119

GitHub - sxcurity/230-OOB: An Out-of-Band XXE server for retrieving file content...

 6 years ago
source link: https://github.com/sxcurity/230-OOB
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
logo.png

Out-of-Band XXE tool
A python script to achieve file read via FTP!

230OOB is a tool that emulates an FTP server, assisting you in achieving file read via Out-of-Band XXE.

Installation

git clone https://github.com/lc/230-OOB

Usage:

Generate an XXE payload & DTD at http://xxe.sh

Start the server:

python3 230.py 2121

everything will be logged to -> extracted.log


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK