0Sec
search
Ctrlk
  • Spider Security
  • offensive security
    • OSCPchevron-right
  • SANS
  • AppSec
    • EWAPTXchevron-right
      • PHP Type Juggling
      • CSP
      • SqlIchevron-right
      • SSTI & CSTI
      • XSS_HTML Injection
      • CORS Attack
      • Clickjacking
      • Open redirect
      • JSONP
      • LFI && LFD && RFI
      • HTTP Host header attacks
      • CSRF
      • XML injection
      • XML external entity (XXE) injection
      • APIs & JWT attacks
      • Insecure Deserialization
      • OAUTH 2.0 authentication vulnerabilities
      • Host Header Injection
      • Insecure Direct Object References (IDOR)
  • Reverse Eng & Malware dev
    • Internalschevron-right
  • cheat sheet
    • Pentest_Notes
    • Linux BOF & Wireless Attacks
    • WriteUps
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. AppSec

EWAPTX

PHP Type Jugglingchevron-rightCSPchevron-rightSqlIchevron-rightSSTI & CSTIchevron-rightXSS_HTML Injectionchevron-rightCORS Attackchevron-rightClickjackingchevron-rightOpen redirectchevron-rightJSONPchevron-rightLFI && LFD && RFIchevron-rightHTTP Host header attackschevron-rightCSRFchevron-rightXML injectionchevron-rightXML external entity (XXE) injectionchevron-rightAPIs & JWT attackschevron-rightInsecure Deserializationchevron-rightOAUTH 2.0 authentication vulnerabilitieschevron-rightHost Header Injectionchevron-rightInsecure Direct Object References (IDOR)chevron-right
PreviousCourse Materialschevron-leftNextPHP Type Jugglingchevron-right