Security Notes
⌘Ctrlk
Security Notes
  • Whoami
  • Notes
    • Qiuch Recon Methodology
    • Enumeration
    • Active Directory Pentesting
    • API-Pen
      • API Discovry
      • Reverse Engineering API Documentation
      • Excessive Data Exposure
      • Vulnerability Scanning
      • API Authentication Attacks
      • API Authorization Attacks
      • Improper Assets Management
      • Mass Assignment
      • SSRF
      • Injection Attacks in API
      • Evasive Maneuvers
      • GraphQL Vulnerabilities
    • Attack Vectors by Port
  • Portswigger Labs
    • A10 Mishandling of Exceptional Conditions
    • A09 Security Logging and Alerting Failures
    • A08 Software or Data Integrity Failures
    • A07 Authentication Failures
    • A06 Insecure Design
    • A05 Injection
    • A04 Cryptographic Failures
    • A03 Software Supply Chain Failures
    • A02 Security Misconfiguration
    • A01 Broken Access Control
  • Uploading an Image Was All I Needed for Full Server Access
  • How I Discovered a Dependency Confusion Vulnerability in a Ruby Application Leading to RCE
  • Privilege Escalation via Impersonation Features feature
  • How I Escalated Simple HTML Injection to SSRF via PDF Rendering
  • How I was able to discover ATO Via IDOR vulnerability
  • how I Bypassed SAML Authentication, and had access to Admin Panel.
Powered by GitBook
  1. Notes

API-Pen

API DiscovryReverse Engineering API DocumentationExcessive Data ExposureVulnerability ScanningAPI Authentication AttacksAPI Authorization AttacksImproper Assets ManagementMass AssignmentSSRFInjection Attacks in APIEvasive ManeuversGraphQL Vulnerabilities
PreviousPassword AttacksNextAPI Discovry

Last updated 1 year ago