117 Commits

Author SHA1 Message Date
SirBroccoli
358b8dcfa5 Merge pull request #1245 from HackTricks-wiki/research_update_src_pentesting-web_deserialization_exploiting-__viewstate-parameter_20250806_014331
Research Update Enhanced src/pentesting-web/deserialization/...
2025-08-10 20:01:59 +02:00
SirBroccoli
b22c60801c Update exploiting-__viewstate-parameter.md 2025-08-10 14:29:54 +02:00
HackTricks News Bot
b5c7e9c7b5 Add content from: Critical Vulnerability Impacting Over 100K Sites Patched in ... 2025-08-06 18:32:46 +00:00
HackTricks News Bot
1018f5af23 Add content from: Research Update: Enhanced src/pentesting-web/deserialization... 2025-08-06 01:46:06 +00:00
SirBroccoli
5fe8a54b20 Merge pull request #1217 from HackTricks-wiki/research_update_src_pentesting-web_xss-cross-site-scripting_dom-invader_20250731_014311
Research Update Enhanced src/pentesting-web/xss-cross-site-s...
2025-08-05 02:06:08 +02:00
SirBroccoli
ac8f184bff Merge pull request #1224 from HackTricks-wiki/research_update_src_pentesting-web_json-xml-yaml-hacking_20250801_015159
Research Update Enhanced src/pentesting-web/json-xml-yaml-ha...
2025-08-04 22:01:55 +02:00
SirBroccoli
8e1ca72db1 Merge pull request #1227 from HackTricks-wiki/research_update_src_pentesting-web_xss-cross-site-scripting_pdf-injection_20250801_162631
Research Update Enhanced src/pentesting-web/xss-cross-site-s...
2025-08-04 20:01:58 +02:00
SirBroccoli
f2f590cee2 Merge pull request #1230 from HackTricks-wiki/research_update_src_pentesting-web_deserialization_nodejs-proto-prototype-pollution_client-side-prototype-pollution_20250802_162356
Research Update Enhanced src/pentesting-web/deserialization/...
2025-08-04 18:02:22 +02:00
SirBroccoli
500e9aa476 Update dom-invader.md 2025-08-04 11:47:40 +02:00
HackTricks News Bot
de44ea7065 Add content from: Research Update: Enhanced src/pentesting-web/deserialization... 2025-08-03 08:27:42 +00:00
HackTricks News Bot
d016b78d3d Add content from: Research Update: Enhanced src/pentesting-web/deserialization... 2025-08-02 16:25:03 +00:00
HackTricks News Bot
200cd44508 Add content from: Research Update: Enhanced src/pentesting-web/xss-cross-site-... 2025-08-01 16:27:26 +00:00
HackTricks News Bot
ebd4800ae1 Add content from: Research Update: Enhanced src/pentesting-web/json-xml-yaml-h... 2025-08-01 01:53:55 +00:00
HackTricks News Bot
57208abfd4 Add content from: Research Update: Enhanced src/pentesting-web/xss-cross-site-... 2025-07-31 01:44:28 +00:00
HackTricks News Bot
b4496aea9a Add content from: SQLMap: Testing SQL Database Vulnerabilities 2025-07-29 18:42:06 +00:00
SirBroccoli
c892f948e1 Merge pull request #1197 from HackTricks-wiki/update_YSoNet___NET_Deserialization_Payload_Generator_20250727_123821
YSoNet .NET Deserialization Payload Generator
2025-07-29 12:01:44 +02:00
SirBroccoli
4ab5c29ae3 Merge pull request #1181 from HackTricks-wiki/research_update_src_pentesting-web_deserialization_basic-java-deserialization-objectinputstream-readobject_20250724_162255
Research Update Enhanced src/pentesting-web/deserialization/...
2025-07-28 20:02:00 +02:00
HackTricks News Bot
22aa5b03a5 Add content from: YSoNet: .NET Deserialization Payload Generator 2025-07-27 12:39:35 +00:00
HackTricks News Bot
eb270d7e87 Add content from: CVE-2025-27136 – LocalS3 CreateBucketConfiguration XXE Injec... 2025-07-25 18:32:48 +00:00
HackTricks News Bot
e2cff2bd2c Add content from: Research Update: Enhanced src/pentesting-web/deserialization... 2025-07-24 16:24:14 +00:00
HackTricks News Bot
a48ba411d6 Add content from: Research Update: Enhanced src/pentesting-web/xss-cross-site-... 2025-07-23 16:27:14 +00:00
SirBroccoli
5a4a275d89 Merge pull request #1166 from HackTricks-wiki/research_update_src_pentesting-web_web-vulnerabilities-methodology_20250721_162521
Research Update Enhanced src/pentesting-web/web-vulnerabilit...
2025-07-23 04:39:04 +02:00
SirBroccoli
105a29a015 Merge pull request #1165 from HackTricks-wiki/update_SharePoint_0-day_uncovered__CVE-2025-53770__20250721_124850
SharePoint 0-day uncovered (CVE-2025-53770)
2025-07-22 22:01:42 +02:00
SirBroccoli
0d133d3eb4 Update web-vulnerabilities-methodology.md 2025-07-22 10:33:52 +02:00
HackTricks News Bot
a94ce50af1 Add content from: Research Update: Enhanced src/pentesting-web/web-vulnerabili... 2025-07-21 16:28:13 +00:00
HackTricks News Bot
7731917ad5 Add content from: SharePoint 0-day uncovered (CVE-2025-53770) 2025-07-21 12:51:19 +00:00
HackTricks News Bot
95d597e7c0 Add content from: Research Update: Enhanced src/pentesting-web/ssrf-server-sid... 2025-07-19 01:31:27 +00:00
carlospolop
a57b661dde f 2025-07-18 16:08:20 +02:00
HackTricks News Bot
683e7bb739 Add content from: Research Update: Enhanced src/pentesting-web/crlf-0d-0a.md 2025-07-16 01:42:58 +00:00
HackTricks News Bot
c3f4c8eaf6 Add content from: SugarCRM ≤ 14.0.0 (css/preview) LESS Code Injection Vulnerab... 2025-07-14 12:40:51 +00:00
SirBroccoli
5de2f07668 Merge pull request #1100 from HackTricks-wiki/update_Pre-auth_SQL_Injection_to_RCE_in_Fortinet_FortiWeb_20250711_182725
Pre-auth SQL Injection to RCE in Fortinet FortiWeb Fabric Co...
2025-07-14 10:34:17 +02:00
SirBroccoli
da3d1d6f49 Merge pull request #1099 from HackTricks-wiki/research_update_src_pentesting-web_http-connection-request-smuggling_20250711_162342
Research Update Enhanced src/pentesting-web/http-connection-...
2025-07-13 00:01:32 +02:00
SirBroccoli
b82c3738a1 Merge branch 'master' into research_update_src_pentesting-web_http-request-smuggling_request-smuggling-in-http-2-downgrades_20250712_013912 2025-07-12 17:12:40 +02:00
SirBroccoli
8e2325171c Merge branch 'master' into update_Pre-auth_SQL_Injection_to_RCE_in_Fortinet_FortiWeb_20250711_182725 2025-07-12 17:12:25 +02:00
SirBroccoli
e65a6bb268 Merge branch 'master' into research_update_src_pentesting-web_http-connection-request-smuggling_20250711_162342 2025-07-12 17:12:10 +02:00
SirBroccoli
ad720976e8 Merge pull request #1095 from HackTricks-wiki/research_update_src_pentesting-web_rate-limit-bypass_20250711_012858
Research Update Enhanced src/pentesting-web/rate-limit-bypas...
2025-07-12 16:01:31 +02:00
HackTricks News Bot
92a9bc7b12 Add content from: Research Update: Enhanced src/todo/radio-hacking/low-power-w... 2025-07-12 10:50:06 +00:00
carlospolop
3ad9a55c92 f 2025-07-12 11:50:55 +02:00
SirBroccoli
1d1354c07d Merge pull request #1101 from HackTricks-wiki/update_Dojo_CTF_Challenge__42__Hex_Color_Palette_XXE_File_20250711_183320
Dojo CTF Challenge #42 Hex Color Palette XXE File Disclosure...
2025-07-12 11:40:31 +02:00
SirBroccoli
24d32ecb5a Merge pull request #1105 from HackTricks-wiki/research_update_src_windows-hardening_active-directory-methodology_printnightmare_20250712_082222
Research Update Enhanced src/windows-hardening/active-direct...
2025-07-12 11:39:59 +02:00
carlospolop
e028317c2b Merge branch 'master' of github.com:HackTricks-wiki/hacktricks 2025-07-12 10:48:51 +02:00
carlospolop
23d3f5017d a 2025-07-12 10:48:33 +02:00
HackTricks News Bot
e3705cacd5 Add content from: Research Update: Enhanced src/windows-hardening/active-direc... 2025-07-12 08:24:17 +00:00
HackTricks News Bot
d0cc46ce8b Add content from: Research Update: Enhanced src/pentesting-web/http-request-sm... 2025-07-12 01:40:49 +00:00
HackTricks News Bot
fd1ef02762 Add content from: Dojo CTF Challenge #42: Hex Color Palette XXE File Disclosur... 2025-07-11 18:37:22 +00:00
HackTricks News Bot
f5fdc6ec50 Add content from: Pre-auth SQL Injection to RCE in Fortinet FortiWeb Fabric Co... 2025-07-11 18:33:07 +00:00
HackTricks News Bot
c65bce5f6d Add content from: Research Update: Enhanced src/pentesting-web/http-connection... 2025-07-11 16:25:39 +00:00
SirBroccoli
b5fa7686cd Merge pull request #1087 from HackTricks-wiki/research_update_src_pentesting-web_sql-injection_ms-access-sql-injection_20250710_082628
Add content: Research Update Enhanced src/pentesting-web/sql-injection/ms...
2025-07-11 12:01:48 +02:00
HackTricks News Bot
a53839b788 Add content from: Research Update: Enhanced src/pentesting-web/rate-limit-bypa... 2025-07-11 01:30:33 +00:00
HackTricks News Bot
6e4b16dfac Add content from: McHire Chatbot Platform: Default Credentials and IDOR Expose... 2025-07-10 12:00:47 +00:00