0Sec
Ctrlk
  • Spider Security
  • offensive security
    • OSCP
  • SANS
  • AppSec
    • EWAPTX
      • PHP Type Juggling
      • CSP
      • SqlI
      • SSTI & CSTI
      • XSS_HTML Injection
      • CORS Attack
      • Clickjacking
      • Open redirect
      • JSONP
      • LFI && LFD && RFI
      • HTTP Host header attacks
      • CSRF
      • XML injection
      • XML external entity (XXE) injection
      • APIs & JWT attacks
      • Insecure Deserialization
      • OAUTH 2.0 authentication vulnerabilities
      • Host Header Injection
      • Insecure Direct Object References (IDOR)
  • Reverse Eng & Malware dev
    • Internals
  • cheat sheet
    • Pentest_Notes
    • Linux BOF & Wireless Attacks
    • WriteUps
Powered by GitBook
On this page
  1. AppSec

EWAPTX

PHP Type JugglingCSPSqlISSTI & CSTIXSS_HTML InjectionCORS AttackClickjackingOpen redirectJSONPLFI && LFD && RFIHTTP Host header attacksCSRFXML injectionXML external entity (XXE) injectionAPIs & JWT attacksInsecure DeserializationOAUTH 2.0 authentication vulnerabilitiesHost Header InjectionInsecure Direct Object References (IDOR)
PreviousCourse MaterialsNextPHP Type Juggling