Web

Web Application TTPs

Table of Contents


HPING3 DoS (T1498)

Hydra Online Brute Force (T1110)

Download HTTP File and Execute (T1105)

Hashcat (T1110.002)

Malicious Javascript (T1059.007)

Execute Fileless Scripts in Golang (T1059)

Golang Reverse Shell (T1059)

Web Applications

Command Injection (T1059)

Special Characters

Ngrok for Command Injection:

Useful Commands: Linux

Useful Commands: Windows

Both Unix and Windows

Time Delay Commands

Redirecting Output

OOB (Out Of Band) Exploitation

WAF Bypasses

XSS Cheat Sheet:

https://cheatsheetseries.owasp.org/cheatsheets/XSS_Filter_Evasion_Cheat_Sheet.htmlarrow-up-right

SSRF Bypasses:

WayBack Machine Enumerator (T1596)

Python script for enumerating Wayback Machine internet archives for potential subdomains, sites, and files; specifically potential password and robots.txt files.

Or use this one-liner to screenshot web pages with EyeWitness!

Golang Webserver Banner Scanner (T1046)

This program reads in a file of IP addresses, outputting the server fingerprint to the terminal.

Minimal Golang WebDAV Server (T1071.001)

Apple Filing Protocol (AFP) (T1021)

The Apple Filing Protocol (AFP), once known as AppleTalk Filing Protocol, is a specialized network protocol included within the Apple File Service (AFS). It is designed to provide file services for macOS and the classic Mac OS.

Pre-Commit Hooks to Prevent Credential Leaks (T1552)

Scanning Git History for Secrets (T1552.001)

Truffleroasting GitHub Organizations (T1552.001)

Turning Nmap into a Vulnerability Scanner Using GitHub Actions (T1595.002)

XSS Testing (T1189)

Use these strings on all input fields and identify what remains after filtering for XSS attacks (Source: Cross Site Scripting Vulnerability Payload List):

Last updated