// HackTricks · CC BY-NC 4.0
Web Pentesting
171 pages · adapted from upstream with source attribution on every page.
001 Web Pentesting 2FA/MFA/OTP Bypass pentesting-web 002 Web Pentesting Abusing Hop-by-Hop Headers pentesting-web 003 Web Pentesting Abusing Service Workers xss-cross-site-scripting 004 Web Pentesting Account Takeover pentesting-web 005 Web Pentesting Basic .NET Deserialization (ObjectDataProvider, ExpandedWrapper, and Json.NET) deserialization 006 Web Pentesting Basic Java Deserialization with ObjectInputStream readObject deserialization 007 Web Pentesting Big Binary Files Upload in PostgreSQL postgresql-injection 008 Web Pentesting Blocking the Main Page to Steal a postMessage postmessage-vulnerabilities 009 Web Pentesting BrowExt - ClickJacking browser-extension-pentesting-methodology 010 Web Pentesting BrowExt - permissions & hostpermissions browser-extension-pentesting-methodology 011 Web Pentesting BrowExt - XSS Example browser-extension-pentesting-methodology 012 Web Pentesting Browser Extension Pentesting Methodology browser-extension-pentesting-methodology 013 Web Pentesting Browser HTTP Request Smuggling http-request-smuggling 014 Web Pentesting Bypass Payment Process pentesting-web 015 Web Pentesting Bypassing SOP with Iframes - 1 postmessage-vulnerabilities 016 Web Pentesting Bypassing SOP with Iframes - 2 postmessage-vulnerabilities 017 Web Pentesting Cache Poisoning and Cache Deception cache-deception 018 Web Pentesting Cache Poisoning to DoS cache-deception 019 Web Pentesting Cache Poisoning via URL discrepancies cache-deception 020 Web Pentesting Captcha Bypass pentesting-web 021 Web Pentesting Chrome Cache to XSS xss-cross-site-scripting 022 Web Pentesting Clickjacking pentesting-web 023 Web Pentesting Client Side Path Traversal pentesting-web 024 Web Pentesting Client Side Prototype Pollution nodejs-proto-prototype-pollution 025 Web Pentesting Client Side Template Injection (CSTI) pentesting-web 026 Web Pentesting Cloud SSRF ssrf-server-side-request-forgery 027 Web Pentesting Command Injection pentesting-web 028 Web Pentesting CommonsCollections1 Payload - Java Transformers to Runtime.exec() and Thread.sleep() deserialization 029 Web Pentesting Connection Pool by Destination Example xs-search 030 Web Pentesting Connection Pool Examples xs-search 031 Web Pentesting Content Security Policy (CSP) Bypass content-security-policy-csp-bypass 032 Web Pentesting Cookie Bomb hacking-with-cookies 033 Web Pentesting Cookie Bomb + Onerror XS Leak xs-search 034 Web Pentesting Cookie Jar Overflow hacking-with-cookies 035 Web Pentesting Cookie Tossing hacking-with-cookies 036 Web Pentesting Cookies Hacking hacking-with-cookies 037 Web Pentesting CORS - Misconfigurations & Bypass pentesting-web 038 Web Pentesting CRLF (%0D%0A) Injection pentesting-web 039 Web Pentesting CSP Bypass via 'self', 'unsafe-inline', and Iframes content-security-policy-csp-bypass 040 Web Pentesting CSRF (Cross Site Request Forgery) pentesting-web 041 Web Pentesting CSS Injection css-injection 042 Web Pentesting CSS Injection Code css-injection 043 Web Pentesting Cypher Injection (Neo4j) sql-injection 044 Web Pentesting Dangling Markup - HTML scriptless injection dangling-markup-html-scriptless-injection 045 Web Pentesting DApps - Decentralized Applications pentesting-web 046 Web Pentesting Debugging Client-Side JavaScript xss-cross-site-scripting 047 Web Pentesting Dependency Confusion pentesting-web 048 Web Pentesting Deserialization deserialization 049 Web Pentesting Dom Clobbering xss-cross-site-scripting 050 Web Pentesting DOM Invader xss-cross-site-scripting 051 Web Pentesting DOM XSS xss-cross-site-scripting 052 Web Pentesting Domain/Subdomain takeover pentesting-web 053 Web Pentesting EL - Expression Language ssti-server-side-template-injection 054 Web Pentesting Email Injections pentesting-web 055 Web Pentesting Event Loop Blocking + Lazy images xs-search 056 Web Pentesting Exploiting \\VIEWSTATE without knowing the secrets deserialization 057 Web Pentesting Exploiting VIEWSTATE Knowing the Secret deserialization 058 Web Pentesting Express Prototype Pollution Gadgets nodejs-proto-prototype-pollution 059 Web Pentesting File Inclusion and Path Traversal file-inclusion 060 Web Pentesting File Upload file-upload 061 Web Pentesting Forced Extension Load & Preferences MAC Forgery (Windows) browser-extension-pentesting-methodology 062 Web Pentesting Formula/CSV/Doc/LaTeX/GhostScript Injection pentesting-web 063 Web Pentesting HTTP Connection Contamination pentesting-web 064 Web Pentesting HTTP Connection Request Smuggling pentesting-web 065 Web Pentesting HTTP Request Smuggling / HTTP Desync Attack http-request-smuggling 066 Web Pentesting HTTP Response Smuggling / Desync pentesting-web 067 Web Pentesting IDOR (Insecure Direct Object Reference) pentesting-web 068 Web Pentesting Iframe Traps pentesting-web 069 Web Pentesting Iframes in XSS, CSP and SOP xss-cross-site-scripting 070 Web Pentesting Integer Overflow (Web Applications) xss-cross-site-scripting 071 Web Pentesting Java DNS Deserialization, GadgetProbe and Java Deserialization Scanner deserialization 072 Web Pentesting Java JSF ViewState Deserialization deserialization 073 Web Pentesting Java SignedObject-gated Deserialization and Pre-auth Reachability via Error Paths deserialization 074 Web Pentesting JavaScript Execution XS Leak xs-search 075 Web Pentesting Jinja2 SSTI ssti-server-side-template-injection 076 Web Pentesting JNDI - Java Naming and Directory Interface & Log4Shell deserialization 077 Web Pentesting JS Hoisting xss-cross-site-scripting 078 Web Pentesting JSON, XML, and YAML Hacking and Issues pentesting-web 079 Web Pentesting JWT Vulnerabilities (JSON Web Tokens) pentesting-web 080 Web Pentesting Laravel Livewire Hydration & Synthesizer Abuse deserialization 081 Web Pentesting LDAP Injection pentesting-web 082 Web Pentesting LESS Code Injection leading to SSRF & Local File Read css-injection 083 Web Pentesting LFI to RCE via PHPInfo file-inclusion 084 Web Pentesting LFI to RCE via Temporary File Uploads file-inclusion 085 Web Pentesting LFI2RCE Via compress.zlib + PHPSTREAMPREFERSTDIO + Path Disclosure file-inclusion 086 Web Pentesting LFI2RCE via Eternal waiting file-inclusion 087 Web Pentesting LFI2RCE via Nginx temp files file-inclusion 088 Web Pentesting LFI2RCE via PHP Filters file-inclusion 089 Web Pentesting LFI2RCE via PHPSESSIONUPLOADPROGRESS file-inclusion 090 Web Pentesting LFI2RCE via Segmentation Fault file-inclusion 091 Web Pentesting Login Bypass login-bypass 092 Web Pentesting Mass Assignment (CWE-915) – Privilege Escalation via Unsafe Model Binding pentesting-web 093 Web Pentesting Misc JS Tricks & Relevant Info xss-cross-site-scripting 094 Web Pentesting MS Access SQL Injection sql-injection 095 Web Pentesting MSSQL Injection sql-injection 096 Web Pentesting MySQL FILE Privilege to Outbound SMB and RCE mysql-injection 097 Web Pentesting MySQL injection mysql-injection 098 Web Pentesting Network - Privilege Escalation, Port Scanning, and NTLM Challenge-Response Disclosure postgresql-injection 099 Web Pentesting Node.js - \\proto\\ and Prototype Pollution nodejs-proto-prototype-pollution 100 Web Pentesting NoSQL injection pentesting-web 101 Web Pentesting OAuth to Account Takeover pentesting-web 102 Web Pentesting Open Redirect pentesting-web 103 Web Pentesting Oracle injection sql-injection 104 Web Pentesting ORM Injection pentesting-web 105 Web Pentesting Parameter Pollution | JSON Injection pentesting-web 106 Web Pentesting PDF Injection xss-cross-site-scripting 107 Web Pentesting PDF Upload: XXE and Same-Origin Policy Bypass file-upload 108 Web Pentesting Pentesting gRPC-Web pentesting-web 109 Web Pentesting performance.now example xs-search 110 Web Pentesting performance.now() + Forced Heavy Task xs-search 111 Web Pentesting phar:// Deserialization file-inclusion 112 Web Pentesting Phone Number Injections pentesting-web 113 Web Pentesting PHP - Deserialization + Autoload Classes deserialization 114 Web Pentesting PL/pgSQL Password Bruteforce postgresql-injection 115 Web Pentesting PostgreSQL dblink and loimport Data Exfiltration postgresql-injection 116 Web Pentesting PostgreSQL injection postgresql-injection 117 Web Pentesting PostMessage Vulnerabilities postmessage-vulnerabilities 118 Web Pentesting Prototype Pollution to RCE nodejs-proto-prototype-pollution 119 Web Pentesting Proxy / WAF Protections Bypass pentesting-web 120 Web Pentesting Python YAML Deserialization deserialization 121 Web Pentesting Race Condition pentesting-web 122 Web Pentesting Rate Limit Bypass pentesting-web 123 Web Pentesting RCE with PostgreSQL Extensions postgresql-injection 124 Web Pentesting RCE with PostgreSQL Languages postgresql-injection 125 Web Pentesting Reflecting Techniques - PoCs and Polygloths CheatSheet pocs-and-polygloths-cheatsheet 126 Web Pentesting Registration & Takeover Vulnerabilities pentesting-web 127 Web Pentesting Regular Expression Denial of Service - ReDoS pentesting-web 128 Web Pentesting Request Smuggling in HTTP/2 Downgrades http-request-smuggling 129 Web Pentesting Reset/Forgotten Password Bypass pentesting-web 130 Web Pentesting Reverse Tab Nabbing pentesting-web 131 Web Pentesting RSQL Injection pentesting-web 132 Web Pentesting Ruby Class Pollution deserialization 133 Web Pentesting Ruby on Rails json pollution deserialization 134 Web Pentesting Same-Site Leaks (SS-Leaks) dangling-markup-html-scriptless-injection 135 Web Pentesting SAML Attacks saml-attacks 136 Web Pentesting SAML Basics saml-attacks 137 Web Pentesting Second-Order Injection with sqlmap sqlmap 138 Web Pentesting Server Side Inclusion/Edge Side Inclusion Injection pentesting-web 139 Web Pentesting Server Side XSS (Dynamic PDF) xss-cross-site-scripting 140 Web Pentesting Shadow DOM xss-cross-site-scripting 141 Web Pentesting Sniff Leak xss-cross-site-scripting 142 Web Pentesting SOAP/JAX-WS ThreadLocal Authentication Bypass pentesting-web 143 Web Pentesting SOME - Same Origin Method Execution xss-cross-site-scripting 144 Web Pentesting SQL Injection sql-injection 145 Web Pentesting SQL Login Bypass Payloads login-bypass 146 Web Pentesting SQLMap sql-injection 147 Web Pentesting SQLMap - Cheatsheet sqlmap 148 Web Pentesting SSRF (Server Side Request Forgery) ssrf-server-side-request-forgery 149 Web Pentesting SSRF Vulnerable Platforms ssrf-server-side-request-forgery 150 Web Pentesting SSTI (Server Side Template Injection) ssti-server-side-template-injection 151 Web Pentesting Steal Info JS xss-cross-site-scripting 152 Web Pentesting Stealing postMessage Data by Navigating an Iframe postmessage-vulnerabilities 153 Web Pentesting Timing Attacks pentesting-web 154 Web Pentesting Unicode Injection unicode-injection 155 Web Pentesting Unicode Normalization unicode-injection 156 Web Pentesting Upgrade Header Smuggling pentesting-web 157 Web Pentesting URL Format Bypass ssrf-server-side-request-forgery 158 Web Pentesting URL Max Length - Client Side xs-search 159 Web Pentesting UUID Insecurities pentesting-web 160 Web Pentesting Web Tool - WFuzz pentesting-web 161 Web Pentesting Web Vulnerabilities Methodology pentesting-web 162 Web Pentesting Web Vulns List pocs-and-polygloths-cheatsheet 163 Web Pentesting WebAssembly linear memory corruption to DOM XSS (template overwrite) xss-cross-site-scripting 164 Web Pentesting WebSocket Attacks pentesting-web 165 Web Pentesting XPATH injection pentesting-web 166 Web Pentesting XS-Search/XS-Leaks xs-search 167 Web Pentesting XSLT Server-Side Injection (Extensible Stylesheet Language Transformations) pentesting-web 168 Web Pentesting XSS (Cross Site Scripting) xss-cross-site-scripting 169 Web Pentesting XSS in Markdown xss-cross-site-scripting 170 Web Pentesting XSSI (Cross-Site Script Inclusion) pentesting-web 171 Web Pentesting XXE - XEE - XML External Entity pentesting-web