Home Page
CMS and Frameworks
1.
Apache
1.1.
APISIX
1.2.
Axis2
1.3.
Apache <=2.4.54
1.4.
Apache 2.4.49
1.5.
File Enumeration via Pseudo Directory Listing
1.6.
Common Apache Directories
1.7.
Tomcat
2.
Drupal
2.1.
Default Directories
2.2.
Unvalidated Redirect
2.3.
RCE /w Admin Credentials
3.
WordPress
3.1.
Directories
3.2.
Parameters
3.3.
Enumeration
3.4.
Logs and Backup Files
3.5.
WordPress <=4.7.4
3.6.
WordPress SSRF
3.7.
Yoast SEO Plugin
3.8.
Plugins & Themes
3.9.
XML-RPC Service
3.10.
WAF Bypass
3.11.
Client-Side ReDOS
3.12.
REST Nonce
3.13.
Gravatar
3.14.
Other
4.
EpiServer
4.1.
Default Directories
4.2.
Ektron
4.3.
Find
5.
IIS
5.1.
Default Directories
5.2.
Debug Mode
5.3.
Tilde Shortname
5.4.
NTLM SSP Authentication
5.5.
Other
6.
Amazon Web Services (AWS)
7.
Atlassian Confluence
8.
ExpressionEngine
9.
SharePoint
10.
Umbrco
General Penetrationtesting
11.
TLS & SSL
11.1.
Client-Initiated Renegotiation
11.2.
TLS and Ciphers
12.
User Enumeration
13.
Loaded Components
14.
File Upload
15.
PHP Source Code Review
16.
DS_Store & Thumbs.db
17.
Filter Testing
18.
Header Exploitation
19.
Host Header Exploitation
20.
HTTP Pipelining
21.
JWT Tokens
22.
SwaggerUI
23.
Google API Key
24.
Local WiFi Passwords
25.
XSS
26.
XSS Inspiration Payloads
Tips and Tricks
27.
Useful Settings & Setups
27.1.
BurpSuite Settings
27.2.
Custom Browser Search
27.3.
www. in Firefox
28.
Fingerprinting
29.
JSON Convertion
30.
Archived URLs
31.
Regex & Grep
32.
Time-Based Graph
OSINT
33.
Finding Leaked Credentials
34.
Social Media
35.
Grographical Maps
36.
GitHub Quirks
37.
Search Engines
38.
WiFi Triangulation
Privacy & Anonymity
39.
Data Removal
Training Grounds
40.
HashCat Mask Attack
Answers
41.
Mask Attack
Other
42.
Research More
43.
To-Do List
44.
Source
Light
Rust
Coal
Navy
Ayu
Cyber Notes
File Upload
File uploads are one of the most common ways to get an RCE on a website.
File Upload Extension Splitting Cheatsheet