there is at least one XSS capable arbitrary file upload in my git repo here. https://git.tcp.direct/d0nk/parler-tricks … it also has the whole API mapped out to build a payload.
-
-
Show this thread
-
since Parler won't be using AWS from tomorrow, I will point it out for you https://git.tcp.direct/d0nk/parler-tricks/src/main/parler/parler_video.py#L18 … this lets you upload any file that will be served from http://video.parler.com with the appropriate Content-Type, including text/html now how is that for free speech?
Show this thread
End of conversation
New conversation -
-
-
@jwz any chance you can amplify? - End of conversation
New conversation -
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Meiklejohnian absolutist. free speech as in free-for-everyone.
mutuals: