The Hacker Recipes
Ctrlk
GitHubTwitterExegolTools
  • Introduction
  • Active Directory
    • Reconnaissance
    • Movement
    • Persistence
  • Web services
    • Reconnaissance
    • Configuration
    • Accounts and sessions
    • User inputs
      • File inclusion
      • Unrestricted file upload
      • SQL injection
      • XSS (Cross-Site Scripting)
      • CSRF (Cross-Site Request Forgery)
      • SSRF (Server-Side Request Forgery)
      • IDOR (Insecure Direct Object Reference)
      • ORED Open redirect
      • Content-Type juggling
      • XXE injection
      • Insecure JSON Web Tokens
      • ๐Ÿ› ๏ธHTTP parameter pollution
      • ๐Ÿ› ๏ธSSTI (Server-Side Template Injection)
      • ๐Ÿ› ๏ธInsecure deserialization
      • ๐Ÿ› ๏ธCRLF injection
      • ๐Ÿ› ๏ธArbitrary file download
      • ๐Ÿ› ๏ธDirectory traversal
      • ๐Ÿ› ๏ธNull-byte injection
  • Systems & services
    • Reconnaissance
    • Initial access (protocols)
    • Initial access (phishing)
    • Privilege escalation
    • Pivoting
  • Evasion
    • (AV) Anti-Virus
    • ๐Ÿ› ๏ธ(EDR) Endpoint Detection and Response
  • ๐Ÿ› ๏ธPhysical
    • Locks
    • Networking
    • Machines
    • Super secret zones
  • ๐Ÿ› ๏ธIntelligence gathering
    • CYBINT
    • OSINT
    • GEOINT
  • ๐Ÿ› ๏ธRADIO
    • RFID
    • Bluetooth
    • Wi-Fi
    • Wireless keyboard/mouse
  • ๐Ÿ› ๏ธmobile apps
    • Android
    • iOS
Powered by GitBook
On this page
  1. Web services

User inputs

File inclusionUnrestricted file uploadSQL injectionXSS (Cross-Site Scripting)CSRF (Cross-Site Request Forgery)SSRF (Server-Side Request Forgery)IDOR (Insecure Direct Object Reference)ORED Open redirectContent-Type jugglingXXE injectionInsecure JSON Web Tokens๐Ÿ› ๏ธHTTP parameter pollution๐Ÿ› ๏ธSSTI (Server-Side Template Injection)๐Ÿ› ๏ธInsecure deserialization๐Ÿ› ๏ธCRLF injection๐Ÿ› ๏ธArbitrary file download๐Ÿ› ๏ธDirectory traversal๐Ÿ› ๏ธNull-byte injection
PreviousLogging inNextFile inclusion

Last updated 4 years ago

Was this helpful?

Was this helpful?