Jump to content

Recommended Posts

Posted

 

In this thread, I'll include all web hacking techniques and methods. The list is not provided by me. I just found it on my HDD. Credits go to whoever collected this information.

 

Parameter manipulation

 

[*] Arbitary File Deletion

[*] Code Execution

[*] Cookie Manipulation ( meta http-equiv & crlf injection )

[*] CRLF Injection ( HTTP response splitting )

[*] Cross Frame Scripting ( XFS )

[*] Cross-Site Scripting ( XSS )

[*] Directory traversal

[*] Email Injection

[*] File inclusion

[*] Full path disclosure

[*] LDAP Injection

[*] PHP code injection

[*] PHP curl_exec() url is controlled by user

[*] PHP invalid data type error message

[*] PHP preg_replace used on user input

[*] PHP unserialize() used on user input

[*] Remote XSL inclusion

[*] Script source code disclosure

[*] Server-Side Includes (SSI) Injection

[*] SQL injection

[*] URL redirection

[*] XPath Injection vulnerability

[*] EXIF

[*]Buffer Overflows

[*]Clickjacking

[*]Dangling Pointers

[*]Format String Attack

[*]FTP Bounce Attack

[*]Symlinking

 

 

This list below fits in category MultiRequest parameter manipulation

 

[*] Blind SQL injection (timing)

[*] Blind SQL/XPath injection (many types)

 

 

This list below fits in category File checks

 

[*] 8.3 DOS filename source code disclosure

[*] Search for Backup files

[*] Cross Site Scripting in URI

[*] PHP super-globals-overwrite

[*] Script errors ( such as the Microsoft IIS Cookie Variable Information Disclosure )

 

 

This list below fits in category Directory checks

 

[*] Cross Site Scripting in path

[*] Cross Site Scripting in Referer

[*] Directory permissions ( mostly for IIS )

[*] HTTP Verb Tampering ( HTTP Verb POST & HTTP Verb WVS )

[*] Possible sensitive files

[*] Session fixation ( jsessionid & PHPSESSID session fixation )

[*] Vulnerabilities ( e.g. Apache Tomcat Directory Traversal, ASP.NET error message etc )

[*] WebDAV ( very vulnerable component of IIS servers )

 

This list below fits in category Text Search Disclosure

 

[*] Application error message

[*] Check for common files

[*] Directory Listing

[*] Email address found

[*] Local path disclosure

[*] Possible sensitive files

[*] Microsoft Office possible sensitive information

[*] Possible internal IP address disclosure

[*] Possible server path disclosure ( Unix and Windows )

[*] Possible username or password disclosure

[*] Sensitive data not encrypted

[*] Source code disclosure

[*] Trojan shell ( r57,c99,crystal shell etc )

[*] ( IF ANY )Wordpress database credentials disclosure

 

This list below fits in category File Uploads

 

[*] Unrestricted File Upload

 

This list below fits in category Authentication

 

[*] Microsoft IIS WebDAV Authentication Bypass

[*] SQL injection in the authentication header

[*] Weak Password

[*] GHDB - Google hacking database ( using dorks to find what google crawlers have found like passwords etc )

 

This list below fits in category Web Services - Parameter manipulation & with multirequest

 

[*] Application Error Message ( testing with empty, NULL, negative, big hex etc )

[*] Code Execution

[*] SQL Injection

[*] XPath Injection

[*] Blind SQL/XPath injection ( test for numeric,string,number inputs etc )

[*] Stored Cross-Site Scripting ( XSS )

[*] Cross-Site Request Forgery ( CSRF )

 

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



  • Posts

    • L2 DEVS - HTML DESIGN (ALL NPC'S)    
    • I only share for free what they are reselling 🙂 You keep crying in all the publications, and if you are looking for h5 or gd wait for 5 or 6 years... cheers.... GENERAL Cached Extended to 8192kb IOBuffer Hair2SlotCache ItemBidAuctioner Clan Hall Current Olympiad Season Rank pages System (Shows Points/Games - Fully Configurable) Automatic Flag Around Raidboss System Offline Shop & Buffers Restore After Restart (Fixed location) Offline Buffer System PvP Auto Announce System Rebuilt with Extra Addons (Fully Configurable, Name, Zones, Rewards) Automatic Announce System Rebuilt with Extra Addons (Fully Configurable) ALT+B Augmentation House Shift+Click Droplist/Spoil List Epic Items Rank RB points Rank ChangeColorName ChangeColorTitle Change Skin (Race) Change Gender Custom Subclass (Acumulative) Achievements Item Delivery System  Augmentations/Enchants Automatic Announce System Auto Learn Skills PvP Reward Pk Reward War Reward Scheme buffer GlobalChatTrade Trade Augment Items Castle Announce Time Castle Standby Time Fix Spiritshots delay SpellbooksDrop Enable/Disable Drop custom Fully configurable, lvl min max allmobs, allrb, individual New cancel effect min,max BlessedarmorEnchantRate BlessedmagicWeaponEnchantRate BlessednormalWeaponEnchantRate MaxSlosChars MaxSlotsDwarfs Enable or disable all commands Fix fast loading npc OlympiadRestoreStatsOnFightStart OlympiadSystemSecondTimeEnabled OlympiadEnterLast10Minute OlympiadThirdClassSummons MinLevelTrade AnnounceSubClassMsg1 AnnounceSubClassMsg2 AnnounceSubClassMsg3 LimitedSubClassRace NoSellItems Change ID SealStones for AA NoPrivateBuyItems NoDropPlayerOnDie DisableSkillEnchantData Show Level Mobs Show npc clan flag DespawnSummonEnBattle SummonPetEnBattle RideSummonPetEnBattle DitanceToTargetMove EnterWorld_Undying EnterWorld_UnHide BlockWhispMessagePlayerToGM UseItemsWithHide CriticalSkillDamageBonusPer=4.0 Disable SSQSystem OnCastle Siege End Use any dyes Buy halls directly in auctioneer without waiting for the auction, configuration to change the item you consume MensajeEnterWorldServer Command .hero enable/disable hero aura Config vip global chat character, chat by systemsg Soulshots: NoSendSystemMessageUse Panel //admin Global vote reward Agathions system Anti Interface, control all patch files by md5 Command .menu configurable, last restart, name, maxusers, privatestores Spawn protection activate deactivate consume items to activate  Activate or deactivate autoloot for vip characters EVENTS Happy Hour Event reworked Configurable by announcements or systemsg Team VS Team Capture The Flag Death Match Last Man Standing Destroy The Base Korean Style Castle Siege Check if the player is inside the tvt event due to disconnection/critical error Top 1/5 killer reward/announce TimeAfk ResetReuseSkills ResetBuffsOnFinish Firework effect Reward win/lost Add Team Location Title custom Red/blue Open Door/Wall System BalanceBishops Show kills in title Invest positions Show Death To Top Delete Non-Subclass Skills     RELOADS Reload Enterworld Html Option Reload Faction System Reload Donate Shop Reload OfflineBuffer Reload Champion NPC Reload CliExt Reload AntiBot Reload Vip System Reload Auction Reload AutoLoot Reload CastleSiegeManager Reload CharacterLock Reload ClanPvPStatus Reload AutoLearn Reload ClanReputationRank Reload ClanSystem Reload CreatureAction Reload Customs.ini Reload L2server.ini Reload SkillData.txt Reload doordata.txt Reload decodata.txt Reload Multisell Reload DropList   Extender tested for more than 3 years. Assured stability. Possibility of adding MOD's upon request. (Not included, consult).
    • some peoples trash is another mans treasure, is that your treasure?   people might like the content but you are still the rat in the room     thats the community judging you.  
    • Keep reselling what I publish here for free!!! 🙂 GG  
  • Topics

×
×
  • Create New...