A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Go to file
2016-10-20 10:22:24 +07:00
CRLF injection Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
CSV injection Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
CVE Shellshock Heartbleed CVE Heartbleed and Shellshcok added 2016-10-20 09:54:29 +07:00
Open redirect Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
PHP include Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
PHP juggling type Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
PHP serialization Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
Remote commands execution Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
SQL injection Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
SSRF injection Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
Tar commands execution Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
Traversal directory Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
Upload insecure files Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
XSS injection Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
XXE files Clean project - Renamed and added PHP juggling type 2016-10-20 10:22:24 +07:00
README.md CVE Heartbleed and Shellshcok added 2016-10-20 09:54:29 +07:00

Payloads All The Things

A list of usefull payloads and bypasses for Web Application Security

TODO:

  • PHP Serialization
  • CSV Injection

To improve:

  • RCE
  • SQL injection
  • XXE
  • SSRF
  • Upload
  • Tar command exec
  • Traversal Directory
  • XSS
  • PHP Include

TODO v2:

  • Remove "_" in dir name
  • Add CVE : Hearbleed and ShellShock ?

/!\ Work in Progress : 40%