119
GitHub - sxcurity/230-OOB: An Out-of-Band XXE server for retrieving file content...
source link: https://github.com/sxcurity/230-OOB
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
230OOB is a tool that emulates an FTP server, assisting you in achieving file read via Out-of-Band XXE.
Installation
git clone https://github.com/lc/230-OOB
Usage:
Generate an XXE payload & DTD at http://xxe.sh
Start the server:
python3 230.py 2121
everything will be logged to -> extracted.log
Recommend
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK