Skip to content
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Branch: master
Clone or download
Latest commit 2b3f072 Apr 28, 2019
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
AWS Amazon Bucket S3 Fixed a typing mistake Mar 15, 2019
CRLF Injection Fix name's capitalization Mar 6, 2019
CSRF Injection Linux Privesc - /etc/passwd writable Apr 7, 2019
CSV Injection Fix name's capitalization Mar 6, 2019
CVE Exploits SAML exploitation + ASREP roasting + Kerbrute Mar 24, 2019
Command Injection Command injection rewritten Apr 21, 2019
Directory Traversal SSRF AWS Elastic Beanstak Apr 21, 2019
File Inclusion Command injection rewritten Apr 21, 2019
GraphQL Injection Command injection rewritten Apr 21, 2019
Insecure Deserialization Added CTF writeup in reference section Mar 20, 2019
Insecure Direct Object References Command injection rewritten Apr 21, 2019
Insecure Management Interface Fix name's capitalization Mar 6, 2019
Insecure Source Code Management GoGitDumper + MySQL summary rewrite Apr 14, 2019
JSON Web Token SAML exploitation + ASREP roasting + Kerbrute Mar 24, 2019
LDAP Injection Fix name's capitalization Mar 6, 2019
LaTeX Injection Fix name's capitalization Mar 6, 2019
Methodology and Resources mitm6 + ntlmrelayx Apr 21, 2019
NoSQL Injection add JSON headers Apr 24, 2019
OAuth Fix name's capitalization Mar 6, 2019
Open Redirect Fix name's capitalization Mar 6, 2019
SAML Injection XSLT in SAML Apr 28, 2019
SQL Injection MSQL UDF sys_exec + SSRF IP: 127.1 and 127.0.1 Apr 20, 2019
Server Side Request Forgery SSRF Google Cloud - add ssh key Apr 22, 2019
Server Side Template Injection sudo_inject + SSTI FreeMarker + Lin PrivEsc passwords Apr 14, 2019
Type Juggling Fix name's capitalization Mar 6, 2019
Upload Insecure Files Update README.md Apr 8, 2019
Web Cache Deception Fix name's capitalization Mar 6, 2019
Web Sockets Use print() function in both Python 2 and Python 3 Apr 26, 2019
XPATH Injection Fix name's capitalization Mar 6, 2019
XSS Injection Fixed link for google CSP bypass Apr 16, 2019
XXE Injection Add XXE inside SVG Mar 23, 2019
_template_vuln SAML exploitation + ASREP roasting + Kerbrute Mar 24, 2019
.gitignore Shell IPv6 + Sandbox credential Jan 7, 2019
README.md Fix name's capitalization Mar 6, 2019

README.md

Payloads All The Things

A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques ! I <3 pull requests :)

You can also contribute with a beer IRL or with buymeacoffee.com

Coffee

Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

  • README.md - vulnerability description and how to exploit it
  • Intruder - a set of files to give to Burp Intruder
  • Images - pictures for the README.md
  • Files - some files referenced in the README.md

You might also like :

Try Harder

Ever wonder where you can use your knowledge ? The following list will help you find "targets" to improve your skills.

Book's list

Grab a book and relax, these ones are the best security books (in my opinion).

More resources

Blogs/Websites

Youtube

You can’t perform that action at this time.