mirror of
https://github.com/danielmiessler/SecLists
synced 2025-12-06 08:53:59 +01:00
| .. | ||
| ASP.NET | ||
| Common-PHP-Filenames.txt | ||
| CommonBackdoors-JSP.fuzz.txt | ||
| CommonBackdoors-PHP.fuzz.txt | ||
| CommonBackdoors-PL.fuzz.txt | ||
| golang.txt | ||
| Java-Spring-Boot.txt | ||
| PHP.fuzz.txt | ||
| README.md | ||
| ror.txt | ||
Java-Spring-Boot.txt
Use for: Detecting actuator endpoints, and testing for RCEs in Spring-Boot instances.
Note that it's possible for a spring-boot backend to be behind a spring-cloud-gateway, which may only route all traffic prefixed with /api/ to the backend. Consider fuzzing the starting prefix api with many different values to find what reaches the backend. A recommended wordlist to fuzz this value with is at Fuzzing/Miscellaneous/schemes.txt