Sinisterly
All Web Application Hacking Methods - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking)
+--- Thread: All Web Application Hacking Methods (/Thread-All-Web-Application-Hacking-Methods)

Pages: 1 2 3 4 5 6


All Web Application Hacking Methods - Shining White - 11-24-2012


I Working on filling this thread with linking tutorial here :
So thread is Under Construction

, we are adding every relative topic here with easy navigation , So thread is not beautiful or attractive , Sorry for that ,
Also thinking : there is lot of threads for same topic , ex: XSS , get one from vote and add only one tutorial here , coz it will make more easy



Parameter manipulation

* Arbitary File Deletion
* Code Execution
* Cookie Manipulation ( meta http-equiv & crlf injection )
* CRLF Injection ( HTTP response splitting )
* Cross Frame Scripting ( XFS )

* Cross-Site Scripting ( XSS )

* Directory traversal
* Email Injection

* File inclusion


* Full path disclosure
* LDAP Injection
* PHP code injection
* PHP curl_exec() url is controlled by user
* PHP invalid data type error message
* PHP preg_replace used on user input
* PHP unserialize() used on user input
* Remote XSL inclusion
* Script source code disclosure
* Server-Side Includes (SSI) Injection
* SQL injection
* URL redirection
* XPath Injection vulnerability
* EXIF


Format String Vulnerabilities
JSON Injection
Parameter Tampering (which I see is already covered, just the topic names are divided)
Iframe Injection
ASP ViewState
Padding Oracle
ASP Forms Authentication

*Buffer Overflows

*Clickjacking
*Dangling Pointers
*Format String Attack
*FTP Bounce Attack
*Symlinking






This list below fits in category MultiRequest parameter manipulation

* Blind SQL injection (timing)

* Blind SQL/XPath injection (many types)



This list below fits in category File checks

* 8.3 DOS filename source code disclosure
* Search for Backup files
* Cross Site Scripting in URI
* PHP super-globals-overwrite
* Script errors ( such as the Microsoft IIS Cookie Variable Information Disclosure )



This list below fits in category Directory checks

* Cross Site Scripting in path
* Cross Site Scripting in Referer
* Directory permissions ( mostly for IIS )
* HTTP Verb Tampering ( HTTP Verb POST & HTTP Verb WVS )
* Possible sensitive files
* Possible sensitive files
* Session fixation ( jsessionid & PHPSESSID session fixation )
* Vulnerabilities ( e.g. Apache Tomcat Directory Traversal, ASP.NET error message etc )
* WebDAV ( very vulnerable component of IIS servers )

* DNN (Dot Net Nuke)

[*]Complete DNN (Dot Net Nuke) - numan_malik999


This list below fits in category Text Search Disclosure

* Application error message
* Check for common files
* Directory Listing
* Email address found
* Local path disclosure
* Possible sensitive files
* Microsoft Office possible sensitive information
* Possible internal IP address disclosure
* Possible server path disclosure ( Unix and Windows )
* Possible username or password disclosure
* Sensitive data not encrypted
* Source code disclosure
* Trojan shell ( r57,c99,crystal shell etc )
* ( IF ANY )Wordpress database credentials disclosure




This list below fits in category File Uploads

* Unrestricted File Upload



This list below fits in category Authentication

* Microsoft IIS WebDAV Authentication Bypass
* SQL injection in the authentication header
* Weak Password
* GHDB - Google hacking database ( using dorks to find what google crawlers have found like passwords etc )




This list below fits in category Web Services - Parameter manipulation & with multirequest

* Application Error Message ( testing with empty, NULL, negative, big hex etc )
* Code Execution

* SQL Injection

[SQLMap]SQL injection + Database takeover - pt. 1 - 1llusion
SQL Injection Tutorial - Solixious
SQLi Complete Noob Guide with video - c0d3rinj3ct0r
My SQL injection complete tutorial - V1P3R


* XPath Injection
* Blind SQL/XPath injection ( test for numeric,string,number inputs etc )
* Stored Cross-Site Scripting ( XSS )

* Cross-Site Request Forgery ( CSRF )


Cross-Site Request Forgery ( CSRF ) - Shining White

----------

New Contributions : Keeper |

Interest on making this more big ? please post below what is missing here more , Smile



RE: All Web Application Hacking Methods - RA1N - 11-24-2012

Nice share. Will be good for users to research things. Lots of topics Biggrin


RE: All Web Application Hacking Methods - Shining White - 11-24-2012

(11-24-2012, 06:15 AM)RA1N Wrote: Nice share. Will be good for users to research things. Lots of topics Biggrin

yeah , it was very useful , thats why i shared , also i got much think even i never heard Biggrin


RE: All Web Application Hacking Methods - LightX - 11-24-2012

This will help me get started. Thank you very much! Smile


RE: All Web Application Hacking Methods - Shining White - 11-24-2012

(11-24-2012, 06:34 AM)LightX Wrote: This will help me get started. Thank you very much! Smile

i just rememberd after i saw your thread :epic:


RE: All Web Application Hacking Methods - Solixious - 11-24-2012

Nice share mate.. It'll really help me out... Smile


RE: All Web Application Hacking Methods - josefsat - 11-25-2012

Ooh, thanks for the share!


RE: All Web Application Hacking Methods - Keeper - 11-26-2012

Damn nice! Definitely one of the most useful posts I've seen on the forum.

Thanks a lot shining!


RE: All Web Application Hacking Methods - Shining White - 11-26-2012

(11-26-2012, 05:52 PM)Keeper Wrote: Damn nice! Definitely one of the most useful posts I've seen on the forum.

Thanks a lot shining!

:ok: dunno who should have the credit
btw um taking credit on sharing :epic:


RE: All Web Application Hacking Methods - LightX - 11-26-2012

Its fine, you can just give it to me Wink