You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When spoofing host header on password reset using "Host:" or "X-Forwarded-Host:", if you receive the error "Invalid hostname", try using the following hostname: xxx.oastify.com?legit-host.web-security-academy.net without a slash.
If you can inject in an XML file and you can't find a way to perform an XXE, think about OS command injection using $() or backticks.
The text was updated successfully, but these errors were encountered:
Sorry i was a bit lazy to write a PR.
Here's a few more tips that may be useful:
xxx.oastify.com?legit-host.web-security-academy.net
without a slash.The text was updated successfully, but these errors were encountered: