Skip to content

Latest commit

 

History

History
187 lines (107 loc) · 5.08 KB

SUMMARY.md

File metadata and controls

187 lines (107 loc) · 5.08 KB

Table of contents

Account Takeover Methodology

Application Level DoS

Authentication Bypass

Broken-Link Hijacking

Broken Auth And Session Management

Bypassing CSP

CMS

CORS

CSRF

Finding CVEs

CheckList

Source Code Review

EXIF Geo Data Not Stripped

File Upload Bypass

Find Origin IP

HTTP Desync Attack

Host-Header Attack

HTML-Injection

IDOR

JWT ATTACK

MFA Bypass

Misconfigurations

OAuth

Open Redirection

Parameter Pollution

Password Reset Functionality

Rate Limit

Recon

SQLi

SSRF

SSTI

Sensitive Info Leaks

Status Code Bypass

Subdomain Takeover

Tabnabbing

WAF Bypasses

Weak Password Policy

XSS

XXE