From ad5854f007cb6f1464c5a74e8e3ec9e2bc584a18 Mon Sep 17 00:00:00 2001 From: paul-ion Date: Thu, 28 Sep 2023 21:47:17 -0400 Subject: [PATCH] Add -i back to curl examples --- .../lessons/secondDegreeBlackBelt/owasp2017deserialization.html | 2 +- .../static/lessons/secondDegreeBlackBelt/owasp2017xxe.html | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/trainingportal/static/lessons/secondDegreeBlackBelt/owasp2017deserialization.html b/trainingportal/static/lessons/secondDegreeBlackBelt/owasp2017deserialization.html index 7e78afe7..f8cade9d 100644 --- a/trainingportal/static/lessons/secondDegreeBlackBelt/owasp2017deserialization.html +++ b/trainingportal/static/lessons/secondDegreeBlackBelt/owasp2017deserialization.html @@ -50,7 +50,7 @@
Challenge Tips and Tricks

 
-curl -H 'Cookie:JSESSIONID=_YOUR_SESSION_ID_' '_COMMAND_PROC_URL_SUBMIT_COMMAND_ACTION_URL' -H 'Content-Type: multipart/form-data;' --form-string 'object=rO0ABXNyAApzZXJpYWwuQ2F0mJizcryhARMCAAFMAARuYW1ldAASTGphdmEvbGFuZy9TdHJpbmc7eHB0AApTZXJpYWwgQ2F0' 
+curl -H 'Cookie:JSESSIONID=_YOUR_SESSION_ID_' -i '_COMMAND_PROC_URL_SUBMIT_COMMAND_ACTION_URL' -H 'Content-Type: multipart/form-data;' --form-string 'object=rO0ABXNyAApzZXJpYWwuQ2F0mJizcryhARMCAAFMAARuYW1ldAASTGphdmEvbGFuZy9TdHJpbmc7eHB0AApTZXJpYWwgQ2F0' 
 
 
Replace the base64 object in the curl command with the object generated by ysoserial using the command of your choice. diff --git a/trainingportal/static/lessons/secondDegreeBlackBelt/owasp2017xxe.html b/trainingportal/static/lessons/secondDegreeBlackBelt/owasp2017xxe.html index cea16e0e..16a52f37 100644 --- a/trainingportal/static/lessons/secondDegreeBlackBelt/owasp2017xxe.html +++ b/trainingportal/static/lessons/secondDegreeBlackBelt/owasp2017xxe.html @@ -28,7 +28,7 @@
Challenge Tips and Tricks

 
-curl '_COMMAND_PROC_HOST_LOGIN_FORM_ACTION_URL_' -H 'Content-Type: multipart/form-data' --form-string 'document=<?xml version=\"1.0\"?><credentials><user>admin</user><password></password></credentials>'
+curl '_COMMAND_PROC_HOST_LOGIN_FORM_ACTION_URL_' -i -H 'Content-Type: multipart/form-data' --form-string 'document=<?xml version=\"1.0\"?><credentials><user>admin</user><password></password></credentials>'
 
 
- You can also save the response of the login page to an HTML file to see how it looks.