Pentest

Pentest

🐧Protocals

🌐 Web App

web Exploitation stuff added soon… <!– Have you seen this…

  • Beginner Should know that ?

[+] 1. Information Disclosure :- Error’s , Special Pages , Features Disclosures … [+] 2. Directory Brute Force [+] 3. Vhost Brute Force [+] 4. Analyzing JWT:- Forge_jwt, none_type_jwt … [+] 5. Different HTTP Method:- Auth Bypass, admin_portals … [+] 6. JS Files Extracter’s :- Extract_endpoints … [+] 7. Broken Access Control:- user_id, password_reset, roles … [] 8. Injections :- SQL, LDAP, COMMAND, HTML, NOSQL, HTML … [+] 9. LFI :- LFI, RFI, PHP Rappers … [] 10. XXE [] 11. XML & YAML [] 12. Open Redirect [] 13. CORES Miscofigurations [] 14. ProtoType Pollution [] 15. File Upload [] 16. Mass Assignment [] 17. IDOR:- [] 18. SSTI:- [] 19. SSRF:- [] 20. CSRF:- [] 21. OAuth 2.0 Attacks –>

⛅ Cloud

  • IAM -Identity and Access Management link
  • s3 -s3 Buckets link

    Aws cloud stuff adding …

🔏 Priv Esc Help Guilds

  • Linux Quick Recon link
  • Windows Quick Recon link
  • AWS Quick Recon link
  • Active Directory link

    More Checklists is Out soon..