Offensive Po3nyo
search
⌘Ctrlk
GitHubBlog
Offensive Po3nyo
  • Introduction
  • 📌Pinned
    • Cheat Sheet
  • 📖background knowledge
    • Active Directory & Windows
    • Linux
    • Web
    • Network
    • CS
  • 🟥Offensive Security
    • axe-battleRed Team Infrastructure
    • shield-keyholeBlue Team Infrastructure
    • magnifying-glassReconnaissance
    • radarInitial Access
    • square-terminalExecution
    • anchorPersistence
    • escalatorPrivilege Escalation
    • book-skullDefense Evasion
    • rectangle-history-circle-userCredential Access
    • map-location-dotDiscovery
    • arrow-progressLateral Movement
    • rssCollection
    • cart-flatbed-boxesExfiltration
    • gamepadCommand and Control
  • 🟦Web Pentesting
    • serverServer-Side
      • SQL injection
      • Authentication
      • Directory traversal
      • Command injection
      • Business logic vulnerabilities
      • Information disclosure
      • Access control
      • File upload vulnerabilities
      • Race conditions
      • Server-side request forgery (SSRF)
      • XXE injection
      • NoSQL injection
      • API testing
      • Web cache deception
      • Insecure deserialization
      • GraphQL API vulnerabilities
      • Server-side template injection (SSTI)
      • Web cache poisoning
      • HTTP Host header attacks
      • HTTP request smuggling
      • OAuth authentication
      • JWT attacks
    • desktopClient-Side
  • 🟩Mobile Pentesting
    • androidAndroid
    • appleIOS
  • 🟨reverse engineering
    • Reverse Engineering
  • 🟧forensic
    • windowsWindows
    • linuxLinux
  • 🟫ETC
    • screwdriver-wrenchTools
    • booksCVE Research
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. 🟦Web Pentesting

serverServer-Side

SQL injectionchevron-rightAuthenticationchevron-rightDirectory traversalchevron-rightCommand injectionchevron-rightBusiness logic vulnerabilitieschevron-rightInformation disclosurechevron-rightAccess controlchevron-rightFile upload vulnerabilitieschevron-rightRace conditionschevron-rightServer-side request forgery (SSRF)chevron-rightXXE injectionchevron-rightNoSQL injectionchevron-rightAPI testingchevron-rightWeb cache deceptionchevron-rightInsecure deserializationchevron-rightGraphQL API vulnerabilitieschevron-rightServer-side template injection (SSTI)chevron-rightWeb cache poisoningchevron-rightHTTP Host header attackschevron-rightHTTP request smugglingchevron-rightOAuth authenticationchevron-rightJWT attackschevron-right
PreviousCommand and Controlchevron-leftNextSQL injectionchevron-right