Find a file
Gorgamite ff3b45e0b7
Added LinPEAS to Linux Privesc.
I very strongly recommend adding LinPEAS to the enumeration tools. LinPEAS is arguably the best linux privesc enumeration tool out there. If you haven't used it, I'd try it out. It highlights all relevant information with color coded text, and you can pass it parameters to control the thoroughness of the scan. You should add WinPEAS for windows privesc as well.
2020-10-29 03:50:05 -07:00
.github Banner HD with credit 2020-08-10 11:36:18 +02:00
_template_vuln SAML exploitation + ASREP roasting + Kerbrute 2019-03-24 13:16:23 +01:00
Account Takeover Add Password Reset Via Username Collision 2020-10-18 18:13:18 -04:00
API Key Leaks Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
AWS Amazon Bucket S3 AWS Patterns 2020-02-23 20:58:53 +01:00
Command Injection clarification in 'bypass character filter' 2020-06-04 17:26:45 +02:00
CORS Misconfiguration CORS Fix typo 2020-10-06 23:17:34 +02:00
CRLF Injection Added Summary in CRLF 2019-12-17 22:12:35 +05:30
CSRF Injection Updated Summary and Fixed Broken Links in CSRF 2019-12-17 22:21:53 +05:30
CSV Injection HQL Injection + references update 2019-06-16 23:45:52 +02:00
CVE Exploits Update big CVEs list 2020-10-18 16:17:03 -04:00
Directory Traversal Update README.md 2020-10-09 18:17:06 +05:30
File Inclusion Specifying alternative access method through SSH 2020-10-25 02:51:07 -07:00
GraphQL Injection Added missing word 2020-08-25 23:14:33 +00:00
Insecure Deserialization Update PHP.md 2020-09-25 09:43:35 +07:00
Insecure Direct Object References Command injection rewritten 2019-04-21 19:50:50 +02:00
Insecure Management Interface Fix name's capitalization 2019-03-07 00:07:55 +01:00
Insecure Source Code Management Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
JSON Web Token RoadRecon + JSON None refs 2020-04-17 16:34:51 +02:00
Kubernetes Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
LaTeX Injection Fix name's capitalization 2019-03-07 00:07:55 +01:00
LDAP Injection add SSH key authentication via LDAP 2020-09-09 12:15:07 +02:00
Methodology and Resources Added LinPEAS to Linux Privesc. 2020-10-29 03:50:05 -07:00
NoSQL Injection Bind shell cheatsheet (Fix #194) 2020-05-24 14:09:46 +02:00
OAuth Masscan + AD password in description + ZSH revshell bugfix + Mimikatz lsass.dmp 2019-05-12 21:34:09 +02:00
Open Redirect Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
Race Condition Race Condition - First Draft 2020-01-26 12:43:59 +01:00
Request Smuggling HTTP Request Smuggling 2020-08-25 14:38:28 +02:00
SAML Injection XSW 4 Fix #205 2020-05-12 14:27:25 +02:00
Server Side Request Forgery Added DNS Rebinding 2020-06-21 16:31:16 -05:00
Server Side Template Injection Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
SQL Injection Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
Tabnabbing Update README.md 2020-10-20 11:34:02 +02:00
Type Juggling add reference 2020-10-23 23:15:59 +07:00
Upload Insecure Files Upload Methodology 2020-09-27 11:16:50 +02:00
Web Cache Deception Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
Web Sockets Added: Cross-Site WebSocket Hijacking (CSWSH) 2020-04-11 16:24:32 +02:00
XPATH Injection Bind shell cheatsheet (Fix #194) 2020-05-24 14:09:46 +02:00
XSLT Injection AD mitigations 2019-12-26 12:09:23 +01:00
XSS Injection Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
XXE Injection Fix(Docs): Correcting typos on the repo 2020-10-17 22:52:35 +02:00
.gitignore Shell IPv6 + Sandbox credential 2019-01-07 18:15:45 +01:00
BOOKS.md README rewrite : BOOKS and YOUTUBE 2019-05-12 22:43:42 +02:00
CONTRIBUTING.md Upload Methodology 2020-09-27 11:16:50 +02:00
LICENSE Create License 2019-05-25 16:27:35 +02:00
README.md Update README.md 2020-08-22 23:45:49 +02:00
YOUTUBE.md Update YOUTUBE.md 2020-10-08 10:01:45 +02:00

Payloads All The Things Tweet

A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques ! I ❤️ pull requests :)

You can also contribute with a 🍻 IRL, or using the sponsor button.

Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

  • README.md - vulnerability description and how to exploit it, including several payloads
  • Intruder - a set of files to give to Burp Intruder
  • Images - pictures for the README.md
  • Files - some files referenced in the README.md

You might also like the Methodology and Resources folder :

You want more ? Check the Books and Youtube videos selections.