Skip to content

Latest commit

 

History

History
88 lines (51 loc) · 3.97 KB

files.md

File metadata and controls

88 lines (51 loc) · 3.97 KB

Files

The most interesting files on this repository are:

Markup tests:

Routing conflict attempts:

Weird stuff and attacks based on the filenames.

The only filenames which are not valid are:

  • contain forward slash /
  • .git
  • . and .., but not ...

Everything else goes:

Magic Git files:

  • Git directory inside Git directory: _git.

    For further mischief, the files in that directory were copied to the top-level of the repository.

  • .gitattributes: TODO empty

    Does not seems to lead to arbitrary code execution, as available diff and merge drivers must be set on the config.

    GitHub seems to ignore it: http://stackoverflow.com/a/24382933/895245

Other interesting things to do are the uppercase .Git and the .git file, which did not fit well in this repository.

XSS attempts:

  • <script>
  • <script src="data:text;utf8,alert('xss')">
  • svg.svg, with an XSS attempt
  • sym-xss. It's path is an XSS attempt.