mirror of
https://github.com/swisskyrepo/PayloadsAllTheThings.git
synced 2025-02-21 14:16:07 +00:00
Fix changed urls
This commit is contained in:
parent
2d4b98b9c2
commit
0913e8c3bd
@ -10,7 +10,7 @@
|
||||
|
||||
## Methodology
|
||||
|
||||
data:image/s3,"s3://crabby-images/297de/297dea3d233a2cda51beeef32036ce729b97d9c6" alt="CSRF_cheatsheet"
|
||||
data:image/s3,"s3://crabby-images/18d29/18d2969ede23563f306d8fc4c0013f59d678ffb8" alt="CSRF_cheatsheet"
|
||||
|
||||
## Payloads
|
||||
|
||||
|
@ -8,7 +8,7 @@ The following magic methods will help you for a PHP Object injection
|
||||
* __destruct() when an object is deleted.
|
||||
* __toString() when an object is converted to a string.
|
||||
|
||||
Also you should check the `Wrapper Phar://` in [File Inclusion - Path Traversal](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion%20-%20Path%20Traversal#wrapper-phar) which use a PHP object injection.
|
||||
Also you should check the `Wrapper Phar://` in [File Inclusion](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/File%20Inclusion#wrapper-phar) which use a PHP object injection.
|
||||
|
||||
## __wakeup in the unserialize function
|
||||
|
||||
|
@ -10,12 +10,12 @@ Attempting to manipulate SQL queries may have goals including:
|
||||
|
||||
## Summary
|
||||
|
||||
* [CheatSheet MSSQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20injection/MSSQL%20Injection.md)
|
||||
* [CheatSheet MySQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20injection/MySQL%20Injection.md)
|
||||
* [CheatSheet OracleSQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20injection/OracleSQL%20Injection.md)
|
||||
* [CheatSheet PostgreSQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20injection/PostgreSQL%20Injection.md)
|
||||
* [CheatSheet SQLite Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20injection/SQLite%20Injection.md)
|
||||
* [CheatSheet Cassandra Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20injection/Cassandra%20Injection.md)
|
||||
* [CheatSheet MSSQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/MSSQL%20Injection.md)
|
||||
* [CheatSheet MySQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/MySQL%20Injection.md)
|
||||
* [CheatSheet OracleSQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/OracleSQL%20Injection.md)
|
||||
* [CheatSheet PostgreSQL Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/PostgreSQL%20Injection.md)
|
||||
* [CheatSheet SQLite Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/SQLite%20Injection.md)
|
||||
* [CheatSheet Cassandra Injection](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/SQL%20Injection/Cassandra%20Injection.md)
|
||||
* [Entry point detection](#entry-point-detection)
|
||||
* [DBMS Identification](#dbms-identification)
|
||||
* [SQL injection using SQLmap](#sql-injection-using-sqlmap)
|
||||
|
@ -176,7 +176,7 @@ http://127.1.1.1:80:\@@127.2.2.2:80/
|
||||
http://127.1.1.1:80#\@127.2.2.2:80/
|
||||
```
|
||||
|
||||
data:image/s3,"s3://crabby-images/821f7/821f7d612640e14190aa313bbc8f1faf23b243a7" alt="https://github.com/swisskyrepo/PayloadsAllTheThings/raw/master/SSRF%20injection/Images/SSRF_Parser.png"
|
||||
data:image/s3,"s3://crabby-images/147a0/147a0265c9d631974684194ee7ade9f9fabbd4f4" alt="https://github.com/swisskyrepo/PayloadsAllTheThings/raw/master/SSRF%20injection/Images/SSRF_Parser.png"
|
||||
|
||||
|
||||
## SSRF exploitation via URL Scheme
|
||||
@ -198,7 +198,7 @@ ssrf.php?url=http://127.0.0.1:80
|
||||
ssrf.php?url=http://127.0.0.1:443
|
||||
```
|
||||
|
||||
data:image/s3,"s3://crabby-images/6f265/6f2654194cf03d5c4f635ed6738e6c4d009213be" alt="SSRF stream"
|
||||
data:image/s3,"s3://crabby-images/78e3e/78e3eb2980da4afda3a2702cc7d82d6405556715" alt="SSRF stream"
|
||||
|
||||
The following URL scheme can be used to probe the network
|
||||
|
||||
|
@ -49,7 +49,7 @@ python2.7 ./tplmap.py -u "http://192.168.56.101:3000/ti?user=InjectHere*&comment
|
||||
|
||||
## Methodology
|
||||
|
||||
data:image/s3,"s3://crabby-images/81f8e/81f8eccc26452ff7083750a79c3a07ed11f86e00" alt="SSTI cheatsheet workflow"
|
||||
data:image/s3,"s3://crabby-images/3a778/3a77818efd07ca9b96364c4427f66adf8564024d" alt="SSTI cheatsheet workflow"
|
||||
|
||||
## Ruby
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user