The Hacker Recipes
search
โŒ˜Ctrlk
GitHubTwitterExegolTools
The Hacker Recipes
  • Introduction
  • Active Directory
    • Reconnaissance
    • Movement
    • Persistence
  • Web services
    • Reconnaissance
    • Configuration
    • Accounts and sessions
    • User inputs
      • File inclusion
      • Unrestricted file upload
      • SQL injection
      • XSS (Cross-Site Scripting)
      • CSRF (Cross-Site Request Forgery)
      • SSRF (Server-Side Request Forgery)
      • IDOR (Insecure Direct Object Reference)
      • ORED Open redirect
      • Content-Type juggling
      • XXE injection
      • Insecure JSON Web Tokens
      • ๐Ÿ› ๏ธHTTP parameter pollution
      • ๐Ÿ› ๏ธSSTI (Server-Side Template Injection)
      • ๐Ÿ› ๏ธInsecure deserialization
      • ๐Ÿ› ๏ธCRLF injection
      • ๐Ÿ› ๏ธArbitrary file download
      • ๐Ÿ› ๏ธDirectory traversal
      • ๐Ÿ› ๏ธNull-byte injection
  • Systems & services
    • Reconnaissance
    • Initial access (protocols)
    • Initial access (phishing)
    • Privilege escalation
    • Pivoting
  • Evasion
    • (AV) Anti-Virus
    • ๐Ÿ› ๏ธ(EDR) Endpoint Detection and Response
  • ๐Ÿ› ๏ธPhysical
    • Locks
    • Networking
    • Machines
    • Super secret zones
  • ๐Ÿ› ๏ธIntelligence gathering
    • CYBINT
    • OSINT
    • GEOINT
  • ๐Ÿ› ๏ธRADIO
    • RFID
    • Bluetooth
    • Wi-Fi
    • Wireless keyboard/mouse
  • ๐Ÿ› ๏ธmobile apps
    • Android
    • iOS
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Web services

User inputs

File inclusionchevron-rightUnrestricted file uploadchevron-rightSQL injectionchevron-rightXSS (Cross-Site Scripting)chevron-rightCSRF (Cross-Site Request Forgery)chevron-rightSSRF (Server-Side Request Forgery)chevron-rightIDOR (Insecure Direct Object Reference)chevron-rightORED Open redirectchevron-rightContent-Type jugglingchevron-rightXXE injectionchevron-rightInsecure JSON Web Tokenschevron-right๐Ÿ› ๏ธHTTP parameter pollutionchevron-right๐Ÿ› ๏ธSSTI (Server-Side Template Injection)chevron-right๐Ÿ› ๏ธInsecure deserializationchevron-right๐Ÿ› ๏ธCRLF injectionchevron-right๐Ÿ› ๏ธArbitrary file downloadchevron-right๐Ÿ› ๏ธDirectory traversalchevron-right๐Ÿ› ๏ธNull-byte injectionchevron-right
PreviousLogging inchevron-leftNextFile inclusionchevron-right

Last updated 4 years ago

Was this helpful?

Was this helpful?