RSS
 

Easter Eggs

I’ve added various Easter Eggs to my website for fun.
You can find out about some of them below:

Shell Simulator

I decided to add a very simple shell simulator to the top of each webpage on my website (don’t ask why, just go with it). It can’t do much at the moment but its still pretty neat!

Try the following commands:

 

Fake XSS

Try to check my search box for a cross site scripting (XSS) vulnerability.

Search for:

Note: This will not work in browsers which use the HTTP header  X-XSS-Protection: 1 to provide reflective Cross-Site Scripting (XSS) protection.

 

Vulnerable download script?

Visit this page:
https://mohammadg.com/download.php?file=invalid-file

And stare at it for a while.

Robot in my Robots.txt

Hmm, how did that get in there?
https://mohammadg.com/robots.txt