Some topic for self Learning


SUBMITTED BY: jaichandtanishq

DATE: Oct. 15, 2018, 9:25 a.m.

FORMAT: Text only

SIZE: 3.6 kB

HITS: 1461

  1. [+] Sql Injection Attack
  2. [+] Hibernate Query Language Injection
  3. [+] Direct OS Code Injection
  4. [+] XML Entity Injection
  5. [+] Broken Authentication and Session
  6. Management
  7. [+] Cross-Site Scripting (XSS)
  8. [+] Insecure Direct Object References
  9. [+] Security Misconfiguration
  10. [+] Sensitive Data Exposure
  11. [+] Missing Function Level Access Control
  12. [+] Cross-Site Request Forgery (CSRF)
  13. [+] Using Components with Known Vulnerabilities
  14. [+] Unvalidated Redirects and Forwards
  15. [+] Cross Site Scripting Attacks
  16. [+] Click Jacking Attacks
  17. [+] DNS Cache Poisoning
  18. [+] Symlinking – An Insider Attack
  19. [+] Cross Site Request Forgery Attacks
  20. [+] Remote Code Execution Attacks
  21. [+] Remote File inclusion
  22. [+] Local file inclusion
  23. [+] EverCookie
  24. [+] Denial oF Service Attack
  25. [+] Cookie Eviction
  26. [+] PHPwn
  27. [+] NAT Pinning
  28. [+] XSHM
  29. [+] MitM DNS Rebinding SSL/TLS Wildcards and
  30. XSS
  31. [+] Quick Proxy Detection
  32. [+] Improving HTTPS Side Channel Attacks
  33. [+] Side Channel Attacks in SSL
  34. [+] Turning XSS into Clickjacking
  35. [+] Bypassing CSRF protections with Click
  36. Jacking and
  37. [+] HTTP Parameter Pollution
  38. [+] URL Hijacking
  39. [+] Stroke Jacking
  40. [+] Fooling B64_Encode(Payload) on WAFs And
  41. Filters
  42. [+] MySQL Stacked Queries with SQL Injection.
  43. [+] Posting Raw XML cross-domain
  44. [+] Generic Cross-Browser Cross-Domain theft
  45. [+] Attacking HTTPS with Cache Injection
  46. [+] Tap Jacking
  47. [+] XSS - Track
  48. [+] Next Generation Click Jacking
  49. [+] XSSing Client-Side Dynamic HTML.
  50. [+] Stroke triggered XSS and Stroke Jacking
  51. [+] Lost iN Translation
  52. [+] Persistent Cross Interface Attacks
  53. [+] Chronofeit Phishing
  54. [+] SQLi Filter Evasion Cheat Sheet (MySQL)
  55. [+] Tabnabbing
  56. [+] UI Redressing
  57. [+] Cookie Poisoning
  58. [+] SSRF
  59. [+] Bruteforce of PHPSESSID
  60. [+] Blended Threats and JavaScript
  61. [+] Cross-Site Port Attacks
  62. [+] CAPTCHA Re-Riding Attack
  63. *Web Application Attacks List :*
  64. Arbitrary file access
  65. Binary planting
  66. Blind SQL Injection
  67. Blind XPath Injection
  68. Brute force attack
  69. Buffer overflow attack
  70. Cache Poisoning
  71. Cash Overflow
  72. Clickjacking
  73. Command injection attacks
  74. Comment Injection Attack
  75. Content Security Policy
  76. Content Spoofing
  77. Credential stuffing
  78. Cross Frame Scripting
  79. Cross Site History Manipulation (XSHM)
  80. Cross Site Tracing
  81. Cross-Site Request Forgery (CSRF)
  82. Cross Site Port Attack (XSPA)
  83. Cross-Site Scripting (XSS)
  84. Cross-User Defacement
  85. Custom Special Character Injection
  86. Denial of Service
  87. Direct Dynamic Code Evaluation (‘Eval Injection’)
  88. Execution After Redirect (EAR)
  89. Exploitation of CORS
  90. Forced browsing
  91. Form action hijacking
  92. Format string attack
  93. Full Path Disclosure
  94. Function Injection
  95. Host Header injection
  96. HTTP Response Splitting
  97. HTTP verb tampering
  98. HTML injection
  99. LDAP injection
  100. Log Injection
  101. Man-in-the-browser attack
  102. Man-in-the-middle attack
  103. Mobile code: invoking untrusted mobile code
  104. Mobile code: non-final public field
  105. Mobile code: object hijack
  106. One-Click Attack
  107. Parameter Delimiter
  108. Page takeover
  109. Path Traversal
  110. Reflected DOM Injection
  111. Regular expression Denial of Service – ReDoS
  112. Repudiation Attack
  113. Resource Injection
  114. Server-Side Includes (SSI) Injection
  115. Session fixation
  116. Session hijacking attack
  117. Session Prediction
  118. Setting Manipulation
  119. Special Element Injection
  120. SMTP injection
  121. SQL Injection
  122. SSI injection
  123. Traffic flood
  124. Web Parameter Tampering
  125. XPATH Injection
  126. XSRF or SSRF

comments powered by Disqus