hacktricks/pentesting-web
mtisec 6b80e74f37
Changing SameSite table for comprehensiveness
The table of the SameSite cookie flag used the term `Normal`, which is taken from the Invicti website, but could be misleading . Changing it in favor of `NotSet`. Further, adding `None` to the table for comprehensiveness. Finally, adding a hint to `NotSet` in the table, because of the changing default behavior of browsers.
Also fixing a typo in a keyword.
2022-10-19 10:40:21 +02:00
..
content-security-policy-csp-bypass Merge pull request #522 from TalebQasem/patch-64 2022-10-17 01:01:38 +02:00
deserialization GitBook: [#3608] No subject 2022-10-16 23:16:14 +00:00
file-inclusion syn cubes 2022-09-27 02:18:19 +02:00
file-upload GitBook: [#3608] No subject 2022-10-16 23:16:14 +00:00
hacking-with-cookies Changing SameSite table for comprehensiveness 2022-10-19 10:40:21 +02:00
http-request-smuggling GitBook: [#3582] No subject 2022-10-08 16:35:25 +00:00
login-bypass change support text 2022-09-09 13:28:04 +02:00
pocs-and-polygloths-cheatsheet change support text 2022-09-09 13:28:04 +02:00
postmessage-vulnerabilities GitBook: [#3603] No subject 2022-10-13 00:56:34 +00:00
saml-attacks GitBook: [#3608] No subject 2022-10-16 23:16:14 +00:00
sql-injection GitBook: [#3592] No subject 2022-10-10 21:08:59 +00:00
ssrf-server-side-request-forgery GitBook: [#3523] No subject 2022-09-30 10:43:59 +00:00
ssti-server-side-template-injection GitBook: [#3540] No subject 2022-10-03 13:43:01 +00:00
unicode-injection GitBook: [#3606] No subject 2022-10-16 14:05:57 +00:00
web-vulnerabilities-methodology GitBook: [#3603] No subject 2022-10-13 00:56:34 +00:00
xs-search GitBook: [#3601] No subject 2022-10-12 22:10:40 +00:00
xss-cross-site-scripting GitBook: [#3603] No subject 2022-10-13 00:56:34 +00:00
2fa-bypass.md Update 2fa-bypass.md 2022-10-07 06:20:43 +06:00
abusing-hop-by-hop-headers.md change support text 2022-09-09 13:28:04 +02:00
bypass-payment-process.md change support text 2022-09-09 13:28:04 +02:00
cache-deception.md Update cache-deception.md 2022-10-09 11:49:04 +06:00
captcha-bypass.md Update captcha-bypass.md 2022-10-09 07:24:32 +06:00
clickjacking.md Update clickjacking.md 2022-10-09 17:25:36 +06:00
client-side-template-injection-csti.md Update client-side-template-injection-csti.md 2022-10-10 03:49:18 +06:00
command-injection.md Update command-injection.md 2022-10-10 06:18:23 +06:00
cors-bypass.md change support text 2022-09-09 13:28:04 +02:00
crlf-0d-0a.md GitBook: [#3563] No subject 2022-10-05 09:28:25 +00:00
cross-site-websocket-hijacking-cswsh.md change support text 2022-09-09 13:28:04 +02:00
csrf-cross-site-request-forgery.md GitBook: [#3582] No subject 2022-10-08 16:35:25 +00:00
dangling-markup-html-scriptless-injection.md change support text 2022-09-09 13:28:04 +02:00
domain-subdomain-takeover.md GitBook: [#3523] No subject 2022-09-30 10:43:59 +00:00
email-injections.md GitBook: [#3523] No subject 2022-09-30 10:43:59 +00:00
file-upload.md change support text 2022-09-09 13:28:04 +02:00
formula-doc-latex-injection.md GitBook: [#3608] No subject 2022-10-16 23:16:14 +00:00
h2c-smuggling.md change support text 2022-09-09 13:28:04 +02:00
hacking-jwt-json-web-tokens.md GitBook: [#3582] No subject 2022-10-08 16:35:25 +00:00
http-connection-request-smuggling.md change support text 2022-09-09 13:28:04 +02:00
http-response-smuggling-desync.md GitBook: [#3582] No subject 2022-10-08 16:35:25 +00:00
idor.md change support text 2022-09-09 13:28:04 +02:00
integer-overflow.md GitBook: [#3596] No subject 2022-10-11 23:01:22 +00:00
ldap-injection.md change support text 2022-09-09 13:28:04 +02:00
nosql-injection.md GitBook: [#3523] No subject 2022-09-30 10:43:59 +00:00
oauth-to-account-takeover.md change support text 2022-09-09 13:28:04 +02:00
open-redirect.md change support text 2022-09-09 13:28:04 +02:00
parameter-pollution.md change support text 2022-09-09 13:28:04 +02:00
race-condition.md GitBook: [#3595] No subject 2022-10-11 22:51:42 +00:00
rate-limit-bypass.md GitBook: [#3523] No subject 2022-09-30 10:43:59 +00:00
registration-vulnerabilities.md change support text 2022-09-09 13:28:04 +02:00
regular-expression-denial-of-service-redos.md change support text 2022-09-09 13:28:04 +02:00
reset-password.md change support text 2022-09-09 13:28:04 +02:00
reverse-tab-nabbing.md change support text 2022-09-09 13:28:04 +02:00
server-side-inclusion-edge-side-inclusion-injection.md GitBook: [#3605] No subject 2022-10-15 14:18:24 +00:00
web-tool-wfuzz.md change support text 2022-09-09 13:28:04 +02:00
xpath-injection.md change support text 2022-09-09 13:28:04 +02:00
xs-search.md GitBook: [#3601] No subject 2022-10-12 22:10:40 +00:00
xslt-server-side-injection-extensible-stylesheet-languaje-transformations.md GitBook: [#3540] No subject 2022-10-03 13:43:01 +00:00
xssi-cross-site-script-inclusion.md change support text 2022-09-09 13:28:04 +02:00
xxe-xee-xml-external-entity.md GitBook: [#3523] No subject 2022-09-30 10:43:59 +00:00