A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Go to file
2016-10-18 14:06:10 +07:00
CRLF CRLF Payload 2016-10-18 15:15:43 +07:00
CSV_Injection Init directory with README 2016-10-18 15:01:56 +07:00
Open_Redirect Open Redirect Payloads 2016-10-18 15:41:18 +07:00
PHP_Serialization XXE payloads 2016-10-18 14:06:10 +07:00
RCE MySQL Payloads 2016-10-18 13:39:17 +07:00
SQL_Injection MySQL Payloads 2016-10-18 13:39:17 +07:00
SSRF Init directory with README 2016-10-18 15:01:56 +07:00
TAR_Code_Exec Init directory with README 2016-10-18 15:01:56 +07:00
Traversal_Directory Init directory with README 2016-10-18 15:01:56 +07:00
Upload Init directory with README 2016-10-18 15:01:56 +07:00
XSS Init directory with README 2016-10-18 15:01:56 +07:00
XXE XXE payloads 2016-10-18 14:06:10 +07:00
README.md XXE payloads 2016-10-18 14:06:10 +07:00

PayloadsAllTheThings

A list of every usefull payloads and bypass for Web Application Security

TODO:

  • XSS
  • Upload
  • Traversal Directory
  • Tar
  • SSRF
  • PHP Serialization
  • CSV Injection

To improve:

  • RCE
  • SQL injection
  • XXE

/!\ Work in Progress : 1%