Hacker News new | ask | show | jobs
by kevindqc 3195 days ago
Why does that return a shell?
1 comments

Web shell via put, still quite common.

Just as common as dorking for common webshells with no or default passwords.

If you need a VPS fast googling for c99 is faster than spinning up something on AWS ;)

Would like to learn more about this.

Hmm... looks like this dropped from 20k to 700 while I wasn't looking, which I guess is a very good thing (these are DVRs!). But FWIW, for "JAWS/1.0 -2017 -2016" on shodan, then "/shell?whoami" returns "root". :)