9f66d48f2b077a884b35ead58bd7b5624817a267
Payloads All The Things
A list of usefull payloads and bypasses for Web Application Security Feel free to improve with your payloads and techniques ! I <3 pull requests :)
Last modifications :
- XSS paylods improved
- Methodology added
- AWS Bucket added
Tools
- Web Developper
- Hackbar
- Burp Proxy
- Fiddler
- DirBuster
- GoBuster
- Knockpy
- SQLmap
- Eyewitness
- Nikto
- Recon-ng
- Wappalyzer
More resources
Book's list:
- Web Hacking 101 - https://leanpub.com/web-hacking-101
- The Web Application Hacker's Handbook - https://www.amazon.fr/Web-Application-Hackers-Handbook-Exploiting/dp/1118026470
Blogs/Websites
Description
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
bountybugbountybypasscheatsheetenumerationhackinghacktoberfestmethodologypayloadpayloadspenetration-testingpentestprivilege-escalationredteamsecurityvulnerabilityweb-application
Readme
MIT
31 MiB
Languages
Python
76.2%
ASP.NET
8.7%
XSLT
5.9%
Classic ASP
3.2%
PHP
3.1%
Other
2.8%