File tree
614 files changed
+865543
-0
lines changed- API Key Leaks
- Files
- IIS-Machine-Keys
- Account Takeover
- mfa-bypass
- Business Logic Errors
- CONTRIBUTING
- CORS Misconfiguration
- CRLF Injection
- Files
- CSV Injection
- CVE Exploits
- Log4Shell
- Clickjacking
- Client Side Path Traversal
- Command Injection
- Intruder
- Cross-Site Request Forgery
- Images
- DNS Rebinding
- DOM Clobbering
- Denial of Service
- Dependency Confusion
- Directory Traversal
- Intruder
- File Inclusion
- Files
- Intruders
- Google Web Toolkit
- GraphQL Injection
- Images
- HTTP Parameter Pollution
- Headless Browser
- files
- Hidden Parameters
- Insecure Deserialization
- DotNET
- Files
- Images
- Java
- Node
- PHP
- Python
- Ruby
- YAML
- Insecure Direct Object References
- Images
- Insecure Management Interface
- Intruder
- Insecure Randomness
- Insecure Source Code Management
- Bazaar
- Files
- Git
- Mercurial
- Subversion
- JSON Web Token
- Java RMI
- LDAP Injection
- Intruder
- LaTeX Injection
- Mass Assignment
- Methodology and Resources
- Active Directory Attack
- Bind Shell Cheatsheet
- Cloud - AWS Pentest
- Cloud - Azure Pentest
- Cobalt Strike - Cheatsheet
- Container - Docker Pentest
- Container - Kubernetes Pentest
- Escape Breakout
- HTML Smuggling
- Hash Cracking
- Initial Access
- Linux - Evasion
- Linux - Persistence
- Linux - Privilege Escalation
- MSSQL Server - Cheatsheet
- Metasploit - Cheatsheet
- Methodology and enumeration
- Network Discovery
- Network Pivoting Techniques
- Office - Attacks
- Powershell - Cheatsheet
- Reverse Shell Cheatsheet
- Source Code Management
- Vulnerability Reports
- Web Attack Surface
- Windows - AMSI Bypass
- Windows - DPAPI
- Windows - Defenses
- Windows - Download and Execute
- Windows - Mimikatz
- Windows - Persistence
- Windows - Privilege Escalation
- Windows - Using credentials
- NoSQL Injection
- Intruder
- OAuth Misconfiguration
- ORM Leak
- Open Redirect
- Intruder
- Prompt Injection
- Prototype Pollution
- Race Condition
- Regular Expression
- Request Smuggling
- SAML Injection
- Images
- SQL Injection
- BigQuery Injection
- Cassandra Injection
- DB2 Injection
- HQL Injection
- Images
- Intruder
- MSSQL Injection
- MySQL Injection
- OracleSQL Injection
- PostgreSQL Injection
- SQLite Injection
- SQLmap
- Server Side Include Injection
- Server Side Request Forgery
- Files
- Images
- Server Side Template Injection
- ASP
- ExpressionLanguage
- Images
- Intruder
- Java
- JavaScript
- PHP
- Python
- Ruby
- Tabnabbing
- Type Juggling
- Images
- Upload Insecure Files
- CVE FFmpeg HLS
- CVE ZIP Symbolic Link
- Configuration Apache .htaccess
- Configuration IIS web.config
- Configuration Python __init__.py
- Configuration uwsgi.ini
- EICAR
- Extension ASP
- Extension HTML
- Extension PHP
- Images
- Jetty RCE
- Picture Compression
- Picture ImageMagick
- Picture Metadata
- Server Side Include
- Web Cache Deception
- Images
- Intruders
- Web Sockets
- Files
- Images
- XPATH Injection
- XSLT Injection
- Files
- XSS Injection
- 1 - XSS Filter Bypass
- 2 - XSS Polyglot
- 3 - XSS Common WAF Bypass
- 4 - CSP Bypass
- 5 - XSS in Angular
- Files
- Images
- Intruders
- XXE Injection
- Files
- Intruders
- Zip Slip
- _LEARNING_AND_SOCIALS
- BOOKS
- TWITTER
- YOUTUBE
- _template_vuln
- assets
- images
- social
- API Key Leaks
- Account Takeover
- Business Logic Errors
- CORS Misconfiguration
- CRLF Injection
- CSV Injection
- CVE Exploits
- Clickjacking
- Client Side Path Traversal
- Command Injection
- Cross-Site Request Forgery
- DNS Rebinding
- DOM Clobbering
- Denial of Service
- Dependency Confusion
- Directory Traversal
- File Inclusion
- Google Web Toolkit
- GraphQL Injection
- HTTP Parameter Pollution
- Headless Browser
- Hidden Parameters
- Insecure Deserialization
- Insecure Direct Object References
- Insecure Management Interface
- Insecure Randomness
- Insecure Source Code Management
- JSON Web Token
- Java RMI
- LDAP Injection
- LaTeX Injection
- Mass Assignment
- Methodology and Resources
- NoSQL Injection
- OAuth Misconfiguration
- ORM Leak
- Open Redirect
- Prompt Injection
- Prototype Pollution
- Race Condition
- Regular Expression
- Request Smuggling
- SAML Injection
- SQL Injection
- Server Side Include Injection
- Server Side Request Forgery
- Server Side Template Injection
- Tabnabbing
- Type Juggling
- Upload Insecure Files
- Configuration Apache .htaccess
- Web Cache Deception
- Web Sockets
- XPATH Injection
- XSLT Injection
- XSS Injection
- XXE Injection
- Zip Slip
- _LEARNING_AND_SOCIALS
- _template_vuln
- javascripts
- lunr
- min
- workers
- stylesheets
- search
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
614 files changed
+865543
-0
lines changedWhitespace-only changes.
+5,623
Large diffs are not rendered by default.
Large diffs are not rendered by default.
Large diffs are not rendered by default.
Large diffs are not rendered by default.
Large diffs are not rendered by default.
Large diffs are not rendered by default.
Large diffs are not rendered by default.
+5,873
Large diffs are not rendered by default.
Large diffs are not rendered by default.
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + |
Large diffs are not rendered by default.
Large diffs are not rendered by default.
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + |
0 commit comments