Commit Graph

69 Commits

Author SHA1 Message Date
Daniel Miessler ea4523a98a Merge pull request #103 from upgoingstar/patch-1
Created Sitefinity_fuzz.txt
2017-05-11 21:49:52 -04:00
Daniel Miessler d4652a7126 Merge pull request #102 from 0x6c7862/master
Golang common routes
2017-05-11 21:49:33 -04:00
Daniel Miessler def29d4e8c Merge pull request #94 from brezelbaecker/master
Added SAP ICM auth guest-login bypass URL
2017-05-11 21:48:38 -04:00
Daniel Miessler 9aab1014e9 Merge pull request #92 from alexlauerman/master
Improved test cases
2017-05-11 21:47:55 -04:00
Daniel Miessler a650494c4e Merge pull request #87 from Rbcafe/patch-3
Create symphony_267_xslt_cms.txt
2017-05-11 21:46:49 -04:00
Daniel Miessler 06eae1fa4b Merge pull request #86 from Rbcafe/patch-2
Create symfony_315_demo.txt
2017-05-11 21:46:32 -04:00
Daniel Miessler 15a13e4ecc Merge pull request #83 from Rbcafe/patch-1
Create nginx.txt
2017-05-11 21:44:15 -04:00
Daniel Miessler 6183717491 Merge pull request #74 from whoot/master
Version and Install files
2017-05-11 21:41:29 -04:00
James Ebentier d9175ca5df Add jsp login page 2017-05-06 18:10:17 -07:00
James Ebentier 75af43ba78 Add rails entry for index potential files 2017-05-06 17:18:57 -07:00
Jason Haddix e134f4c3c6 Update Logins.fuzz.txt
invocactf
2017-05-06 13:24:59 -07:00
Jason Haddix 82ae9d7576 Update Common_PHP_Filenames.txt 2017-05-06 13:22:59 -07:00
Jason Haddix 25939f605f Create db_backups.txt 2017-01-16 18:03:00 -08:00
Shubham mittal b09bf67599 Created Sitefinity_fuzz.txt
For CMS Sitefinity
2016-12-29 15:55:42 +05:30
lxb 844400b9b0 Golang common routes 2016-12-20 10:01:31 +11:00
Wojtek Przibylla 5b3ed33eeb Added string sap/admin/index.html that bypasses the guest
authentication for the ICM Administration interface. Related to the URL sap/admin/default.html string which requires authentication.
2016-11-07 16:20:52 +01:00
Alex Lauerman 0097d1823b Created Linux File List
Generated a trimmed list of common Linux files, useful in blindly fuzzing path traversal and XXE.
2016-10-29 20:50:31 -05:00
Rbcafe 249d5690f3 Create symphony_267_xslt_cms.txt
Files inside "Symphony XSLT CMS 2.6.7"

Best regards
@rbcafe
2016-10-13 10:32:38 +02:00
Rbcafe 7c60ee37bc Create symfony_315_demo.txt
Files inside "Symfony Demo Application"
2016-10-13 10:24:23 +02:00
Rbcafe 859a46344c Create nginx.txt 2016-10-10 10:49:35 +02:00
Jan Rude 1ac97d75e5 Version and Install files
Added new Changelog/install files as seen in Typo3 and Tomcat
2016-09-08 09:31:49 +02:00
Daniel Miessler 8ef8694256 Merge pull request #67 from henshin/patch-1
Support for CVE-2007-1860 mod_jk double encoding
2016-08-17 11:09:14 -07:00
Ailton Caetano 022b00b4c9 added a couple of folders to Vignette lists 2016-07-29 19:04:07 -03:00
Tiago Sintra fff5faa976 Support for CVE-2007-1860 mod_jk double encoding
Added paths that will check access control bypass using double encoding (CVE-2007-1860) that could allow a remote user to access Tomcat's administration panel.
Based on the scenario demonstrated on https://pentesterlab.com/exercises/cve-2007-1860/course
2016-07-28 14:10:42 +02:00
g0tmi1k aad07fff50 Removed duplicate values - awk '!x[$0]++' 2016-05-17 12:39:21 +01:00
g0tmi1k 164a5337b2 Remove multi empty lines 2016-05-17 12:20:38 +01:00
g0tmi1k 89b2494409 Added file extensions 2016-05-17 12:08:06 +01:00
g0tmi1k 457997fd6a Changing permissions to everything matches - 0644 2016-05-17 12:04:45 +01:00
Daniel Miessler d698104724 Moved public repo stuff to Discovery. 2016-03-29 16:08:29 -07:00
Daniel Miessler d67b07d6d3 Merge pull request #47 from alexlauerman/patch-1
Removed trailing whitespace from entries in axis.txt
2016-03-07 13:02:34 -08:00
Jay Turla c64ee8540c Update ApacheTomcat.fuzz.txt
adding MicroStrategy Web Universal Administrator
2016-01-28 07:36:40 +08:00
Alex Lauerman 2674664a49 Removed trailing whitespace
Requesting "/happyaxis.jsp     HTTP/1.1" (note the extra whitespace) could cause issue.
2016-01-26 11:23:42 -06:00
Daniel Miessler ee8e5385df Merge pull request #30 from albinowax/master
Add wordlist for bruteforcing hidden GET/POST parameters
2016-01-04 13:29:30 -08:00
Daniel Miessler 5197526414 Merge pull request #32 from g0tmi1k/DNS
DNS
2016-01-04 13:28:29 -08:00
Jason Haddix bd0bba2498 Create quickhits.txt
user submitted via twitter, source: https://bo0om.ru/fuzz.txt
2015-12-02 23:33:37 -08:00
Jason Haddix 8b4e1a4e85 add dns recon 2015-11-03 12:28:19 -08:00
Daniel Miessler 155664bcce Added RobotsDisallowed content to Discovery/Web_Content 2015-09-23 09:41:27 -07:00
g0tmi1k 4713733624 ethicalhack3r's Zone Transfers The Alexa Top 1M
Source: http://www.ethicalhack3r.co.uk/zone-transf`ers-on-the-alexa-top-1-million-part-2/
2015-08-27 11:06:24 +01:00
g0tmi1k 6ba1cc3751 Fix permissions 2015-08-27 11:00:45 +01:00
James Kettle 9309803f3f Add wordlist for bruteforcing hidden GET/POST parameters 2015-08-13 14:11:37 +01:00
Daniel Miessler 232ce766d9 Moar structure. 2015-08-04 11:20:14 -07:00
Daniel Miessler 70a2b58c5d Moar directory motionz. 2015-08-04 10:50:55 -07:00
Daniel Miessler c90f845a8f Updating project structure. 2015-08-04 10:38:59 -07:00
Daniel Miessler 49f1acb96c Updating project structure. 2015-08-04 10:34:44 -07:00
Daniel Miessler df0622ea7f Merge pull request #18 from shipcod3/patch-7
Create backup_files.txt
2015-02-09 21:51:56 -08:00
JT fa8a4e3a2e Create Common_PHP_Filenames.txt
common PHP filenames
2015-02-04 15:21:01 +08:00
JT 8295de1680 Create backup_files.txt
backup files for common CMS config files
2015-02-04 14:57:47 +08:00
Daniel Miessler f1f512c541 Merge pull request #10 from dalvarezs/businessobjects
SAP BusinessObjects URLs
2015-02-03 19:43:31 -08:00
Daniel Miessler 424740cb96 Merge pull request #11 from shipcod3/master
Adding more payloads for PHP fuzz and 'malicious.txt', strings for finding backdoor shells, rootkits, botnets, and exploitable functions
2015-02-03 19:43:15 -08:00
Daniel Miessler 312e524624 Merge pull request #12 from shipcod3/patch-1
Update Apache.fuzz.txt
2015-02-03 19:42:48 -08:00