Commit Graph

1075 Commits

Author SHA1 Message Date
HAHWUL
e6f549f96e
Add ZAP FileUpload AddOn to Tools 2021-10-20 09:07:29 +09:00
HAHWUL
2a16009386
Added referer header validation check in CSRF 2021-06-23 10:05:14 +09:00
Swissky
a69e911926
Merge pull request #379 from alexlauerman/master
Adding updated flowchart to CSRF page
2021-06-19 09:46:49 +02:00
Alex Lauerman
aeecfe0742
Adding updated flowchart 2021-06-18 11:01:17 -05:00
Alex Lauerman
fdc65d3ad1
Add files via upload 2021-06-18 10:55:04 -05:00
Swissky
18556c2caf
Merge pull request #378 from PinkDev1/patch-3
Fixed typo/wording on "Tips" section in Blind-XSS
2021-06-17 09:24:06 +02:00
PinkDev1
21c1690adf
Fixed typo on "Tips" section 2021-06-16 19:24:17 +00:00
Swissky
e9b38b8f43
Merge pull request #377 from ajdumanhug/master
Add AWS SSRF Bypasses
2021-06-16 18:41:39 +02:00
Aj Dumanhug
78e8bcf136
Add AWS SSRF Bypasses 2021-06-16 23:42:50 +08:00
Swissky
62b897c936
Merge pull request #376 from noraj/patch-2
XSS: add quick tips for bXSS
2021-06-16 13:56:29 +02:00
Swissky
2a4631eb8f
Merge pull request #375 from noraj/patch-1
XSS: remove bluelotus
2021-06-16 13:56:07 +02:00
Alexandre ZANNI
c469236204
XSS: add quick tips for bXSS 2021-06-16 13:25:46 +02:00
Alexandre ZANNI
8547ac7dfc
XSS: remove bluelotus
the project is empty
2021-06-16 13:18:08 +02:00
Swissky
b006551bfe
Merge pull request #374 from tex2e/patch-1
Fix snippets
2021-06-14 16:10:54 +02:00
Mako
9c569990dc
Fix snippets
Fix snippets in Command Injection.
2021-06-14 19:36:23 +09:00
Swissky
ad9c15b824
Merge pull request #370 from Annihilat0r/master
add NoSQLi payload
2021-05-29 22:38:13 +02:00
Korolenko Serhii
013ca1f9b0 add NoSQLi payload 2021-05-29 13:04:13 +03:00
Swissky
e3e3ca6ba2
Merge pull request #366 from mpgn/master
Update Smarty Template Injection
2021-05-20 18:08:20 +02:00
mpgn
367296c1f1
Update Smarty Template Injection 2021-05-20 16:42:51 +02:00
Swissky
28f68f47ae
Merge pull request #365 from Shrewk/patch-1
Updates JWT tool
2021-05-19 12:05:59 +02:00
Shrewk
99e4868447
Updates JWT tool
Update of JWT_Tool args
2021-05-19 03:26:57 +02:00
Swissky
4ae6982f63
Merge pull request #362 from noraj/patch-1
add RCE via Apache logs in log poisoning
2021-05-10 13:13:34 +02:00
Alexandre ZANNI
61eed94f18
add RCE via Apache logs in log poisoning 2021-05-10 11:48:14 +02:00
Swissky
a723a34449 PS Transcript + PPLdump.exe 2021-05-06 18:26:00 +02:00
Swissky
28a48bd696
Merge pull request #361 from sokaRepo/master
Add AWS DynamoDB enumeration
2021-04-30 22:21:28 +02:00
soka
a4bdabea83 Add AWS DynamoDB enumeration 2021-04-30 21:44:21 +02:00
Swissky
1592756f9c
Merge pull request #348 from pswalia2u/patch-1
Update Reverse Shell Cheatsheet.md
2021-04-26 10:05:59 +02:00
Swissky
9753f369e3
Merge pull request #358 from gregxsunday/master
improved XXE SVG payloads to be valid XMLs
2021-04-24 15:40:01 +02:00
gregxsunday
43a9a5d235 improved XXE SVG payloads to be valid XMLs 2021-04-24 14:45:45 +02:00
Swissky
08b59f2856 AD update CME+DCOM 2021-04-21 22:27:07 +02:00
Swissky
22340c8fc2
Merge pull request #356 from 0dayCTF/patch-1
Update Reverse Shell Cheatsheet.md
2021-04-18 18:34:49 +02:00
Ryan Montgomery
7ae038d919
Update Reverse Shell Cheatsheet.md
Added: Automatic Reverse Shell Generator
2021-04-18 10:50:41 -04:00
Swissky
ba2c02cc3e
Merge pull request #355 from clem9669/patch-6
Update Linux - Privilege Escalation.md
2021-04-15 12:46:15 +02:00
clem9669
7a564cb859
Update Linux - Privilege Escalation.md
Fixing Markdow URL typo in writable network-scripts section
2021-04-15 10:07:43 +00:00
Swissky
2b43fa8bfc
Merge pull request #353 from micahvandeusen/master
Added method to read gMSA
2021-04-10 18:04:28 +02:00
Micah Van Deusen
f23de13d96
Added method to read gMSA 2021-04-10 10:58:05 -05:00
Swissky
90eefc3b2e
Merge pull request #351 from ricxpl/patch-1
Improve Ruby reverse shell
2021-04-02 22:39:36 +02:00
Ricardo
604618ed41
Improve Ruby reverse shell
Now the reverse shell supports the "cd" command and maintains persistence when an error is raised.
2021-04-02 16:36:58 -04:00
Swissky
d8d26d8fb3
Merge pull request #350 from secnigma/patch-2
Added Netcat BusyBox
2021-04-01 14:31:12 +02:00
secnigma
059a866fd2
Added Netcat BusyBox
Some embedded systems like busybox won't have mkfifo present; instead, they will have mknod. This updated code can spawn reverse shell in systems that use mknod instead of mkfifo.
2021-04-01 13:27:20 +05:30
Swissky
4f89c0a6d2
Merge pull request #349 from SecGus/master
Add .ashx shell
2021-03-30 15:31:53 +02:00
chivato
2c0fff2a7a
Add .ashx shell 2021-03-30 13:56:31 +01:00
pswalia2u
209380740b
Update Reverse Shell Cheatsheet.md
Added new Bash TCP reverse shell
2021-03-28 18:58:07 +05:30
Swissky
0443babe35 Relay + MSSQL Read File 2021-03-25 18:25:02 +01:00
Swissky
f6b9d63bf8 DCOM exploitation and MSSQL CLR 2021-03-24 22:26:23 +01:00
Swissky
bd2166027e GMSA Password + Dart Reverse Shell 2021-03-24 12:44:35 +01:00
Swissky
af9f103655
Merge pull request #346 from linoskoczek/master
Fix links in XSS Injection Summary
2021-03-18 21:18:28 +01:00
linoskoczek
825295e465
Update README.md
Fix broken links in Summary
2021-03-18 19:16:59 +00:00
Swissky
5a3427cf9b
Merge pull request #345 from Tametomo/patch-1
Added additional CSV injection cases patterned after in the wild samples
2021-03-17 09:36:25 +01:00
Tametomo
126555e5f9
Update README.md
Add additional CSV test cases
2021-03-16 19:17:01 -06:00