Web Security Module

Web Security Knowledge Base

Comprehensive web application security testing guide covering OWASP Top 10, real-world exploitation techniques, payloads, and mitigation strategies.

💉 SQL Injection

Database compromise via unsanitized queries. 50+ payloads.

💻 Command Injection

OS command execution through vulnerable inputs. RCE payloads.

📦 Insecure Deserialization

PHP/Java/Python deserialization exploitation. POP chains.

⚡ Remote Code Execution

Full remote code execution techniques and payloads.

🔴 Cross Site Scripting

Malicious JavaScript execution. 40+ payloads.

🔗 Server Side Request Forgery

Backend arbitrary requests. Cloud metadata exploitation.

📝 Server Side Template Injection

Template injection leading to RCE. Jinja2, Twig, ERB.

🔍 XML External Entity

XXE injection for file disclosure, SSRF, DoS.

📄 LFI / RFI

Local and Remote File Inclusion. PHP wrappers.

🔓 IDOR / BOLA

Insecure Direct Object Reference. Horizontal/Vertical privilege escalation.

🔑 JWT Attacks

JWT algorithm confusion, weak signing, key injection.

📂 Path Traversal

Directory traversal for file access.

🎭 CSRF

Cross-Site Request Forgery token bypass techniques.

🌐 CORS Misconfiguration

CORS origin bypass, credential leakage.

➡️ Open Redirect

URL redirection exploitation and bypass.

📄 HTML Injection

HTML/JS injection via unsanitized input.

🗄️ NoSQL Injection

MongoDB, Redis injection techniques.

🔗 Remote File Inclusion

RFI exploitation for RCE.

🐘 PHP Object Injection

PHP deserialization exploitation, magic methods.

🖥️ SSI Injection

Server-Side Include injection.

📊 XPath Injection

XPath query injection attacks.

🔐 LDAP Injection

LDAP query injection.

📋 Log Injection

Log poisoning and injection.

🔗 Sensitive Data in URL

Session tokens exposed in URLs.

💾 Sensitive Data in LocalStorage

Token theft from browser storage.

📦 Sensitive Backup Files

Backup file exposure.

🔑 Default Credentials

Default password exploitation.

📂 Directory Listing

Directory listing enabled.

⚠️ Error Message Disclosure

Verbose error information leakage.

🔓 Insufficient Brute Force Protection

Brute force attack prevention bypass.

🔢 OTP Brute Force

One-time password prediction/bypass.

🔐 Weak Password Policy

Weak password requirements.

🔒 Weak Cryptographic Algorithm

Use of deprecated crypto algorithms.

🔓 Plaintext Password Storage

Password stored without hashing.

💳 Credit Card Exposure

PAN/PCI data exposure.

🚫 Missing Function Access Control

Broken access control.

🔒 Missing HTTPS / Weak TLS

Insecure transport configuration.

📅 Outdated Server Software

Unpatched server vulnerabilities.

📚 Vulnerable Components

Outdated libraries and dependencies.

📰 Vulnerable WordPress

WordPress CMS vulnerabilities.

🌍 Subdomain Takeover

DNS subdomain hijacking.

⬆️ Vertical Privilege Escalation

Privilege escalation to admin.

💰 Business Logic Flaws

Price/inventory manipulation.

📤 File Upload Vulnerabilities

Webshell upload, bypass techniques.