Commit graph

405 commits

Author SHA1 Message Date
MelarDev
5a8f6408e7
Resolvers file for subdomain brute force
The resolvers file is mainly used in subdomain finder tools such as amass, massdns and subbrute.
The list was taken from blechschmidt/massdns github repository. There is a larger list in the subbrute
repository, but that list is no longer maintained.
Source: https://github.com/blechschmidt/massdns/blob/master/lists/resolvers.txt
2018-07-26 10:46:22 +01:00
Adam Muntner
ecb0850538 Strings which can be accidentally expanded into different strings if evaluated in the wrong context
e.g. used as a printf format string or via Perl or shell eval. Might expose sensitive data from the program doing the interpolation, or might just represent the wrong string.

from minimaxir/big-list-of-naughty-strings
2017-01-16 12:55:38 -05:00
Adam Muntner
80772679c2 Strings which crashed iMessage in iOS versions 8.3 and earlier
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:53:07 -05:00
Adam Muntner
85f3e0bd0d Strings which punish the fools who use cat/type on this file
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:51:19 -05:00
Adam Muntner
ccb5013d61 Innocuous strings which may be blocked by profanity filters (https://en.wikipedia.org/wiki/Scunthorpe_problem)
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:50:05 -05:00
Adam Muntner
480f487cbf Update invalid-filenames-microsoft.txt 2017-01-16 12:48:39 -05:00
Adam Muntner
d4dfa84417 Strings which contain unicode with an "upsidedown" effect (via http://www.upsidedowntext.com)
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:44:51 -05:00
Adam Muntner
1e797dcaf3 Strings which contain "corrupted" text. The corruption will not appear in non-HTML text, however. (via http://www.eeemo.net)
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:44:01 -05:00
Adam Muntner
330b3613f9 Strings which contain text that should be rendered RTL if possible (e.g. Arabic, Hebrew)
from minimaxir/big-list-of-naughty-strings/
2017-01-16 12:43:14 -05:00
Adam Muntner
0c8789bb6a Update emoji.txt 2017-01-16 12:40:55 -05:00
Adam Muntner
7b5e1e92e8 Create regionalindicators.txt
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:40:31 -05:00
Adam Muntner
7d53ff81f5 Create README.md 2017-01-16 12:38:32 -05:00
Adam Muntner
5a5b403c1f add unicode files 2017-01-16 12:35:19 -05:00
Adam Muntner
df5fd2e3ef Strings which contain Emoji; should be the same behavior as two-byte characters, but not always
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:26:04 -05:00
Adam Muntner
9ddc02dcb8 Strings which consists of Japanese-style emoticons
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:22:46 -05:00
Adam Muntner
594f0894b4 Strings which contain two-byte characters: can cause rendering issues or character-length issues
minimaxir/big-list-of-naughty-strings
2017-01-16 12:21:34 -05:00
Adam Muntner
9deeda4647 Strings which contain misplaced quotation marks; can cause encoding errors
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:20:21 -05:00
Adam Muntner
ada2f9308f common unicode symbols (e.g. smart quotes),Subscript/Superscript/Accents, cause rendering issues.
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:18:52 -05:00
Adam Muntner
855a9d38de Strings which contain common special ASCII characters (may need to be escaped)
from minimaxir/big-list-of-naughty-string
2017-01-16 12:13:32 -05:00
Adam Muntner
374c6ad1c2 Rename crlf-notes.txt to README.md 2017-01-16 12:11:33 -05:00
Adam Muntner
2f08d13363 Strings which can be interpreted as numeric
from minimaxir/big-list-of-naughty-strings
2017-01-16 12:04:47 -05:00
Adam Muntner
3b0e33f5ae Update date to 2017, add addtl license 2017-01-16 11:42:39 -05:00
Adam Muntner
fb8d7dbbc5 Update README.md 2017-01-16 11:36:46 -05:00
Adam Muntner
493cc33aa2 Update README.md 2017-01-16 11:29:57 -05:00
Adam Muntner
f5b606f0e4 Update README.md 2017-01-16 11:29:02 -05:00
Adam Muntner
e528f450fa Update README.md 2017-01-16 11:20:36 -05:00
Adam Muntner
7767fdee50 Update README.md 2017-01-16 11:07:42 -05:00
Adam Muntner
a2a79b4236 Update README.md 2017-01-16 11:07:10 -05:00
Adam Muntner
f64b14efaf Update README.md 2017-01-16 00:03:20 -05:00
Adam Muntner
da3d4e1fa9 Added additional likely method names 2017-01-15 23:52:10 -05:00
Adam Muntner
e25608f9fa Merge pull request #161 from elnerd/patch-4
Added TRACK method to http-methods
2017-01-15 15:25:42 -05:00
Adam Muntner
abe819f21c Merge pull request #160 from sempf/patch-1
Create json version of debug params
2017-01-15 15:24:01 -05:00
Adam Muntner
fa3e68b231 Merge pull request #155 from elnerd/patch-3
Patch 3 - added h2-h6 tags
2017-01-15 15:23:14 -05:00
Adam Muntner
715977900d Merge pull request #159 from merttasci/patch-1
added 2 style context XSS attacks for LESS
2017-01-15 15:22:34 -05:00
Adam Muntner
1e6472ea75 Merge pull request #154 from elnerd/patch-2
Create html_attributes.txt
2017-01-15 15:21:35 -05:00
Adam Muntner
7b3433f960 Merge pull request #147 from GuiOm/master
Add HTML event attributes
2017-01-15 15:21:19 -05:00
El Nerdo
9cd7e5a2d0 Added TRACK method to http-methods
According to https://www.owasp.org/index.php/Cross_Site_Tracing - the TRACK method is IIS specific variant of TRACE.
2016-12-19 11:38:35 +01:00
Bill Sempf
02f6aa2687 Create json version of debug params
I like this for AJAXy sites.
2016-12-15 10:25:54 -05:00
Adam Muntner
6e3e71822b Delete command-execution-cheatsheat-unix.txt 2016-11-15 16:31:53 -05:00
Mert Tasci
6724d78102 added 2 style context XSS attacks for LESS
cc: https://twitter.com/merttasci_/status/786878767604043776
2016-10-19 14:12:27 +03:00
Adam Muntner
71407d12e0 Create README.md 2016-10-17 09:06:26 -04:00
Adam Muntner
a07e0fea2f from https://github.com/attackercan/
https://github.com/attackercan/regexp-security-cheatsheet
2016-10-17 09:01:36 -04:00
Adam Muntner
22fe7c4b1a Delete README.rb 2016-10-17 08:54:04 -04:00
Adam Muntner
e3a9f305b7 Update README.rb 2016-10-17 08:52:48 -04:00
Adam Muntner
e5b926eadd Update README.rb 2016-10-17 08:52:08 -04:00
Adam Muntner
db8c767952 Create README.rb 2016-10-17 08:51:50 -04:00
Adam Muntner
c4d8de6c78 Add PNG IDAT chunk webshell link & cleanup 2016-10-16 20:24:55 -04:00
Adam Muntner
837c737b28 Tiny php remote os commanding backdoor
Example usage:

http://host/?c=id
2016-10-16 15:47:43 -04:00
Adam Muntner
89c59e7d74 Update arbitrary redirect docs 2016-10-12 03:44:16 -04:00
Adam Muntner
e951c9f277 doc page 1.0 for open redirect patterns 2016-10-12 03:22:12 -04:00