Burp Suite User Forum

Create new post

Duplicate secret file in "Remote code execution via web shell upload"

CryptoSecEd | Last updated: Nov 30, 2023 02:35PM UTC

Hello, In the File upload vulnerability lab "Remote code execution via web shell upload", there is a duplicate secret file in the "/home/carlos" folder. Both files have the exact same name and content (I didn't know that this was possible, I'd really like to know how it came about). It is still possible to complete the lab, but one has to be careful as a command like "cat" to view the contents will output both files. I can't imagine any reason why this would occur, so I'm assuming it is a bug, but if it was deliberate I would really like to know why. Thomas.

Ben, PortSwigger Agent | Last updated: Dec 01, 2023 09:39AM UTC

Hi Thomas, Are you able to confirm the payload that you are using for this lab so that we can see exactly what you are doing? In addition to the above, what information is being returned in the response?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.