技术 - Web安全测试技术点
XS-SearchXSSI (Cross-Site Script Inclusion)XSS (Cross Site Scripting)XXE - XEE - XML External EntityXSLT Server Side Injection (Extensible Stylesheet Languaje Transformations)XPATH injectionWeb Tool - WFuzzUnicode Normalization vulnerabilitySSTI (Server Side Template Injection)SSRF (Server Side Request Forgery)SQL InjectionReset/Forgotten Password BypassRegular expression Denial of Service - ReDoSRate Limit BypassRace ConditionPostMessage VulnerabilitiesParameter PollutionOAuth to Account takeoverLDAP InjectionNoSQL injectionJWT Vulnerabilities (Json Web Tokens)IDORHTTP Request Smuggling / HTTP Desync AttackFormula InjectionFile UploadFile Inclusion/Path traversalEmail Header InjectionDeserializationDomain/Subdomain takeoverCSRF (Cross Site Request Forgery)Dangling Markup - HTML scriptless injectionCRLF (%0D%0A) InjectionCross-site WebSocket hijacking (CSWSH)CORS - Misconfigurations & BypassCookies HackingContent Security Policy (CSP) BypassClient Side Template Injection (CSTI)Command InjectionClickjackingCache Poisoning and Cache DeceptionCaptcha BypassBypass Payment ProcessAbusing hop-by-hop headers2FA/OTP Bypass
最后更新于
这有帮助吗?