mirror of
https://github.com/swisskyrepo/PayloadsAllTheThings
synced 2025-12-06 17:02:53 +01:00
Update README.md
Add the "?" trick.
This commit is contained in:
parent
b918095775
commit
e9de4e9d78
1 changed files with 8 additions and 0 deletions
|
|
@ -114,6 +114,14 @@ http://www.yoursite.com/http://www.theirsite.com/
|
||||||
http://www.yoursite.com/folder/www.folder.com
|
http://www.yoursite.com/folder/www.folder.com
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Using "?" characted, browser will translate it to "/?"
|
||||||
|
|
||||||
|
```powershell
|
||||||
|
http://www.yoursite.com?http://www.theirsite.com/
|
||||||
|
http://www.yoursite.com?folder/www.folder.com
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
Host/Split Unicode Normalization
|
Host/Split Unicode Normalization
|
||||||
```powershell
|
```powershell
|
||||||
https://evil.c℀.example.com . ---> https://evil.ca/c.example.com
|
https://evil.c℀.example.com . ---> https://evil.ca/c.example.com
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue