├── LICENSE ├── README.md ├── bounty-1-scope.md ├── bounty-2-recon-domains.md ├── bounty-3-recon-net.md ├── ftp-vuln-vsftp.md ├── jar-file.md ├── kerb-exploit-pykek.md ├── mssql-get-svc-hash.md ├── mssql-meta.md ├── mssql-xpcmdshell.md ├── mysql-webshell.md ├── nfs-setuid.md ├── pop3-session.md ├── regex-basics.md ├── shell-upgrade.md ├── smb-exploit-eternal.md ├── smb-exploit-netapi.md ├── smb-exploit-srvos2featont.md ├── smb-info.md ├── smb-rpcclient.md ├── smb-sysvol.md ├── srv-tor.md ├── ssh-restricted-shell-bypass.md ├── tools.md ├── txfr-ftp-script.md ├── txfr-windows-smb-hash.md ├── vnc-auth-bypass.md ├── web-api-attacks.md ├── web-api.md ├── web-app-aspx.md ├── web-app-cf-lfi.md ├── web-app-drupal-notes.md ├── web-app-drupal7.md ├── web-app-wordpress-notes.md ├── web-bypass-upload.md ├── web-bypass-waf.md ├── web-dir-traversal.md ├── web-idor.md ├── web-iis-versions.md ├── web-js-lint.md ├── web-js-urls.md ├── web-php-lfi-list.md ├── web-php-lfi-windows.md ├── web-session-attacks.md ├── web-sqli-basics.md ├── web-sqli-mysql.md ├── web-sqli-orderby.md ├── web-ssl-client-certs.md ├── web-ssl-openfck.md ├── web-xss-keyboard.md └── web-xss.md /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/LICENSE -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/README.md -------------------------------------------------------------------------------- /bounty-1-scope.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/bounty-1-scope.md -------------------------------------------------------------------------------- /bounty-2-recon-domains.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/bounty-2-recon-domains.md -------------------------------------------------------------------------------- /bounty-3-recon-net.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/bounty-3-recon-net.md -------------------------------------------------------------------------------- /ftp-vuln-vsftp.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/ftp-vuln-vsftp.md -------------------------------------------------------------------------------- /jar-file.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/jar-file.md -------------------------------------------------------------------------------- /kerb-exploit-pykek.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/kerb-exploit-pykek.md -------------------------------------------------------------------------------- /mssql-get-svc-hash.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/mssql-get-svc-hash.md -------------------------------------------------------------------------------- /mssql-meta.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/mssql-meta.md -------------------------------------------------------------------------------- /mssql-xpcmdshell.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/mssql-xpcmdshell.md -------------------------------------------------------------------------------- /mysql-webshell.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/mysql-webshell.md -------------------------------------------------------------------------------- /nfs-setuid.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/nfs-setuid.md -------------------------------------------------------------------------------- /pop3-session.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/pop3-session.md -------------------------------------------------------------------------------- /regex-basics.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/regex-basics.md -------------------------------------------------------------------------------- /shell-upgrade.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/shell-upgrade.md -------------------------------------------------------------------------------- /smb-exploit-eternal.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/smb-exploit-eternal.md -------------------------------------------------------------------------------- /smb-exploit-netapi.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/smb-exploit-netapi.md -------------------------------------------------------------------------------- /smb-exploit-srvos2featont.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/smb-exploit-srvos2featont.md -------------------------------------------------------------------------------- /smb-info.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/smb-info.md -------------------------------------------------------------------------------- /smb-rpcclient.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/smb-rpcclient.md -------------------------------------------------------------------------------- /smb-sysvol.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/smb-sysvol.md -------------------------------------------------------------------------------- /srv-tor.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/srv-tor.md -------------------------------------------------------------------------------- /ssh-restricted-shell-bypass.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/ssh-restricted-shell-bypass.md -------------------------------------------------------------------------------- /tools.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/tools.md -------------------------------------------------------------------------------- /txfr-ftp-script.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/txfr-ftp-script.md -------------------------------------------------------------------------------- /txfr-windows-smb-hash.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/txfr-windows-smb-hash.md -------------------------------------------------------------------------------- /vnc-auth-bypass.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/vnc-auth-bypass.md -------------------------------------------------------------------------------- /web-api-attacks.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-api-attacks.md -------------------------------------------------------------------------------- /web-api.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-api.md -------------------------------------------------------------------------------- /web-app-aspx.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-app-aspx.md -------------------------------------------------------------------------------- /web-app-cf-lfi.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-app-cf-lfi.md -------------------------------------------------------------------------------- /web-app-drupal-notes.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-app-drupal-notes.md -------------------------------------------------------------------------------- /web-app-drupal7.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-app-drupal7.md -------------------------------------------------------------------------------- /web-app-wordpress-notes.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-app-wordpress-notes.md -------------------------------------------------------------------------------- /web-bypass-upload.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-bypass-upload.md -------------------------------------------------------------------------------- /web-bypass-waf.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-bypass-waf.md -------------------------------------------------------------------------------- /web-dir-traversal.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-dir-traversal.md -------------------------------------------------------------------------------- /web-idor.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-idor.md -------------------------------------------------------------------------------- /web-iis-versions.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-iis-versions.md -------------------------------------------------------------------------------- /web-js-lint.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-js-lint.md -------------------------------------------------------------------------------- /web-js-urls.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-js-urls.md -------------------------------------------------------------------------------- /web-php-lfi-list.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-php-lfi-list.md -------------------------------------------------------------------------------- /web-php-lfi-windows.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-php-lfi-windows.md -------------------------------------------------------------------------------- /web-session-attacks.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-session-attacks.md -------------------------------------------------------------------------------- /web-sqli-basics.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-sqli-basics.md -------------------------------------------------------------------------------- /web-sqli-mysql.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-sqli-mysql.md -------------------------------------------------------------------------------- /web-sqli-orderby.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-sqli-orderby.md -------------------------------------------------------------------------------- /web-ssl-client-certs.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-ssl-client-certs.md -------------------------------------------------------------------------------- /web-ssl-openfck.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-ssl-openfck.md -------------------------------------------------------------------------------- /web-xss-keyboard.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-xss-keyboard.md -------------------------------------------------------------------------------- /web-xss.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/stevemcilwain/secrets/HEAD/web-xss.md --------------------------------------------------------------------------------