Skip to content

KbaHaxor/WebHacking

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

WebHacking

....

Task Checklist

  • Manual application discovery
  • Automated discovery(Subdomaintakeover)
  • Harvesting public information
  • Session fixation
  • Weak session token quality
  • Weak session token management
  • Weak logout
  • Cross-site request forgery
  • Weak CORS
  • Session token protection
  • No session timeout
  • Session encryption (SSL/TLS)
  • Password strength enforcement
  • Authentication bypass
  • Unauthenticated URL access
  • Password brute force
  • Default account(admin)
  • Insecure authorization design
  • Only client side authorization
  • Variable manipulation
  • Direct access to resources
  • IDOR
  • Reflected XSS
  • Stored XSS
  • DOM based XSS
  • Wrong content-type
  • HTTP header injection
  • Malicious URL redirect
  • Clickjacking
  • LFI
  • RFI
  • XML external entity injection
  • OS command injection
  • SQL injection
  • Malicious file upload
  • Backup files
  • Leaking stackt-traces
  • Comments
  • Path disclosure
  • Directory listing

Help

FAQ

References

About

WebHacking checklist

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published