Web
Web uygulamalarına yönelik saldırı teknikleri, OWASP Top 10 (2021) ve OWASP Web Security Testing Guide (WSTG) temel alınarak Türkçe olarak derlenmiştir. Her sayfa; zafiyetin nasıl çalıştığını, tespit ve sömürü metodolojisini ve pratik komutları içerir.
- İçerik Keşfi & Recon — subdomain, dizin/parametre keşfi, JS/arşiv
- Subdomain Takeover — sarkan DNS kayıtlarını ele geçirme
Zafiyet katalogu
Section titled “Zafiyet katalogu”- OWASP Top 10 (2021) — kategorilerin özeti ve eşlemesi
- SQL Injection — veritabanı sorgu enjeksiyonu
- Cross-Site Scripting (XSS) — istemci tarafı script enjeksiyonu
- Server-Side Request Forgery (SSRF) — sunucuyu vekil olarak kullanma
- OS Command Injection — işletim sistemi komut enjeksiyonu
- Path Traversal & File Inclusion — dizin gezinme, LFI/RFI
- Dosya Yükleme Zafiyetleri — kötü amaçlı dosya yükleme
- XML External Entity (XXE) — XML dış varlık enjeksiyonu
- Insecure Deserialization — güvensiz seri kaldırma
- Cross-Site Request Forgery (CSRF) — siteler arası istek sahteciliği
- Broken Access Control & IDOR — yetkilendirme atlatma
- Authentication Failures — kimlik doğrulama zafiyetleri
- NoSQL Injection — MongoDB vb. operatör/JS enjeksiyonu
- Server-Side Template Injection (SSTI) — şablon motoru enjeksiyonu → RCE
- LDAP Injection — dizin arama filtresi enjeksiyonu
- HTTP Request Smuggling — CL/TE uyuşmazlığı ile istek kaçakçılığı
- CORS Misconfiguration — origin yansıtma ve credential ifşası
- Open Redirect — açık yönlendirme ve OAuth token hırsızlığı
- Web Cache Poisoning & Deception — önbellek zehirleme/aldatma
- İş Mantığı Zafiyetleri — akış ve kural atlatma
- Race Condition — eşzamanlılık/TOCTOU suistimali
- GraphQL Saldırıları — introspection, alias brute, DoS
- Prototype Pollution — Object.prototype kirletme
- API Güvenliği (OWASP API Top 10) — BOLA, BFLA, kütle atama
- JWT Saldırıları — alg=none, zayıf secret, alg confusion
- OAuth 2.0 & SAML Saldırıları — SSO akış zafiyetleri, XSW
- Host Header Injection — parola sıfırlama zehirleme
- CRLF Injection & Response Splitting — başlık/yanıt enjeksiyonu
- HTTP Parameter Pollution (HPP) — çoklu parametre uyuşmazlığı
- WebSocket Saldırıları — CSWSH ve mesaj enjeksiyonu
- Clickjacking — UI redressing
- Dependency Confusion & Paket Suistimatı — tedarik zinciri
İlgili araçlar
Section titled “İlgili araçlar”Teknik sayfalarında geçen payload’lar için: XSS Payload Generator, Payload Encoder, JWT Inspector ve Clickjacking PoC.
Tüm konu başlıkları
Section titled “Tüm konu başlıkları”- 2FA/MFA/OTP Bypass
- hop-by-hop headers
- Account Takeover
- BrowExt - ClickJacking
- BrowExt - permissions & host_permissions
- BrowExt - XSS Example
- Forced Extension Load Preferences Mac Forgery Windows
- Browser Extension Pentesting Methodology
- Bypass Payment Process
- Cache Poisoning to DoS
- Cache Poisoning via URL discrepancies
- Cache Poisoning and Cache Deception
- Captcha Bypass
- Client Side Path Traversal
- Client Side Template Injection (CSTI)
- CSP bypass: self + ‘unsafe-inline’ with Iframes
- Content Security Policy (CSP) Bypass
- CORS - Misconfigurations & Bypass
- CRLF (%0D%0A) Injection
- CSRF (Cross Site Request Forgery)
- Dangling Markup - HTML scriptless injection
- SS-Leaks
- DApps - Decentralized Applications
- Basic .Net deserialization (ObjectDataProvider gadget, ExpandedWrapper, and Json.Net)
- Basic Java Deserialization (ObjectInputStream, readObject)
- Exploiting \\_\\_VIEWSTATE knowing the secrets
- Exploiting \\_\\_VIEWSTATE without knowing the secrets
- Deserialization
- Java DNS Deserialization, GadgetProbe and Java Deserialization Scanner
- Java JSF ViewState (.faces) Deserialization
- Java Signedobject Gated Deserialization
- CommonsCollection1 Payload - Java Transformers to Rutime exec() and Thread Sleep
- JNDI - Java Naming and Directory Interface & Log4Shell
- Livewire Hydration Synthesizer Abuse
- Client Side Prototype Pollution
- Express Prototype Pollution Gadgets
- NodeJS - \\\\proto\\\\ & prototype Pollution
- Prototype Pollution to RCE
- PHP - Deserialization + Autoload Classes
- Python Yaml Deserialization
- Ruby Class Pollution
- Ruby Json Pollution
- Domain/Subdomain takeover
- Email Injections
- File Inclusion/Path traversal
- LFI2RCE Via compress.zlib + PHP_STREAM_PREFER_STUDIO + Path Disclosure
- LFI2RCE via Eternal waiting
- LFI2RCE via Nginx temp files
- LFI2RCE via PHP Filters
- LFI2RCE via phpinfo()
- LFI2RCE via Segmentation Fault
- LFI2RCE Via temp file uploads
- phar:// deserialization
- LFI2RCE via PHP_SESSION_UPLOAD_PROGRESS
- PDF Upload - XXE and CORS bypass
- Formula/CSV/Doc/LaTeX/GhostScript Injection
- gRPC-Web Pentest
- Upgrade Header Smuggling
- JWT Vulnerabilities (Json Web Tokens)
- Cookie Bomb
- Cookie Jar Overflow
- Cookie Tossing
- Cookies Hacking
- HTTP Connection Contamination
- HTTP Connection Request Smuggling
- Browser HTTP Request Smuggling
- HTTP Request Smuggling / HTTP Desync Attack
- Request Smuggling in HTTP/2 Downgrades
- HTTP Response Smuggling / Desync
- IDOR
- Iframe Traps
- JSON, XML and YAML Hacking
- Login Bypass
- Login bypass List
- Mass Assignment Cwe 915
- OAuth to Account takeover
- ORM Injection
- Phone Number Injections
- Reflecting Techniques - PoCs and Polygloths CheatSheet
- Web Vulns List
- Blocking main page to steal postmessage
- Bypassing SOP with Iframes - 1
- Bypassing SOP with Iframes - 2
- PostMessage Vulnerabilities
- Steal postmessage modifying iframe location
- Proxy / WAF Protections Bypass
- Rate Limit Bypass
- Registration & Takeover Vulnerabilities
- Regular expression Denial of Service - ReDoS
- Reset/Forgotten Password Bypass
- Reverse Tab Nabbing
- RSQL Injection
- SAML Attacks
- SAML Basics
- Server Side Inclusion/Edge Side Inclusion Injection
- Soap Jax Ws Threadlocal Auth Bypass
- Cypher Injection (neo4j)
- MS Access SQL Injection
- MSSQL Injection
- MySQL injection
- MySQL File priv to SSRF/RCE
- Oracle injection
- Big Binary Files Upload (PostgreSQL)
- dblink/lo_import data exfiltration
- PostgreSQL injection
- Network - Privesc, Port Scanner and NTLM chanllenge response disclosure
- PL/pgSQL Password Bruteforce
- RCE with PostgreSQL Extensions
- RCE with PostgreSQL Languages
- Sqlmap
- Second Order Injection - SQLMap
- Cloud SSRF
- SSRF (Server Side Request Forgery)
- SSRF Vulnerable Platforms
- URL Format Bypass
- EL - Expression Language
- SSTI (Server Side Template Injection)
- Jinja2 SSTI
- Timing Attacks
- Unicode Injection
- Unicode Normalization
- UUID Insecurities
- Web Tool - WFuzz
- Web Vulnerabilities Methodology
- WebSocket Attacks
- XPATH injection
- Connection Pool by Destination Example
- Connection Pool Examples
- Cookie Bomb + Onerror XS Leak
- CSS Injection Code
- CSS Injection
- LESS Code Injection
- Event Loop Blocking + Lazy images
- XS Search
- JavaScript Execution XS Leak
- performance.now + Force heavy task
- performance.now example
- URL Max Length - Client Side
- XSLT Server Side Injection (Extensible Stylesheet Language Transformations)
- Abusing Service Workers
- Chrome Cache to XSS
- Debugging Client Side JS
- Dom Clobbering
- DOM Invader
- DOM XSS
- Iframes in XSS, CSP and SOP
- XSS (Cross Site Scripting)
- JS Hoisting
- Misc JS Tricks & Relevant Info
- PDF Injection
- Server Side XSS (Dynamic PDF)
- Shadow DOM
- Sniff Leak
- SOME - Same Origin Method Execution
- Steal Info JS
- Wasm Linear Memory Template Overwrite Xss
- XSS in Markdown
- XSSI (Cross-Site Script Inclusion)
- XXE - XEE - XML External Entity