Pentest Notes
Ctrlk
  • ๐Ÿ /home/x3m1Sec/.pt-notes
  • ๐Ÿ“Pentest Notes
  • ๐ŸŽฎCTFs
  • ๐ŸŽ“Road to certification
    • eJPTv2
    • CPTS
      • My review
      • Notes
        • Enumeration
        • Nmap
        • Attacking Common Applications
        • Attacking Common Services
        • Active Directory Enumeration & Attacks
        • Linux Privilege Escalation
        • Windows Privilege Escalation
        • Server-side Attacks
        • Web Attacks
          • 1.-HTTP-verb-tampering
          • 2.-Insecure-direct-object-references-idor
          • 3.-XML-external-entity-xxe-injection
          • Web-attacks-to-the-point
        • Web Service & API Attacks
        • Command-injections
        • SQL-injection
        • XSS
        • Broken Authentication
        • Login-brute-forcing
        • Password-attacks
        • Password-cracking
        • Session Security Guide
        • File-transfer
        • File-upload-attacks
        • Shells and payloads
        • Upgrading-tty-shell
        • Using-the-metasploit-framework
        • File Inclusion
        • Ligolo-ng
        • Pivoting-tunneling-and-port-forwarding
        • TIPS
        • CheatSheet
    • OSCP
  • ๐Ÿ“šResources
Powered by GitBook
On this page
  1. ๐ŸŽ“Road to certification
  2. CPTS
  3. Notes

Web Attacks

1.-HTTP-verb-tampering2.-Insecure-direct-object-references-idor3.-XML-external-entity-xxe-injectionWeb-attacks-to-the-point
PreviousServer-side-vulnerabilitiesNext1.-HTTP-verb-tampering

Last updated 6 months ago