ridwankun12

Web Security Topics

Feb 27th, 2020 (edited)
193
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.53 KB | None | 0 0
  1. [+] Sql Injection Attack
  2. [+] Hibernate Query Language Injection
  3. [+] Direct OS Code Injection
  4. [+] XML Entity Injection
  5. [+] Broken Authentication and Session Management
  6. [+] Cross-Site Scripting (XSS)
  7. [+] Insecure Direct Object References
  8. [+] Security Misconfiguration
  9. [+] Sensitive Data Exposure
  10. [+] Missing Function Level Access Control
  11. [+] Cross-Site Request Forgery (CSRF)
  12. [+] Using Components with Known Vulnerabilities
  13. [+] Unvalidated Redirects and Forwards
  14. [+] Cross Site Scripting Attacks
  15. [+] Click Jacking Attacks
  16. [+] DNS Cache Poisoning
  17. [+] Symlinking – An Insider Attack
  18. [+] Cross Site Request Forgery Attacks
  19. [+] Remote Code Execution Attacks
  20. [+] Remote File inclusion
  21. [+] Local file inclusion
  22. [+] EverCookie
  23. [+] Denial oF Service Attack
  24. [+] Cookie Eviction
  25. [+] PHPwn
  26. [+] NAT Pinning
  27. [+] XSHM
  28. [+] MitM DNS Rebinding SSL/TLS Wildcards and
  29. [+] Quick Proxy Detection
  30. [+] Improving HTTPS Side Channel Attacks
  31. [+] Side Channel Attacks in SSL
  32. [+] Turning XSS into Clickjacking
  33. [+] Bypassing CSRF protections with ClickJacking
  34. [+] HTTP Parameter Pollution
  35. [+] URL Hijacking
  36. [+] Stroke Jacking
  37. [+] Fooling B64_Encode(Payload) on WAFs And Filters
  38. [+] MySQL Stacked Queries with SQL Injection.
  39. [+] Posting Raw XML cross-domain
  40. [+] Generic Cross-Browser Cross-Domain theft
  41. [+] Attacking HTTPS with Cache Injection
  42. [+] Tap Jacking
  43. [+] XSS - Track
  44. [+] Next Generation Click Jacking
  45. [+] XSSing Client-Side Dynamic HTML.
  46. [+] Stroke triggered XSS and Stroke Jacking
  47. [+] Lost iN Translation
  48. [+] Persistent Cross Interface Attacks
  49. [+] Chronofeit Phishing
  50. [+] SQLi Filter Evasion Cheat Sheet (MySQL)
  51. [+] Tabnabbing
  52. [+] UI Redressing
  53. [+] Cookie Poisoning
  54. [+] SSRF
  55. [+] Bruteforce of PHPSESSID
  56. [+] Blended Threats and JavaScript
  57. [+] Cross-Site Port Attacks
  58. [+] CAPTCHA Re-Riding Attack
  59.  
  60. *Web Application Attacks List
  61. [+] Arbitrary file access
  62. [+] Binary planting
  63. [+] Blind SQL Injection
  64. [+] Blind XPath Injection
  65. [+] Brute force attack
  66. [+] Buffer overflow attack
  67. [+] Cache Poisoning
  68. [+] Cash Overflow
  69. [+] Clickjacking
  70. [+] Command injection attacks
  71. [+] Comment Injection Attack
  72. [+] Content Security Policy
  73. [+] Content Spoofing
  74. [+] Credential stuffing
  75. [+] Cross Frame Scripting
  76. [+] Cross Site History Manipulation (XSHM)
  77. [+] Cross Site Tracing
  78. [+] Cross-Site Request Forgery (CSRF)
  79. [+] Cross Site Port Attack (XSPA)
  80. [+] Cross-Site Scripting (XSS)
  81. [+] Cross-User Defacement
  82. [+] Custom Special Character Injection
  83. [+] Denial of Service
  84. [+] Direct Dynamic Code Evaluation (‘Eval Injection’)
  85. [+] Execution After Redirect (EAR)
  86. [+] Exploitation of CORS
  87. [+] Forced browsing
  88. [+] Form action hijacking
  89. [+] Format string attack
  90. [+] Full Path Disclosure
  91. [+] Function Injection
  92. [+] Host Header injection
  93. [+] HTTP Response Splitting
  94. [+] HTTP verb tampering
  95. [+] HTML injection
  96. [+] LDAP injection
  97. [+] Log Injection
  98. [+] Man-in-the-browser attack
  99. [+] Man-in-the-middle attack
  100. [+] Mobile code: invoking untrusted mobile code
  101. [+] Mobile code: non-final public field
  102. [+] Mobile code: object hijack
  103. [+] One-Click Attack
  104. [+] Parameter Delimiter
  105. [+] Page takeover
  106. [+] Path Traversal
  107. [+] Reflected DOM Injection
  108. [+] Regular expression Denial of Service – ReDoS
  109. [+] Repudiation Attack
  110. [+] Resource Injection
  111. [+] Server-Side Includes (SSI) Injection
  112. [+] Session fixation
  113. [+] Session hijacking attack
  114. [+] Session Prediction
  115. [+] Setting Manipulation
  116. [+] Special Element Injection
  117. [+] SMTP injection
  118. [+] SQL Injection
  119. [+] SSI injection
  120. [+] Traffic flood
  121. [+] Web Parameter Tampering
  122. [+] XPATH Injection
  123. [+] XSRF or SSRF
Add Comment
Please, Sign In to add comment