 SwisskyandGitHub
|
434cc897f9
|
Merge pull request #857 from HackingRepo/patch-6
Add Bypass using localhost TLD
|
2026-07-23 17:07:33 +02:00 |
|
 SwisskyandGitHub
|
12e5d82ca6
|
Update localhost ping example in README
Updated example in README to use 'PayloadsAllTheThings.localhost' instead of 'ghahgahhah.localhost'.
|
2026-07-23 17:07:09 +02:00 |
|
 SwisskyandGitHub
|
c142771628
|
Merge pull request #854 from TH3L30/master
Add four-dot traversal bypass payloads to deep_traversal.txt
|
2026-07-15 10:20:27 +02:00 |
|
 SwisskyandGitHub
|
5443cbde38
|
Merge pull request #852 from timoshinoleg-eng/fix-contributing-grammar
Fix grammar in contribution guide
|
2026-06-19 13:08:18 +02:00 |
|
Swissky
|
f9fa514178
|
Fix sponsor logo
|
2026-06-06 12:27:21 +02:00 |
|
Swissky
|
9549c2140d
|
Update sponsors logo
|
2026-06-06 12:22:01 +02:00 |
|
 SwisskyandGitHub
|
601e26b569
|
Merge pull request #850 from hanxing95/add-talordata-sponsor
Add Talordata sponsor
|
2026-06-06 12:08:51 +02:00 |
|
Swissky
|
e961fef231
|
Update reference date, fix format
|
2026-04-22 16:04:22 +02:00 |
|
Swissky
|
d4e6eda4ad
|
Normalize commands, callbacks and references
|
2026-04-22 15:03:31 +02:00 |
|
 SwisskyandGitHub
|
a79b1f5692
|
Merge pull request #839 from liuwlx/codex/csv-injection-sanitize-references
docs: sanitize CSV injection examples and normalize references
|
2026-04-22 13:19:14 +02:00 |
|
 SwisskyandGitHub
|
87c2862e1a
|
Merge pull request #840 from liuwlx/codex/dependency-confusion-reference-dates
docs: normalize dependency confusion reference dates
|
2026-04-22 13:18:05 +02:00 |
|
Swissky
|
3ca2ecee21
|
GraphQL update
|
2026-04-18 17:45:41 +02:00 |
|
Swissky
|
3b069f0334
|
PTH Web Archive
|
2026-04-08 23:16:30 +02:00 |
|
Swissky
|
a41ae2c572
|
Python Path File
|
2026-04-08 22:56:27 +02:00 |
|
 SwisskyandGitHub
|
f695b0a527
|
Merge pull request #824 from noraj/patch-2
XXE zip recompression tips
|
2026-03-16 14:57:15 +01:00 |
|
Swissky
|
497fbe925b
|
Archive external reference links via Wayback Machine
Replace direct URLs in Markdown references with their
web.archive.org equivalents to prevent link rot.
|
2026-03-09 13:02:28 +01:00 |
|
Swissky
|
769b300f4f
|
SQLi Auth Bypass fix example
|
2026-03-04 19:18:40 +01:00 |
|
Swissky
|
d8e749cdc5
|
Fix title error
|
2026-03-02 18:23:58 +01:00 |
|
Swissky
|
ae9c45f474
|
Fix markdown linter
|
2026-03-02 18:07:33 +01:00 |
|
 SwisskyandGitHub
|
2e32d27e47
|
Merge pull request #820 from vladko312/master
SSTI and Insecure Deserialization improvements based on the new version of my research
|
2026-03-02 18:05:30 +01:00 |
|
 SwisskyandGitHub
|
b60551efe9
|
Fix CI/CD markdown
|
2026-03-02 18:04:20 +01:00 |
|
 SwisskyandGitHub
|
3051fc8115
|
Fix formatting issues in SpEL section of Java.md
|
2026-03-02 17:58:19 +01:00 |
|
 SwisskyandGitHub
|
3c063a8616
|
Fix formatting for SpEL and OGNL examples in Java.md
|
2026-03-02 17:57:38 +01:00 |
|
 SwisskyandGitHub
|
5c487edc05
|
Change title to 'Elixir Deserialization' and update content
Updated the title and provided a brief overview of Server-Side Template Injection in Elixir.
|
2026-03-02 17:52:24 +01:00 |
|
 SwisskyandGitHub
|
f99fe06c2f
|
Update Python.md to clarify payload compatibility
Removed note about platform-specific payloads and added information on creating a universal payload using eval.
|
2026-03-02 17:45:36 +01:00 |
|
Swissky
|
10d41d2e7d
|
XS-Leaks
|
2026-02-16 17:33:43 +01:00 |
|
Swissky
|
0b76ce0737
|
CSS Injection
|
2026-02-15 17:52:09 +01:00 |
|
 SwisskyandGitHub
|
66ef235835
|
Merge pull request #818 from HAK3R4LIFE/master
Improve clarity in 2FA bypass documentation
|
2026-02-02 12:31:27 +01:00 |
|
 SwisskyandGitHub
|
019bd50246
|
Merge pull request #819 from ocnu/patch-typo-fix
Fix small typo in README
|
2026-02-02 12:30:49 +01:00 |
|
 SwisskyandGitHub
|
50b8eb957f
|
Merge pull request #815 from pgoslatara/actup/update-actions-1768915364
chore: Update outdated GitHub Actions versions
|
2026-01-21 18:39:35 +01:00 |
|
 SwisskyandGitHub
|
a711494a64
|
Merge pull request #812 from vladko312/master
New SSTI payloads for Error-Based and Boolean-Based techniques
|
2026-01-03 22:51:40 +01:00 |
|
 SwisskyandGitHub
|
08b5c4c868
|
Unordered list style [Expected: dash; Actual: asterisk]
|
2026-01-03 22:50:37 +01:00 |
|
 SwisskyandGitHub
|
45661ef925
|
Merge pull request #809 from HackingRepo/patch-2
Update README with URL parsing examples
|
2026-01-03 16:57:44 +01:00 |
|
Swissky
|
cd548698eb
|
Reverse Proxy Misconfigurations markdown linting
|
2026-01-03 16:52:21 +01:00 |
|
 SwisskyandGitHub
|
b890ac4c9d
|
Merge pull request #813 from MegaManSec/master
add gixy-next
|
2026-01-03 16:48:55 +01:00 |
|
 SwisskyandGitHub
|
2c2552d1fe
|
Update Gixy-Next link in README.md
|
2026-01-03 16:48:14 +01:00 |
|
Swissky
|
d345536ff4
|
Fix markdown linting
|
2026-01-03 15:47:05 +01:00 |
|
 SwisskyandGitHub
|
41f2f96509
|
Merge pull request #808 from Brum3ns/master
Updated SSTI with novel obfuscation payloads
|
2026-01-03 15:44:38 +01:00 |
|
Swissky
|
bd72827e58
|
ORM leak lint + crapsecret
|
2026-01-02 19:46:23 +01:00 |
|
Swissky
|
39da0328b8
|
Indicators for deserialization
|
2025-12-12 11:32:33 +01:00 |
|
Swissky
|
ba62eed782
|
SQLite extensions
|
2025-12-07 19:52:51 +01:00 |
|
Swissky
|
ca50df2336
|
Fix markdown linting
|
2025-11-15 17:36:38 +01:00 |
|
 SwisskyandGitHub
|
80a6b5e1d0
|
Merge pull request #806 from Reelix/patch-1
Fixed missing {FILE} placeholders
|
2025-11-15 11:34:17 -05:00 |
|
 SwisskyandGitHub
|
e653e7c67b
|
Merge pull request #802 from Aaditya-Chunekar/patch-1
hacktoberfest - Update YouTube.md with new resources
|
2025-11-15 11:31:35 -05:00 |
|
 SwisskyandGitHub
|
24527a5155
|
Merge pull request #791 from piranhaAD/patch-1
Correcting the Payload for xxe ssrf
|
2025-11-15 11:19:05 -05:00 |
|
Swissky
|
832b54fd95
|
Syntax Highlighting SSTI
|
2025-11-15 17:11:42 +01:00 |
|
Swissky
|
5c0ee4c6d9
|
SQL injection hashed password + MSSQL links
|
2025-11-02 18:21:19 +01:00 |
|
Swissky
|
d49faf9874
|
Markdown Fix Lint
|
2025-10-05 18:54:42 +02:00 |
|
Swissky
|
0dc0978853
|
Brute Force and Rate Limit
|
2025-10-05 18:51:11 +02:00 |
|
 SwisskyandGitHub
|
fc06c0e13b
|
Merge pull request #797 from mbiesiad/master
Update Web Attack Surface.md
|
2025-10-02 10:40:26 -04:00 |
|
 SwisskyandGitHub
|
8cf79275a6
|
Merge pull request #795 from cclauss/patch-1
Upgrade GitHub Actions
|
2025-10-01 12:47:14 -04:00 |
|
 SwisskyandGitHub
|
bd5b09a85b
|
Merge pull request #793 from DivInstance/chore/mkdocs-edit-link-and-readme-polish
chore(docs): fix MkDocs edit link and polish README grammar
|
2025-09-19 08:48:05 -04:00 |
|
 SwisskyandGitHub
|
ebf2b0d912
|
Merge pull request #792 from pranjalpokharel7/master
Remove broken link for SQLite
|
2025-09-13 08:15:02 -04:00 |
|
Swissky
|
b391de2117
|
Lint fix
|
2025-08-14 11:09:47 +02:00 |
|
 SwisskyandGitHub
|
72df15e2e8
|
Merge pull request #786 from n3rada/master
Add Velocity SSTI payloads with base64 command support
|
2025-08-13 20:39:34 +02:00 |
|
 SwisskyandGitHub
|
2f9f87bfae
|
Merge pull request #777 from youknowwho-98/patch-1
Update NoSQL.txt
|
2025-08-13 16:07:06 +02:00 |
|
 SwisskyandGitHub
|
0c5b7c3953
|
Merge pull request #774 from 1PingSun/master
2025-04-04 Add Detecting Web Cache Deception Content
|
2025-08-13 16:04:43 +02:00 |
|
 SwisskyandGitHub
|
ad79082eb4
|
Merge pull request #784 from HackingRepo/patch-2
Update README.md
|
2025-08-13 12:54:25 +02:00 |
|
Swissky
|
cc670aa544
|
SQL injection - Fix linting errors
|
2025-08-13 12:07:35 +02:00 |
|
 SwisskyandGitHub
|
b10a11041c
|
Merge pull request #790 from KadirArslan/master
Improved Prompt Injection Section with Missing Content
|
2025-08-13 12:07:13 +02:00 |
|
 SwisskyandGitHub
|
81b3f85dc4
|
Merge pull request #776 from m14r41/patch-1
enhancement: clarified and expanded details on Second-Order SQL Injec…
|
2025-08-13 11:52:43 +02:00 |
|
 SwisskyandGitHub
|
6cb0048e22
|
Update README.md
|
2025-08-13 11:52:26 +02:00 |
|
Swissky
|
5e0b097983
|
Virtual Hosts + Encoding and Transformations
|
2025-08-12 20:59:36 +02:00 |
|
Swissky
|
cd15d85969
|
Rounding Errors
|
2025-08-03 16:32:40 +02:00 |
|
 SwisskyandGitHub
|
178949896f
|
Merge pull request #787 from clemensGooooo/master
Fixed several typos
|
2025-07-29 19:09:56 +02:00 |
|
Swissky
|
ed28a07244
|
Fix typo in table header
|
2025-07-26 22:58:51 +02:00 |
|
Swissky
|
7faf14a960
|
SQL injection - Generic Bypass (Space)
|
2025-07-26 22:54:45 +02:00 |
|
Swissky
|
ac73b0c619
|
PDO Prepared Statements
|
2025-07-26 15:21:23 +02:00 |
|
Swissky
|
61fa0020c5
|
Reverse Proxy Misconfigurations
|
2025-07-24 14:06:52 +02:00 |
|
Swissky
|
3709358334
|
Sponsors table with logo and description
|
2025-07-19 11:05:38 +02:00 |
|
Swissky
|
d1b616812b
|
Sponsors table with logo and description
|
2025-07-19 11:00:03 +02:00 |
|
Swissky
|
b9af758141
|
Fix markdownlint configuration
|
2025-07-18 14:34:03 +02:00 |
|
Swissky
|
aaf084e7f1
|
Adding SerpApi sponsor
|
2025-07-18 14:31:46 +02:00 |
|
 SwisskyandGitHub
|
dc33caaceb
|
Merge pull request #781 from stenzzor/patch-1
Update README.md
|
2025-07-10 10:26:03 +02:00 |
|
Swissky
|
3fd2f8c481
|
Headless Browser + JSON Jackson
|
2025-07-02 22:23:13 +02:00 |
|
 SwisskyandGitHub
|
aaf6bdf394
|
Merge pull request #779 from florianamette/patch-1
Add support for `||` (concatenation) operator in PostgreSQL for time based SQL injection
|
2025-05-22 22:32:26 +02:00 |
|
Swissky
|
bb8cab1ea3
|
Update Source Code Management Links
|
2025-05-10 22:04:38 +02:00 |
|
Swissky
|
7eb75cead5
|
SQLmap Custom Tamper and Preprocess Scripts
|
2025-04-09 11:14:37 +02:00 |
|
Swissky
|
8379e65ce0
|
NoSQL injection WAF
|
2025-04-01 20:22:10 +02:00 |
|
Swissky
|
f344fa50a6
|
Fix typo 2
|
2025-03-27 11:24:46 +01:00 |
|
Swissky
|
ab7e7390dc
|
Fix broken links
|
2025-03-27 11:16:36 +01:00 |
|
Swissky
|
f3be75a4da
|
Markdown Linting - Improving rules
|
2025-03-26 22:51:26 +01:00 |
|
Swissky
|
2611dd1ba3
|
Markdown Linting - SQL, Juggling, XSLT, XSS, Zip
|
2025-03-26 20:53:03 +01:00 |
|
Swissky
|
bad860d79d
|
Markdown Linting - SSI, SSRF, SSTI
|
2025-03-26 17:49:42 +01:00 |
|
Swissky
|
6963d1a21c
|
Markdown Linting - Mass Assignment, NoSQL, OAuth, Redirect
|
2025-03-26 17:06:01 +01:00 |
|
Swissky
|
5f244f4437
|
Markdown Linting - Source Code, JWT, RMI, LDAP, LaTeX
|
2025-03-26 16:48:22 +01:00 |
|
Swissky
|
d174593b4f
|
Markdown Linting - Parameters, Browsers, Deserialization Randomness
|
2025-03-26 16:33:07 +01:00 |
|
Swissky
|
e03cdfff14
|
Markdown Linting - CSV, CVE, DBS, LFI, GWT, GraphQL
|
2025-03-26 16:22:53 +01:00 |
|
Swissky
|
e6eb436eb1
|
Markdown Linting - CORS, CRLF, CSPT, CSRF, Command Injection
|
2025-03-24 16:52:42 +01:00 |
|
Swissky
|
9465e12b76
|
Markdown Linting - API, Business Logic, Clickjacking
|
2025-03-24 16:16:58 +01:00 |
|
Swissky
|
48d8dc5578
|
Markdown Linting - Methodology
|
2025-03-24 16:00:54 +01:00 |
|
Swissky
|
e25a025e13
|
DB2 Command Execution with QSYS2.QCMDEXC
|
2025-03-24 15:42:22 +01:00 |
|
Swissky
|
bc6efd695b
|
Prompt Injection Update
|
2025-03-17 19:50:19 +01:00 |
|
hacker
|
04d498aa3f
|
XXE - Fix typo
|
2025-03-17 17:02:00 +01:00 |
|
 SwisskyandGitHub
|
df8c196567
|
Merge pull request #772 from Diebbo/patch-1
FIX broken link
|
2025-03-13 10:49:21 +01:00 |
|
hacker
|
64b36854a7
|
External Variable Modification
|
2025-03-07 12:15:00 +01:00 |
|
 SwisskyandGitHub
|
0e93caed81
|
Merge pull request #769 from DoongPark/fix-parentheses
Fix extra parentheses in MySQL Injection.md
|
2025-02-19 21:08:47 +01:00 |
|
 SwisskyandGitHub
|
dd946bedc0
|
Merge pull request #768 from sehraramiz/sehraramiz-patch-xxe-1
Add missing -r flag for xxe excel file rebuilding with zip command
|
2025-02-18 21:49:42 +01:00 |
|
 SwisskyandGitHub
|
7e64eda3bf
|
Merge pull request #765 from Tednoob17/master
Update YOUTUBE.md
|
2025-02-09 21:37:19 +01:00 |
|
 SwisskyandGitHub
|
0f30c6b846
|
Update YOUTUBE.md - Fix markdown style
|
2025-02-09 21:27:49 +01:00 |
|