO
- [ ] Encode PHP web shell payload to bypass WAFs and AVs
- [ ] Custom PHP web shell payload command-line option
- [ ] File upload feature in built-in PHP web shell
- [ ] File download feature in built-in PHP web shell
- [ ] Change direction feature in built-in PHP web shell
- [ ] Auto remove PHP web shell
- [x] Save web shells to file