cirosantilli / test-git-web-interface

Tests to find bugs on Git web interfaces like GitHub, GitLab, etc. <script>alert('xss')</script>
javascript:alert('xss')
75 stars 39 forks source link

camo.githubusercontent.com is vulnerable to ssrf. #105

Open isuspendyou76219 opened 2 years ago

isuspendyou76219 commented 2 years ago

Logs camo out of the following websites:

isuspendyou76219 commented 2 years ago
isuspendyou76219 commented 2 years ago

Actually blocking github camo from accessing github (you may get blocked too.)

isuspendyou76219 commented 2 years ago