A list of useful payloads and bypass for Web Application Security and Pentest/CTF
 
 
 
 
 
 
Go to file
Swissky 23f00b55d5 Update SQL injection with Information.schema alternatives 2017-02-06 09:50:13 +01:00
AWS Amazon Bucket S3 AWS added, XSS and methodology update 2016-11-11 16:03:35 +07:00
CRLF injection Enumeration added and improvement for CRLF/XSS/SQL 2016-11-02 20:26:00 +07:00
CSV injection
CVE Shellshock Heartbleed
NoSQL injection
OAuth XSS,SQL OAuth Updated 2016-12-04 01:03:59 +07:00
Open redirect
PHP include Methodology added, XSS payloads updated,little fix 2016-11-06 12:42:50 +07:00
PHP juggling type
PHP serialization
Remote commands execution Methodo, SQL,RCE,XSS,XXE updated 2016-12-20 19:46:06 +01:00
SQL injection Update SQL injection with Information.schema alternatives 2017-02-06 09:50:13 +01:00
SSRF injection Minor Updates in SQL-SSRF-XSS 2017-01-07 20:51:47 +01:00
Tar commands execution
Traversal directory
Upload insecure files Methodo, SQL,RCE,XSS,XXE updated 2016-12-20 19:46:06 +01:00
XSS injection Update SQL injection with Information.schema alternatives 2017-02-06 09:50:13 +01:00
XXE injections Methodo, SQL,RCE,XSS,XXE updated 2016-12-20 19:46:06 +01:00
.gitignore Methodology added, XSS payloads updated,little fix 2016-11-06 12:42:50 +07:00
Methodology_and_enumeration.md Minor Updates in SQL-SSRF-XSS 2017-01-07 20:51:47 +01:00
README.md XSS,SQL OAuth Updated 2016-12-04 01:03:59 +07:00

README.md

Payloads All The Things

A list of usefull payloads and bypasses for Web Application Security Feel free to improve with your payloads and techniques ! I <3 pull requests :)

Last modifications :

  • XSS paylods improved
  • OAuth vulnerabilities added
  • AWS Bucket added
  • SQL payloads updated

Tools

More resources

Book's list:

Blogs/Websites