Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
api-pentestapi-securitybug-bounty-huntersbugbountybypasscheatsheetenumerationexploithackingowasppayloadspenetration-testingpentestreconredteamsecurityvulnerabilityweb-application-securitywebhackingwebsecurity
2FA_OTP_Bypass.md | ||
API Key Leak.md | ||
Bypass 403.md | ||
Captcha Bypass.md | ||
CSP Bypass.md | ||
CSRF.md | ||
Dom Clobbering.md | ||
File Upload.md | ||
IDOR.md | ||
JWT.md | ||
LoggerPlusPlus.md | ||
NoSQL Injection.md | ||
Open Redirect.md | ||
Race Condition.md | ||
README.md | ||
Recon.md | ||
Reset Password Bypass.md | ||
SSRF.md | ||
XSS.md |
Web Hacking + Bug Bounty Tricks
These are my bug bounty / Pentest notes that I have gathered from various sources.
You can also contribute.
Table of Contents
- 2FA/OTP Bypass
- API Key Leak
- Bypass 403
- CSP Bypass
- CSRF
- Captcha Bypass
- Dom Clobbering
- File Upload
- IDOR
- JWT Attacks
- LoggerPlusPlus (Burp extension)
- NoSQL Injection
- Open Redirect
- Race Condition
- Recon
- Reset Password Bypass
- SSRF
- XSS
Will always be updated ...