Highlights
- Pro
Pinned Loading
-
Invicti-Security/brainstorm
Invicti-Security/brainstorm PublicA smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery
-
Invicti-Security/web-inf-path-trav
Invicti-Security/web-inf-path-trav PublicTool for helping in the exploitation of path traversal vulnerabilities in Java web applications
-
quick primer on how to exploit path ...
quick primer on how to exploit path traversals in Java web apps (i.e. you can read WEB-INF/web.xml) 1so, you can read WEB-INF/web.xml. how can you escalate this issue?
23[step 1]. try to read other common Java files such as WEB-INF/web-jetty.xml.
45use a specialized wordlist such as the following (from Sergey Bobrov/BlackFan):
-
orange-confusion-attacks
orange-confusion-attacks PublicRepro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
-
-
client-side-prototype-pollution-expo...
client-side-prototype-pollution-expoitation.md 1I was trying to exploit a client-side prototype pollution and nothing was working.
23I figured out that if you try to use a script gadget by visiting a URL like this dirrectly:
45```
Something went wrong, please refresh the page to try again.
If the problem persists, check the GitHub status page or contact support.
If the problem persists, check the GitHub status page or contact support.