No description
Find a file
Markus d57dcabf46
Web Sockets: Update README.md
Update outdated link to blog post and add Hacktricks as reference
2023-02-24 10:37:52 +01:00
.github Workflow cleanup 2023-02-11 20:32:36 +01:00
_LEARNING_AND_SOCIALS
_template_vuln
Account Takeover Formatting changes 2023-01-04 21:06:36 +05:30
API Key Leaks Api Key Leaks: Add Trivy to tools section 2022-10-01 17:20:51 +02:00
Argument Injection
AWS Amazon Bucket S3
Command Injection
CORS Misconfiguration SOCKS Compatibility Table + CORS 2023-01-05 01:50:11 +01:00
CRLF Injection
CSRF Injection
CSV Injection
CVE Exploits
Dependency Confusion
Directory Traversal
DNS Rebinding
File Inclusion
GraphQL Injection Add GraphQL Threat Matrix 2022-12-06 14:24:46 +01:00
HTTP Parameter Pollution Add RubyOnRails HTTP Parameter Pollution 2022-11-08 19:06:51 +01:00
Insecure Deserialization fix rawsec url 2023-01-11 23:19:26 +01:00
Insecure Direct Object References
Insecure Management Interface
Insecure Randomness
Insecure Source Code Management
Java RMI
JSON Web Token
Kubernetes
LaTeX Injection
LDAP Injection
Methodology and Resources Kerberos Tickets Dump, Convert, Replay 2023-02-21 23:21:22 +01:00
NoSQL Injection
OAuth Misconfiguration
Open Redirect
Race Condition
Request Smuggling update old url's 2022-10-26 20:36:15 -05:00
SAML Injection
Server Side Request Forgery SSRF + XSS details + XXE BOM 2022-12-13 22:29:20 +01:00
Server Side Template Injection MOTD + SpEL injection 2023-02-20 17:21:43 +01:00
SQL Injection Update PostgreSQL Injection.md 2023-01-03 21:02:57 -08:00
Tabnabbing
Type Juggling
Upload Insecure Files
Web Cache Deception
Web Sockets Web Sockets: Update README.md 2023-02-24 10:37:52 +01:00
XPATH Injection
XSLT Injection
XSS Injection WSL + RDP Passwords + MSPaint Escape 2023-02-11 17:49:55 +01:00
XXE Injection add XXE in Java 2023-01-19 10:23:56 +01:00
.gitignore
CONTRIBUTING.md
LICENSE
mkdocs.yml Github Pages 2023-02-11 20:11:33 +01:00
README.md Update sponsor link 2023-02-14 14:26:49 +01:00

Payloads All The Things

A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques !
I ❤️ pull requests :)

You can also contribute with a 🍻 IRL, or using the sponsor button

Sponsor Tweet

An alternative display version is available at PayloadsAllTheThingsWeb.

📖 Documentation

Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

  • README.md - vulnerability description and how to exploit it, including several payloads
  • Intruder - a set of files to give to Burp Intruder
  • Images - pictures for the README.md
  • Files - some files referenced in the README.md

You might also like the Methodology and Resources folder :

You want more ? Check the Books and Youtube videos selections.

👨‍💻 Contributions

Be sure to read CONTRIBUTING.md

Thanks again for your contribution! ❤️

🧙‍♂️ Sponsors

This project is proudly sponsored by these companies.