Skip to content

Commit

Permalink
Merge pull request #6 from PortSwigger/4-reference-localhost-avoid-us…
Browse files Browse the repository at this point in the history
…ing-in-the-protocol-portion-of-the-absolute-url

Fake absolute URL without leading //
  • Loading branch information
d0ge committed Sep 5, 2024
2 parents 64dc2b7 + e0a6de4 commit 468f9ec
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions src/fake_relative_urls.json
Original file line number Diff line number Diff line change
Expand Up @@ -609,6 +609,15 @@
"tags": ["URL"],
"id": "5d2743398cd2346eb0a4008174a817498c7f685e"
},
{
"payload": "<attacker>",
"description": "http:/0/<attacker>",
"filters": [],
"prefix": "http:/0/",
"suffix": "",
"tags": ["URL"],
"id": "c316f024b09e4fcbc1c7ff5072087354d747fd98"
},
{
"payload": "\u200b<attacker>",
"description": "HTML entities ZeroWidthSpace, NegativeVeryThinSpace, NegativeThinSpace, NegativeMediumSpace, NegativeThickSpace (U+200B) allowed inside host",
Expand Down

0 comments on commit 468f9ec

Please sign in to comment.