Catálogo local de técnicas y productos
Catálogo local de técnicas y productos
Índice generado desde el corpus disponible. La presencia de una referencia no implica aplicabilidad. Usar primero el motor de aplicabilidad.
Web
Entradas disponibles: 171.
hacktricks/src/pentesting-web/2fa-bypass.md· 2fa bypasshacktricks/src/pentesting-web/abusing-hop-by-hop-headers.md· abusing hop by hop headershacktricks/src/pentesting-web/account-takeover.md· account takeoverhacktricks/src/pentesting-web/browser-extension-pentesting-methodology/README.md· browser extension pentesting methodologyhacktricks/src/pentesting-web/browser-extension-pentesting-methodology/browext-clickjacking.md· browext clickjackinghacktricks/src/pentesting-web/browser-extension-pentesting-methodology/browext-permissions-and-host_permissions.md· browext permissions and host_permissionshacktricks/src/pentesting-web/browser-extension-pentesting-methodology/browext-xss-example.md· browext xss examplehacktricks/src/pentesting-web/browser-extension-pentesting-methodology/forced-extension-load-preferences-mac-forgery-windows.md· forced extension load preferences mac forgery windowshacktricks/src/pentesting-web/bypass-payment-process.md· bypass payment processhacktricks/src/pentesting-web/cache-deception/README.md· cache deceptionhacktricks/src/pentesting-web/cache-deception/cache-poisoning-to-dos.md· cache poisoning to doshacktricks/src/pentesting-web/cache-deception/cache-poisoning-via-url-discrepancies.md· cache poisoning via url discrepancieshacktricks/src/pentesting-web/captcha-bypass.md· captcha bypasshacktricks/src/pentesting-web/clickjacking.md· clickjackinghacktricks/src/pentesting-web/client-side-path-traversal.md· client side path traversalhacktricks/src/pentesting-web/client-side-template-injection-csti.md· client side template injection cstihacktricks/src/pentesting-web/command-injection.md· command injectionhacktricks/src/pentesting-web/content-security-policy-csp-bypass/README.md· content security policy csp bypasshacktricks/src/pentesting-web/content-security-policy-csp-bypass/csp-bypass-self-+-unsafe-inline-with-iframes.md· csp bypass self + unsafe inline with iframeshacktricks/src/pentesting-web/cors-bypass.md· cors bypasshacktricks/src/pentesting-web/crlf-0d-0a.md· crlf 0d 0ahacktricks/src/pentesting-web/csrf-cross-site-request-forgery.md· csrf cross site request forgeryhacktricks/src/pentesting-web/dangling-markup-html-scriptless-injection/README.md· dangling markup html scriptless injectionhacktricks/src/pentesting-web/dangling-markup-html-scriptless-injection/ss-leaks.md· ss leakshacktricks/src/pentesting-web/dapps-DecentralizedApplications.md· dapps DecentralizedApplicationshacktricks/src/pentesting-web/dependency-confusion.md· dependency confusionhacktricks/src/pentesting-web/deserialization/README.md· deserializationhacktricks/src/pentesting-web/deserialization/basic-.net-deserialization-objectdataprovider-gadgets-expandedwrapper-and-json.net.md· basic .net deserialization objectdataprovider gadgets expandedwrapper and json.nethacktricks/src/pentesting-web/deserialization/basic-java-deserialization-objectinputstream-readobject.md· basic java deserialization objectinputstream readobjecthacktricks/src/pentesting-web/deserialization/exploiting-__viewstate-knowing-the-secret.md· exploiting __viewstate knowing the secrethacktricks/src/pentesting-web/deserialization/exploiting-__viewstate-parameter.md· exploiting __viewstate parameterhacktricks/src/pentesting-web/deserialization/java-dns-deserialization-and-gadgetprobe.md· java dns deserialization and gadgetprobehacktricks/src/pentesting-web/deserialization/java-jsf-viewstate-.faces-deserialization.md· java jsf viewstate .faces deserializationhacktricks/src/pentesting-web/deserialization/java-signedobject-gated-deserialization.md· java signedobject gated deserializationhacktricks/src/pentesting-web/deserialization/java-transformers-to-rutime-exec-payload.md· java transformers to rutime exec payloadhacktricks/src/pentesting-web/deserialization/jndi-java-naming-and-directory-interface-and-log4shell.md· jndi java naming and directory interface and log4shellhacktricks/src/pentesting-web/deserialization/livewire-hydration-synthesizer-abuse.md· livewire hydration synthesizer abusehacktricks/src/pentesting-web/deserialization/nodejs-proto-prototype-pollution/README.md· nodejs proto prototype pollutionhacktricks/src/pentesting-web/deserialization/nodejs-proto-prototype-pollution/client-side-prototype-pollution.md· client side prototype pollutionhacktricks/src/pentesting-web/deserialization/nodejs-proto-prototype-pollution/express-prototype-pollution-gadgets.md· express prototype pollution gadgetshacktricks/src/pentesting-web/deserialization/nodejs-proto-prototype-pollution/prototype-pollution-to-rce.md· prototype pollution to rcehacktricks/src/pentesting-web/deserialization/php-deserialization-+-autoload-classes.md· php deserialization + autoload classeshacktricks/src/pentesting-web/deserialization/python-yaml-deserialization.md· python yaml deserializationhacktricks/src/pentesting-web/deserialization/ruby-_json-pollution.md· ruby _json pollutionhacktricks/src/pentesting-web/deserialization/ruby-class-pollution.md· ruby class pollutionhacktricks/src/pentesting-web/domain-subdomain-takeover.md· domain subdomain takeoverhacktricks/src/pentesting-web/email-injections.md· email injectionshacktricks/src/pentesting-web/file-inclusion/README.md· file inclusionhacktricks/src/pentesting-web/file-inclusion/lfi2rce-via-compress.zlib-+-php_stream_prefer_studio-+-path-disclosure.md· lfi2rce via compress.zlib + php_stream_prefer_studio + path disclosurehacktricks/src/pentesting-web/file-inclusion/lfi2rce-via-eternal-waiting.md· lfi2rce via eternal waitinghacktricks/src/pentesting-web/file-inclusion/lfi2rce-via-nginx-temp-files.md· lfi2rce via nginx temp fileshacktricks/src/pentesting-web/file-inclusion/lfi2rce-via-php-filters.md· lfi2rce via php filtershacktricks/src/pentesting-web/file-inclusion/lfi2rce-via-phpinfo.md· lfi2rce via phpinfohacktricks/src/pentesting-web/file-inclusion/lfi2rce-via-segmentation-fault.md· lfi2rce via segmentation faulthacktricks/src/pentesting-web/file-inclusion/lfi2rce-via-temp-file-uploads.md· lfi2rce via temp file uploadshacktricks/src/pentesting-web/file-inclusion/phar-deserialization.md· phar deserializationhacktricks/src/pentesting-web/file-inclusion/via-php_session_upload_progress.md· via php_session_upload_progresshacktricks/src/pentesting-web/file-upload/README.md· file uploadhacktricks/src/pentesting-web/file-upload/pdf-upload-xxe-and-cors-bypass.md· pdf upload xxe and cors bypasshacktricks/src/pentesting-web/formula-csv-doc-latex-ghostscript-injection.md· formula csv doc latex ghostscript injectionhacktricks/src/pentesting-web/grpc-web-pentest.md· grpc web pentesthacktricks/src/pentesting-web/h2c-smuggling.md· h2c smugglinghacktricks/src/pentesting-web/hacking-jwt-json-web-tokens.md· hacking jwt json web tokenshacktricks/src/pentesting-web/hacking-with-cookies/README.md· hacking with cookieshacktricks/src/pentesting-web/hacking-with-cookies/cookie-bomb.md· cookie bombhacktricks/src/pentesting-web/hacking-with-cookies/cookie-jar-overflow.md· cookie jar overflowhacktricks/src/pentesting-web/hacking-with-cookies/cookie-tossing.md· cookie tossinghacktricks/src/pentesting-web/http-connection-contamination.md· http connection contaminationhacktricks/src/pentesting-web/http-connection-request-smuggling.md· http connection request smugglinghacktricks/src/pentesting-web/http-request-smuggling/README.md· http request smugglinghacktricks/src/pentesting-web/http-request-smuggling/browser-http-request-smuggling.md· browser http request smugglinghacktricks/src/pentesting-web/http-request-smuggling/request-smuggling-in-http-2-downgrades.md· request smuggling in http 2 downgradeshacktricks/src/pentesting-web/http-response-smuggling-desync.md· http response smuggling desynchacktricks/src/pentesting-web/idor.md· idorhacktricks/src/pentesting-web/iframe-traps.md· iframe trapshacktricks/src/pentesting-web/json-xml-yaml-hacking.md· json xml yaml hackinghacktricks/src/pentesting-web/ldap-injection.md· ldap injectionhacktricks/src/pentesting-web/login-bypass/README.md· login bypasshacktricks/src/pentesting-web/login-bypass/sql-login-bypass.md· sql login bypasshacktricks/src/pentesting-web/mass-assignment-cwe-915.md· mass assignment cwe 915hacktricks/src/pentesting-web/nosql-injection.md· nosql injectionhacktricks/src/pentesting-web/oauth-to-account-takeover.md· oauth to account takeoverhacktricks/src/pentesting-web/open-redirect.md· open redirecthacktricks/src/pentesting-web/orm-injection.md· orm injectionhacktricks/src/pentesting-web/parameter-pollution.md· parameter pollutionhacktricks/src/pentesting-web/phone-number-injections.md· phone number injectionshacktricks/src/pentesting-web/pocs-and-polygloths-cheatsheet/README.md· pocs and polygloths cheatsheethacktricks/src/pentesting-web/pocs-and-polygloths-cheatsheet/web-vulns-list.md· web vulns listhacktricks/src/pentesting-web/postmessage-vulnerabilities/README.md· postmessage vulnerabilitieshacktricks/src/pentesting-web/postmessage-vulnerabilities/blocking-main-page-to-steal-postmessage.md· blocking main page to steal postmessagehacktricks/src/pentesting-web/postmessage-vulnerabilities/bypassing-sop-with-iframes-1.md· bypassing sop with iframes 1hacktricks/src/pentesting-web/postmessage-vulnerabilities/bypassing-sop-with-iframes-2.md· bypassing sop with iframes 2hacktricks/src/pentesting-web/postmessage-vulnerabilities/steal-postmessage-modifying-iframe-location.md· steal postmessage modifying iframe locationhacktricks/src/pentesting-web/proxy-waf-protections-bypass.md· proxy waf protections bypasshacktricks/src/pentesting-web/race-condition.md· race conditionhacktricks/src/pentesting-web/rate-limit-bypass.md· rate limit bypasshacktricks/src/pentesting-web/registration-vulnerabilities.md· registration vulnerabilitieshacktricks/src/pentesting-web/regular-expression-denial-of-service-redos.md· regular expression denial of service redoshacktricks/src/pentesting-web/reset-password.md· reset passwordhacktricks/src/pentesting-web/reverse-tab-nabbing.md· reverse tab nabbinghacktricks/src/pentesting-web/rsql-injection.md· rsql injectionhacktricks/src/pentesting-web/saml-attacks/README.md· saml attackshacktricks/src/pentesting-web/saml-attacks/saml-basics.md· saml basicshacktricks/src/pentesting-web/server-side-inclusion-edge-side-inclusion-injection.md· server side inclusion edge side inclusion injectionhacktricks/src/pentesting-web/soap-jax-ws-threadlocal-auth-bypass.md· soap jax ws threadlocal auth bypasshacktricks/src/pentesting-web/sql-injection/README.md· sql injectionhacktricks/src/pentesting-web/sql-injection/cypher-injection-neo4j.md· cypher injection neo4jhacktricks/src/pentesting-web/sql-injection/ms-access-sql-injection.md· ms access sql injectionhacktricks/src/pentesting-web/sql-injection/mssql-injection.md· mssql injectionhacktricks/src/pentesting-web/sql-injection/mysql-injection/README.md· mysql injectionhacktricks/src/pentesting-web/sql-injection/mysql-injection/mysql-ssrf.md· mysql ssrfhacktricks/src/pentesting-web/sql-injection/oracle-injection.md· oracle injectionhacktricks/src/pentesting-web/sql-injection/postgresql-injection/README.md· postgresql injectionhacktricks/src/pentesting-web/sql-injection/postgresql-injection/big-binary-files-upload-postgresql.md· big binary files upload postgresqlhacktricks/src/pentesting-web/sql-injection/postgresql-injection/dblink-lo_import-data-exfiltration.md· dblink lo_import data exfiltrationhacktricks/src/pentesting-web/sql-injection/postgresql-injection/network-privesc-port-scanner-and-ntlm-chanllenge-response-disclosure.md· network privesc port scanner and ntlm chanllenge response disclosurehacktricks/src/pentesting-web/sql-injection/postgresql-injection/pl-pgsql-password-bruteforce.md· pl pgsql password bruteforcehacktricks/src/pentesting-web/sql-injection/postgresql-injection/rce-with-postgresql-extensions.md· rce with postgresql extensionshacktricks/src/pentesting-web/sql-injection/postgresql-injection/rce-with-postgresql-languages.md· rce with postgresql languageshacktricks/src/pentesting-web/sql-injection/sqlmap/README.md· sqlmaphacktricks/src/pentesting-web/sql-injection/sqlmap/second-order-injection-sqlmap.md· second order injection sqlmaphacktricks/src/pentesting-web/sql-injection/sqlmap.md· sqlmaphacktricks/src/pentesting-web/ssrf-server-side-request-forgery/README.md· ssrf server side request forgeryhacktricks/src/pentesting-web/ssrf-server-side-request-forgery/cloud-ssrf.md· cloud ssrfhacktricks/src/pentesting-web/ssrf-server-side-request-forgery/ssrf-vulnerable-platforms.md· ssrf vulnerable platformshacktricks/src/pentesting-web/ssrf-server-side-request-forgery/url-format-bypass.md· url format bypasshacktricks/src/pentesting-web/ssti-server-side-template-injection/README.md· ssti server side template injectionhacktricks/src/pentesting-web/ssti-server-side-template-injection/el-expression-language.md· el expression languagehacktricks/src/pentesting-web/ssti-server-side-template-injection/jinja2-ssti.md· jinja2 sstihacktricks/src/pentesting-web/timing-attacks.md· timing attackshacktricks/src/pentesting-web/unicode-injection/README.md· unicode injectionhacktricks/src/pentesting-web/unicode-injection/unicode-normalization.md· unicode normalizationhacktricks/src/pentesting-web/uuid-insecurities.md· uuid insecuritieshacktricks/src/pentesting-web/web-tool-wfuzz.md· web tool wfuzzhacktricks/src/pentesting-web/web-vulnerabilities-methodology.md· web vulnerabilities methodologyhacktricks/src/pentesting-web/websocket-attacks.md· websocket attackshacktricks/src/pentesting-web/xpath-injection.md· xpath injectionhacktricks/src/pentesting-web/xs-search/README.md· xs searchhacktricks/src/pentesting-web/xs-search/connection-pool-by-destination-example.md· connection pool by destination examplehacktricks/src/pentesting-web/xs-search/connection-pool-example.md· connection pool examplehacktricks/src/pentesting-web/xs-search/cookie-bomb-+-onerror-xs-leak.md· cookie bomb + onerror xs leakhacktricks/src/pentesting-web/xs-search/css-injection/README.md· css injectionhacktricks/src/pentesting-web/xs-search/css-injection/css-injection-code.md· css injection codehacktricks/src/pentesting-web/xs-search/css-injection/less-code-injection.md· less code injectionhacktricks/src/pentesting-web/xs-search/event-loop-blocking-+-lazy-images.md· event loop blocking + lazy imageshacktricks/src/pentesting-web/xs-search/javascript-execution-xs-leak.md· javascript execution xs leakhacktricks/src/pentesting-web/xs-search/performance.now-+-force-heavy-task.md· performance.now + force heavy taskhacktricks/src/pentesting-web/xs-search/performance.now-example.md· performance.now examplehacktricks/src/pentesting-web/xs-search/url-max-length-client-side.md· url max length client sidehacktricks/src/pentesting-web/xslt-server-side-injection-extensible-stylesheet-language-transformations.md· xslt server side injection extensible stylesheet language transformationshacktricks/src/pentesting-web/xss-cross-site-scripting/README.md· xss cross site scriptinghacktricks/src/pentesting-web/xss-cross-site-scripting/abusing-service-workers.md· abusing service workershacktricks/src/pentesting-web/xss-cross-site-scripting/chrome-cache-to-xss.md· chrome cache to xsshacktricks/src/pentesting-web/xss-cross-site-scripting/debugging-client-side-js.md· debugging client side jshacktricks/src/pentesting-web/xss-cross-site-scripting/dom-clobbering.md· dom clobberinghacktricks/src/pentesting-web/xss-cross-site-scripting/dom-invader.md· dom invaderhacktricks/src/pentesting-web/xss-cross-site-scripting/dom-xss.md· dom xsshacktricks/src/pentesting-web/xss-cross-site-scripting/iframes-in-xss-and-csp.md· iframes in xss and csphacktricks/src/pentesting-web/xss-cross-site-scripting/integer-overflow.md· integer overflowhacktricks/src/pentesting-web/xss-cross-site-scripting/js-hoisting.md· js hoistinghacktricks/src/pentesting-web/xss-cross-site-scripting/other-js-tricks.md· other js trickshacktricks/src/pentesting-web/xss-cross-site-scripting/pdf-injection.md· pdf injectionhacktricks/src/pentesting-web/xss-cross-site-scripting/server-side-xss-dynamic-pdf.md· server side xss dynamic pdfhacktricks/src/pentesting-web/xss-cross-site-scripting/shadow-dom.md· shadow domhacktricks/src/pentesting-web/xss-cross-site-scripting/sniff-leak.md· sniff leakhacktricks/src/pentesting-web/xss-cross-site-scripting/some-same-origin-method-execution.md· some same origin method executionhacktricks/src/pentesting-web/xss-cross-site-scripting/steal-info-js.md· steal info jshacktricks/src/pentesting-web/xss-cross-site-scripting/wasm-linear-memory-template-overwrite-xss.md· wasm linear memory template overwrite xsshacktricks/src/pentesting-web/xss-cross-site-scripting/xss-in-markdown.md· xss in markdownhacktricks/src/pentesting-web/xssi-cross-site-script-inclusion.md· xssi cross site script inclusionhacktricks/src/pentesting-web/xxe-xee-xml-external-entity.md· xxe xee xml external entity
Productos web
Entradas disponibles: 89.
hacktricks/src/network-services-pentesting/pentesting-web/403-and-401-bypasses.md· 403 and 401 bypasseshacktricks/src/network-services-pentesting/pentesting-web/README.md· pentesting webhacktricks/src/network-services-pentesting/pentesting-web/aem-adobe-experience-cloud.md· aem adobe experience cloudhacktricks/src/network-services-pentesting/pentesting-web/angular.md· angularhacktricks/src/network-services-pentesting/pentesting-web/apache-tapestry.md· apache tapestryhacktricks/src/network-services-pentesting/pentesting-web/apache.md· apachehacktricks/src/network-services-pentesting/pentesting-web/artifactory-hacking-guide.md· artifactory hacking guidehacktricks/src/network-services-pentesting/pentesting-web/bolt-cms.md· bolt cmshacktricks/src/network-services-pentesting/pentesting-web/buckets/README.md· bucketshacktricks/src/network-services-pentesting/pentesting-web/buckets/firebase-database.md· firebase databasehacktricks/src/network-services-pentesting/pentesting-web/cgi.md· cgihacktricks/src/network-services-pentesting/pentesting-web/code-review-tools.md· code review toolshacktricks/src/network-services-pentesting/pentesting-web/custom-protocols.md· custom protocolshacktricks/src/network-services-pentesting/pentesting-web/django.md· djangohacktricks/src/network-services-pentesting/pentesting-web/dotnet-soap-wsdl-client-exploitation.md· dotnet soap wsdl client exploitationhacktricks/src/network-services-pentesting/pentesting-web/dotnetnuke-dnn.md· dotnetnuke dnnhacktricks/src/network-services-pentesting/pentesting-web/drupal/README.md· drupalhacktricks/src/network-services-pentesting/pentesting-web/drupal/drupal-rce.md· drupal rcehacktricks/src/network-services-pentesting/pentesting-web/electron-desktop-apps/README.md· electron desktop appshacktricks/src/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-electron-internal-code.md· electron contextisolation rce via electron internal codehacktricks/src/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-ipc.md· electron contextisolation rce via ipchacktricks/src/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-preload-code.md· electron contextisolation rce via preload codehacktricks/src/network-services-pentesting/pentesting-web/flask.md· flaskhacktricks/src/network-services-pentesting/pentesting-web/fortinet-fortiweb.md· fortinet fortiwebhacktricks/src/network-services-pentesting/pentesting-web/geonetwork.md· geonetworkhacktricks/src/network-services-pentesting/pentesting-web/git.md· githacktricks/src/network-services-pentesting/pentesting-web/golang.md· golanghacktricks/src/network-services-pentesting/pentesting-web/grafana.md· grafanahacktricks/src/network-services-pentesting/pentesting-web/graphql.md· graphqlhacktricks/src/network-services-pentesting/pentesting-web/h2-java-sql-database.md· h2 java sql databasehacktricks/src/network-services-pentesting/pentesting-web/iis-internet-information-services.md· iis internet information serviceshacktricks/src/network-services-pentesting/pentesting-web/imagemagick-security.md· imagemagick securityhacktricks/src/network-services-pentesting/pentesting-web/ispconfig.md· ispconfighacktricks/src/network-services-pentesting/pentesting-web/jboss.md· jbosshacktricks/src/network-services-pentesting/pentesting-web/jira.md· jirahacktricks/src/network-services-pentesting/pentesting-web/joomla.md· joomlahacktricks/src/network-services-pentesting/pentesting-web/jsp.md· jsphacktricks/src/network-services-pentesting/pentesting-web/laravel.md· laravelhacktricks/src/network-services-pentesting/pentesting-web/meshcentral.md· meshcentralhacktricks/src/network-services-pentesting/pentesting-web/microsoft-sharepoint.md· microsoft sharepointhacktricks/src/network-services-pentesting/pentesting-web/moodle.md· moodlehacktricks/src/network-services-pentesting/pentesting-web/nextjs.md· nextjshacktricks/src/network-services-pentesting/pentesting-web/nginx.md· nginxhacktricks/src/network-services-pentesting/pentesting-web/nodejs-express.md· nodejs expresshacktricks/src/network-services-pentesting/pentesting-web/perl-tricks.md· perl trickshacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/README.md· php tricks esphacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-rce-abusing-object-creation-new-usd_get-a-usd_get-b.md· php rce abusing object creation new usd_get a usd_get bhacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-ssrf.md· php ssrfhacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/README.md· php useful functions disable_functions open_basedir bypasshacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-dl-function.md· disable_functions bypass dl functionhacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-imagick-less-than-3.3.0-php-greater-than-5.4-exploit.md· disable_functions bypass imagick less than 3.3.0 php greater than 5.4 exploithacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-mod_cgi.md· disable_functions bypass mod_cgihacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-4-greater-than-4.2.0-php-5-pcntl_exec.md· disable_functions bypass php 4 greater than 4.2.0 php 5 pcntl_exechacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2-fopen-exploit.md· disable_functions bypass php 5.2 fopen exploithacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.3-win32std-ext-protections-bypass.md· disable_functions bypass php 5.2.3 win32std ext protections bypasshacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-5.2.4-and-5.2.5-php-curl.md· disable_functions bypass php 5.2.4 and 5.2.5 php curlhacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-7.0-7.4-nix-only.md· disable_functions bypass php 7.0 7.4 nix onlyhacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-fpm-fastcgi.md· disable_functions bypass php fpm fastcgihacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-less-than-5.2.9-on-windows.md· disable_functions bypass php less than 5.2.9 on windowshacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-perl-extension-safe_mode-bypass-exploit.md· disable_functions bypass php perl extension safe_mode bypass exploithacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-php-safe_mode-bypass-via-proc_open-and-custom-environment-exploit.md· disable_functions bypass php safe_mode bypass via proc_open and custom environment exploithacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-bypass-via-mem.md· disable_functions bypass via memhacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.2.4-ioncube-extension-exploit.md· disable_functions php 5.2.4 ioncube extension exploithacktricks/src/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass/disable_functions-php-5.x-shellshock-exploit.md· disable_functions php 5.x shellshock exploithacktricks/src/network-services-pentesting/pentesting-web/prestashop.md· prestashophacktricks/src/network-services-pentesting/pentesting-web/proxmox-ve.md· proxmox vehacktricks/src/network-services-pentesting/pentesting-web/put-method-webdav.md· put method webdavhacktricks/src/network-services-pentesting/pentesting-web/python.md· pythonhacktricks/src/network-services-pentesting/pentesting-web/rocket-chat.md· rocket chathacktricks/src/network-services-pentesting/pentesting-web/roundcube.md· roundcubehacktricks/src/network-services-pentesting/pentesting-web/ruby-tricks.md· ruby trickshacktricks/src/network-services-pentesting/pentesting-web/servicenow.md· servicenowhacktricks/src/network-services-pentesting/pentesting-web/sitecore/README.md· sitecorehacktricks/src/network-services-pentesting/pentesting-web/special-http-headers.md· special http headershacktricks/src/network-services-pentesting/pentesting-web/spring-actuators.md· spring actuatorshacktricks/src/network-services-pentesting/pentesting-web/symphony.md· symphonyhacktricks/src/network-services-pentesting/pentesting-web/telerik-ui-aspnet-ajax-unsafe-reflection-webresource-axd.md· telerik ui aspnet ajax unsafe reflection webresource axdhacktricks/src/network-services-pentesting/pentesting-web/tomcat/README.md· tomcathacktricks/src/network-services-pentesting/pentesting-web/traefik.md· traefikhacktricks/src/network-services-pentesting/pentesting-web/uncovering-cloudflare.md· uncovering cloudflarehacktricks/src/network-services-pentesting/pentesting-web/veeam-service-provider-console.md· veeam service provider consolehacktricks/src/network-services-pentesting/pentesting-web/vmware-esx-vcenter....md· vmware esx vcenter…hacktricks/src/network-services-pentesting/pentesting-web/vuejs.md· vuejshacktricks/src/network-services-pentesting/pentesting-web/web-api-pentesting.md· web api pentestinghacktricks/src/network-services-pentesting/pentesting-web/werkzeug.md· werkzeughacktricks/src/network-services-pentesting/pentesting-web/wordpress.md· wordpresshacktricks/src/network-services-pentesting/pentesting-web/wsgi.md· wsgihacktricks/src/network-services-pentesting/pentesting-web/zabbix.md· zabbixhacktricks/src/network-services-pentesting/pentesting-web/zoneminder-motioneye-motion.md· zoneminder motioneye motion
Servicios de red
Entradas disponibles: 111.
hacktricks/src/network-services-pentesting/10000-network-data-management-protocol-ndmp.md· 10000 network data management protocol ndmphacktricks/src/network-services-pentesting/1026-pentesting-rusersd.md· 1026 pentesting rusersdhacktricks/src/network-services-pentesting/1080-pentesting-socks.md· 1080 pentesting sockshacktricks/src/network-services-pentesting/1099-pentesting-java-rmi.md· 1099 pentesting java rmihacktricks/src/network-services-pentesting/11211-memcache/README.md· 11211 memcachehacktricks/src/network-services-pentesting/11211-memcache/memcache-commands.md· memcache commandshacktricks/src/network-services-pentesting/113-pentesting-ident.md· 113 pentesting identhacktricks/src/network-services-pentesting/12346-udp-pentesting-cisco-sd-wan-control-plane.md· 12346 udp pentesting cisco sd wan control planehacktricks/src/network-services-pentesting/135-pentesting-msrpc.md· 135 pentesting msrpchacktricks/src/network-services-pentesting/137-138-139-pentesting-netbios.md· 137 138 139 pentesting netbioshacktricks/src/network-services-pentesting/1414-pentesting-ibmmq.md· 1414 pentesting ibmmqhacktricks/src/network-services-pentesting/1521-1522-1529-pentesting-oracle-listener.md· 1521 1522 1529 pentesting oracle listenerhacktricks/src/network-services-pentesting/15672-pentesting-rabbitmq-management.md· 15672 pentesting rabbitmq managementhacktricks/src/network-services-pentesting/1723-pentesting-pptp.md· 1723 pentesting pptphacktricks/src/network-services-pentesting/1883-pentesting-mqtt-mosquitto.md· 1883 pentesting mqtt mosquittohacktricks/src/network-services-pentesting/2375-pentesting-docker.md· 2375 pentesting dockerhacktricks/src/network-services-pentesting/24007-24008-24009-49152-pentesting-glusterfs.md· 24007 24008 24009 49152 pentesting glusterfshacktricks/src/network-services-pentesting/27017-27018-mongodb.md· 27017 27018 mongodbhacktricks/src/network-services-pentesting/3128-pentesting-squid.md· 3128 pentesting squidhacktricks/src/network-services-pentesting/32100-udp-pentesting-pppp-cs2-p2p-cameras.md· 32100 udp pentesting pppp cs2 p2p camerashacktricks/src/network-services-pentesting/3260-pentesting-iscsi.md· 3260 pentesting iscsihacktricks/src/network-services-pentesting/3299-pentesting-saprouter.md· 3299 pentesting saprouterhacktricks/src/network-services-pentesting/3632-pentesting-distcc.md· 3632 pentesting distcchacktricks/src/network-services-pentesting/3690-pentesting-subversion-svn-server.md· 3690 pentesting subversion svn serverhacktricks/src/network-services-pentesting/3702-udp-pentesting-ws-discovery.md· 3702 udp pentesting ws discoveryhacktricks/src/network-services-pentesting/4222-pentesting-nats.md· 4222 pentesting natshacktricks/src/network-services-pentesting/43-pentesting-whois.md· 43 pentesting whoishacktricks/src/network-services-pentesting/4369-pentesting-erlang-port-mapper-daemon-epmd.md· 4369 pentesting erlang port mapper daemon epmdhacktricks/src/network-services-pentesting/44134-pentesting-tiller-helm.md· 44134 pentesting tiller helmhacktricks/src/network-services-pentesting/44818-ethernetip.md· 44818 ethernetiphacktricks/src/network-services-pentesting/47808-udp-bacnet.md· 47808 udp bacnethacktricks/src/network-services-pentesting/4786-cisco-smart-install.md· 4786 cisco smart installhacktricks/src/network-services-pentesting/4840-pentesting-opc-ua.md· 4840 pentesting opc uahacktricks/src/network-services-pentesting/49-pentesting-tacacs+.md· 49 pentesting tacacs+hacktricks/src/network-services-pentesting/5000-pentesting-docker-registry.md· 5000 pentesting docker registryhacktricks/src/network-services-pentesting/50030-50060-50070-50075-50090-pentesting-hadoop.md· 50030 50060 50070 50075 50090 pentesting hadoophacktricks/src/network-services-pentesting/512-pentesting-rexec.md· 512 pentesting rexechacktricks/src/network-services-pentesting/515-pentesting-line-printer-daemon-lpd.md· 515 pentesting line printer daemon lpdhacktricks/src/network-services-pentesting/5353-udp-multicast-dns-mdns.md· 5353 udp multicast dns mdnshacktricks/src/network-services-pentesting/5439-pentesting-redshift.md· 5439 pentesting redshifthacktricks/src/network-services-pentesting/554-8554-pentesting-rtsp.md· 554 8554 pentesting rtsphacktricks/src/network-services-pentesting/5555-android-debug-bridge.md· 5555 android debug bridgehacktricks/src/network-services-pentesting/5601-pentesting-kibana.md· 5601 pentesting kibanahacktricks/src/network-services-pentesting/5671-5672-pentesting-amqp.md· 5671 5672 pentesting amqphacktricks/src/network-services-pentesting/584-pentesting-afp.md· 584 pentesting afphacktricks/src/network-services-pentesting/5984-pentesting-couchdb.md· 5984 pentesting couchdbhacktricks/src/network-services-pentesting/5985-5986-pentesting-omi.md· 5985 5986 pentesting omihacktricks/src/network-services-pentesting/5985-5986-pentesting-winrm.md· 5985 5986 pentesting winrmhacktricks/src/network-services-pentesting/6000-pentesting-x11.md· 6000 pentesting x11hacktricks/src/network-services-pentesting/623-udp-ipmi.md· 623 udp ipmihacktricks/src/network-services-pentesting/6379-pentesting-redis.md· 6379 pentesting redishacktricks/src/network-services-pentesting/69-udp-tftp.md· 69 udp tftphacktricks/src/network-services-pentesting/7-tcp-udp-pentesting-echo.md· 7 tcp udp pentesting echohacktricks/src/network-services-pentesting/700-pentesting-epp.md· 700 pentesting epphacktricks/src/network-services-pentesting/8009-pentesting-apache-jserv-protocol-ajp.md· 8009 pentesting apache jserv protocol ajphacktricks/src/network-services-pentesting/8086-pentesting-influxdb.md· 8086 pentesting influxdbhacktricks/src/network-services-pentesting/8089-splunkd.md· 8089 splunkdhacktricks/src/network-services-pentesting/8333-18333-38333-18444-pentesting-bitcoin.md· 8333 18333 38333 18444 pentesting bitcoinhacktricks/src/network-services-pentesting/873-pentesting-rsync.md· 873 pentesting rsynchacktricks/src/network-services-pentesting/9000-pentesting-fastcgi.md· 9000 pentesting fastcgihacktricks/src/network-services-pentesting/9001-pentesting-hsqldb.md· 9001 pentesting hsqldbhacktricks/src/network-services-pentesting/9100-pjl.md· 9100 pjlhacktricks/src/network-services-pentesting/9200-pentesting-elasticsearch.md· 9200 pentesting elasticsearchhacktricks/src/network-services-pentesting/cassandra.md· cassandrahacktricks/src/network-services-pentesting/ipsec-ike-vpn-pentesting.md· ipsec ike vpn pentestinghacktricks/src/network-services-pentesting/nfs-service-pentesting.md· nfs service pentestinghacktricks/src/network-services-pentesting/pentesting-264-check-point-firewall-1.md· pentesting 264 check point firewall 1hacktricks/src/network-services-pentesting/pentesting-631-internet-printing-protocol-ipp.md· pentesting 631 internet printing protocol ipphacktricks/src/network-services-pentesting/pentesting-compaq-hp-insight-manager.md· pentesting compaq hp insight managerhacktricks/src/network-services-pentesting/pentesting-dns.md· pentesting dnshacktricks/src/network-services-pentesting/pentesting-finger.md· pentesting fingerhacktricks/src/network-services-pentesting/pentesting-ftp/README.md· pentesting ftphacktricks/src/network-services-pentesting/pentesting-ftp/ftp-bounce-attack.md· ftp bounce attackhacktricks/src/network-services-pentesting/pentesting-ftp/ftp-bounce-download-2oftp-file.md· ftp bounce download 2oftp filehacktricks/src/network-services-pentesting/pentesting-imap.md· pentesting imaphacktricks/src/network-services-pentesting/pentesting-irc.md· pentesting irchacktricks/src/network-services-pentesting/pentesting-iso-8583-payment-sockets.md· pentesting iso 8583 payment socketshacktricks/src/network-services-pentesting/pentesting-jdwp-java-debug-wire-protocol.md· pentesting jdwp java debug wire protocolhacktricks/src/network-services-pentesting/pentesting-kerberos-88/README.md· pentesting kerberos 88hacktricks/src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux.md· harvesting tickets from linuxhacktricks/src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-windows.md· harvesting tickets from windowshacktricks/src/network-services-pentesting/pentesting-ldap.md· pentesting ldaphacktricks/src/network-services-pentesting/pentesting-modbus.md· pentesting modbushacktricks/src/network-services-pentesting/pentesting-mssql-microsoft-sql-server/README.md· pentesting mssql microsoft sql serverhacktricks/src/network-services-pentesting/pentesting-mssql-microsoft-sql-server/types-of-mssql-users.md· types of mssql usershacktricks/src/network-services-pentesting/pentesting-mysql.md· pentesting mysqlhacktricks/src/network-services-pentesting/pentesting-ntp.md· pentesting ntphacktricks/src/network-services-pentesting/pentesting-pop.md· pentesting pophacktricks/src/network-services-pentesting/pentesting-postgresql.md· pentesting postgresqlhacktricks/src/network-services-pentesting/pentesting-rdp.md· pentesting rdphacktricks/src/network-services-pentesting/pentesting-remote-gdbserver.md· pentesting remote gdbserverhacktricks/src/network-services-pentesting/pentesting-rlogin.md· pentesting rloginhacktricks/src/network-services-pentesting/pentesting-rpcbind.md· pentesting rpcbindhacktricks/src/network-services-pentesting/pentesting-rsh.md· pentesting rshhacktricks/src/network-services-pentesting/pentesting-sap.md· pentesting saphacktricks/src/network-services-pentesting/pentesting-smb/README.md· pentesting smbhacktricks/src/network-services-pentesting/pentesting-smb/ksmbd-attack-surface-and-fuzzing-syzkaller.md· ksmbd attack surface and fuzzing syzkallerhacktricks/src/network-services-pentesting/pentesting-smb/rpcclient-enumeration.md· rpcclient enumerationhacktricks/src/network-services-pentesting/pentesting-smtp/README.md· pentesting smtphacktricks/src/network-services-pentesting/pentesting-smtp/smtp-commands.md· smtp commandshacktricks/src/network-services-pentesting/pentesting-smtp/smtp-smuggling.md· smtp smugglinghacktricks/src/network-services-pentesting/pentesting-snmp/README.md· pentesting snmphacktricks/src/network-services-pentesting/pentesting-snmp/cisco-snmp.md· cisco snmphacktricks/src/network-services-pentesting/pentesting-snmp/snmp-rce.md· snmp rcehacktricks/src/network-services-pentesting/pentesting-ssh.md· pentesting sshhacktricks/src/network-services-pentesting/pentesting-telnet.md· pentesting telnethacktricks/src/network-services-pentesting/pentesting-veeam-backup-and-replication.md· pentesting veeam backup and replicationhacktricks/src/network-services-pentesting/pentesting-vnc.md· pentesting vnchacktricks/src/network-services-pentesting/pentesting-voip/README.md· pentesting voiphacktricks/src/network-services-pentesting/pentesting-voip/basic-voip-protocols/README.md· basic voip protocolshacktricks/src/network-services-pentesting/pentesting-voip/basic-voip-protocols/sip-session-initiation-protocol.md· sip session initiation protocol
Móvil
Entradas disponibles: 67.
hacktricks/src/mobile-pentesting/android-app-pentesting/README.md· android app pentestinghacktricks/src/mobile-pentesting/android-app-pentesting/abusing-android-media-pipelines-image-parsers.md· abusing android media pipelines image parsershacktricks/src/mobile-pentesting/android-app-pentesting/accessibility-services-abuse.md· accessibility services abusehacktricks/src/mobile-pentesting/android-app-pentesting/adb-commands.md· adb commandshacktricks/src/mobile-pentesting/android-app-pentesting/android-anti-instrumentation-and-ssl-pinning-bypass.md· android anti instrumentation and ssl pinning bypasshacktricks/src/mobile-pentesting/android-app-pentesting/android-application-level-virtualization.md· android application level virtualizationhacktricks/src/mobile-pentesting/android-app-pentesting/android-applications-basics.md· android applications basicshacktricks/src/mobile-pentesting/android-app-pentesting/android-enterprise-work-profile-bypass.md· android enterprise work profile bypasshacktricks/src/mobile-pentesting/android-app-pentesting/android-hce-nfc-emv-relay-attacks.md· android hce nfc emv relay attackshacktricks/src/mobile-pentesting/android-app-pentesting/android-physical-attacks.md· android physical attackshacktricks/src/mobile-pentesting/android-app-pentesting/android-task-hijacking.md· android task hijackinghacktricks/src/mobile-pentesting/android-app-pentesting/android-vpn-bypass.md· android vpn bypasshacktricks/src/mobile-pentesting/android-app-pentesting/apk-decompilers.md· apk decompilershacktricks/src/mobile-pentesting/android-app-pentesting/avd-android-virtual-device.md· avd android virtual devicehacktricks/src/mobile-pentesting/android-app-pentesting/baseband-and-soc-isolation-exploitation.md· baseband and soc isolation exploitationhacktricks/src/mobile-pentesting/android-app-pentesting/bypass-biometric-authentication-android.md· bypass biometric authentication androidhacktricks/src/mobile-pentesting/android-app-pentesting/content-protocol.md· content protocolhacktricks/src/mobile-pentesting/android-app-pentesting/drozer-tutorial/README.md· drozer tutorialhacktricks/src/mobile-pentesting/android-app-pentesting/drozer-tutorial/exploiting-content-providers.md· exploiting content providershacktricks/src/mobile-pentesting/android-app-pentesting/exploiting-a-debuggeable-applciation.md· exploiting a debuggeable applciationhacktricks/src/mobile-pentesting/android-app-pentesting/firmware-level-zygote-backdoor-libandroid_runtime.md· firmware level zygote backdoor libandroid_runtimehacktricks/src/mobile-pentesting/android-app-pentesting/flutter.md· flutterhacktricks/src/mobile-pentesting/android-app-pentesting/frida-tutorial/README.md· frida tutorialhacktricks/src/mobile-pentesting/android-app-pentesting/frida-tutorial/frida-tutorial-1.md· frida tutorial 1hacktricks/src/mobile-pentesting/android-app-pentesting/frida-tutorial/frida-tutorial-2.md· frida tutorial 2hacktricks/src/mobile-pentesting/android-app-pentesting/frida-tutorial/objection-tutorial.md· objection tutorialhacktricks/src/mobile-pentesting/android-app-pentesting/frida-tutorial/owaspuncrackable-1.md· owaspuncrackable 1hacktricks/src/mobile-pentesting/android-app-pentesting/google-ctf-2018-shall-we-play-a-game.md· google ctf 2018 shall we play a gamehacktricks/src/mobile-pentesting/android-app-pentesting/in-memory-jni-shellcode-execution.md· in memory jni shellcode executionhacktricks/src/mobile-pentesting/android-app-pentesting/inputmethodservice-ime-abuse.md· inputmethodservice ime abusehacktricks/src/mobile-pentesting/android-app-pentesting/insecure-in-app-update-rce.md· insecure in app update rcehacktricks/src/mobile-pentesting/android-app-pentesting/install-burp-certificate.md· install burp certificatehacktricks/src/mobile-pentesting/android-app-pentesting/intent-injection.md· intent injectionhacktricks/src/mobile-pentesting/android-app-pentesting/make-apk-accept-ca-certificate.md· make apk accept ca certificatehacktricks/src/mobile-pentesting/android-app-pentesting/manual-deobfuscation.md· manual deobfuscationhacktricks/src/mobile-pentesting/android-app-pentesting/play-integrity-attestation-bypass.md· play integrity attestation bypasshacktricks/src/mobile-pentesting/android-app-pentesting/react-native-application.md· react native applicationhacktricks/src/mobile-pentesting/android-app-pentesting/reversing-native-libraries.md· reversing native librarieshacktricks/src/mobile-pentesting/android-app-pentesting/shizuku-privileged-api.md· shizuku privileged apihacktricks/src/mobile-pentesting/android-app-pentesting/smali-changes.md· smali changeshacktricks/src/mobile-pentesting/android-app-pentesting/spoofing-your-location-in-play-store.md· spoofing your location in play storehacktricks/src/mobile-pentesting/android-app-pentesting/tapjacking.md· tapjackinghacktricks/src/mobile-pentesting/android-app-pentesting/webview-attacks.md· webview attackshacktricks/src/mobile-pentesting/android-checklist.md· android checklisthacktricks/src/mobile-pentesting/cordova-apps.md· cordova appshacktricks/src/mobile-pentesting/ios-pentesting/README.md· ios pentestinghacktricks/src/mobile-pentesting/ios-pentesting/air-keyboard-remote-input-injection.md· air keyboard remote input injectionhacktricks/src/mobile-pentesting/ios-pentesting/basic-ios-testing-operations.md· basic ios testing operationshacktricks/src/mobile-pentesting/ios-pentesting/burp-configuration-for-ios.md· burp configuration for ioshacktricks/src/mobile-pentesting/ios-pentesting/extracting-entitlements-from-compiled-application.md· extracting entitlements from compiled applicationhacktricks/src/mobile-pentesting/ios-pentesting/frida-configuration-in-ios.md· frida configuration in ioshacktricks/src/mobile-pentesting/ios-pentesting/ios-app-extensions.md· ios app extensionshacktricks/src/mobile-pentesting/ios-pentesting/ios-basics.md· ios basicshacktricks/src/mobile-pentesting/ios-pentesting/ios-custom-uri-handlers-deeplinks-custom-schemes.md· ios custom uri handlers deeplinks custom schemeshacktricks/src/mobile-pentesting/ios-pentesting/ios-hooking-with-objection.md· ios hooking with objectionhacktricks/src/mobile-pentesting/ios-pentesting/ios-pentesting-without-jailbreak.md· ios pentesting without jailbreakhacktricks/src/mobile-pentesting/ios-pentesting/ios-protocol-handlers.md· ios protocol handlershacktricks/src/mobile-pentesting/ios-pentesting/ios-serialisation-and-encoding.md· ios serialisation and encodinghacktricks/src/mobile-pentesting/ios-pentesting/ios-testing-environment.md· ios testing environmenthacktricks/src/mobile-pentesting/ios-pentesting/ios-uiactivity-sharing.md· ios uiactivity sharinghacktricks/src/mobile-pentesting/ios-pentesting/ios-uipasteboard.md· ios uipasteboardhacktricks/src/mobile-pentesting/ios-pentesting/ios-universal-links.md· ios universal linkshacktricks/src/mobile-pentesting/ios-pentesting/ios-webviews.md· ios webviewshacktricks/src/mobile-pentesting/ios-pentesting/itunesstored-bookassetd-sandbox-escape.md· itunesstored bookassetd sandbox escapehacktricks/src/mobile-pentesting/ios-pentesting/zero-click-messaging-image-parser-chains.md· zero click messaging image parser chainshacktricks/src/mobile-pentesting/ios-pentesting-checklist.md· ios pentesting checklisthacktricks/src/mobile-pentesting/xamarin-apps.md· xamarin apps
IA
Entradas disponibles: 25.
hacktricks/src/AI/AI-Assisted-Fuzzing-and-Vulnerability-Discovery.md· AI Assisted Fuzzing and Vulnerability Discoveryhacktricks/src/AI/AI-Burp-MCP.md· AI Burp MCPhacktricks/src/AI/AI-Deep-Learning.md· AI Deep Learninghacktricks/src/AI/AI-MCP-Servers.md· AI MCP Servershacktricks/src/AI/AI-Model-Data-Preparation-and-Evaluation.md· AI Model Data Preparation and Evaluationhacktricks/src/AI/AI-Models-RCE.md· AI Models RCEhacktricks/src/AI/AI-Prompts.md· AI Promptshacktricks/src/AI/AI-Reinforcement-Learning-Algorithms.md· AI Reinforcement Learning Algorithmshacktricks/src/AI/AI-Risk-Frameworks.md· AI Risk Frameworkshacktricks/src/AI/AI-Supervised-Learning-Algorithms.md· AI Supervised Learning Algorithmshacktricks/src/AI/AI-Unsupervised-Learning-Algorithms.md· AI Unsupervised Learning Algorithmshacktricks/src/AI/AI-llm-architecture/0.-basic-llm-concepts.md· 0. basic llm conceptshacktricks/src/AI/AI-llm-architecture/1.-tokenizing.md· 1. tokenizinghacktricks/src/AI/AI-llm-architecture/2.-data-sampling.md· 2. data samplinghacktricks/src/AI/AI-llm-architecture/3.-token-embeddings.md· 3. token embeddingshacktricks/src/AI/AI-llm-architecture/4.-attention-mechanisms.md· 4. attention mechanismshacktricks/src/AI/AI-llm-architecture/5.-llm-architecture.md· 5. llm architecturehacktricks/src/AI/AI-llm-architecture/6.-pre-training-and-loading-models.md· 6. pre training and loading modelshacktricks/src/AI/AI-llm-architecture/7.0.-lora-improvements-in-fine-tuning.md· 7.0. lora improvements in fine tuninghacktricks/src/AI/AI-llm-architecture/7.1.-fine-tuning-for-classification.md· 7.1. fine tuning for classificationhacktricks/src/AI/AI-llm-architecture/7.2.-fine-tuning-to-follow-instructions.md· 7.2. fine tuning to follow instructionshacktricks/src/AI/AI-llm-architecture/README.md· AI llm architecturehacktricks/src/AI/KYC-Bypass-Using-AI.md· KYC Bypass Using AIhacktricks/src/AI/README.md· AIhacktricks/src/AI/Web-Black-Box-AI-Pentester-Bots.md· Web Black Box AI Pentester Bots
Cloud y hardening Linux
Entradas disponibles: 90.
hacktricks/src/linux-hardening/README.md· linux hardeninghacktricks/src/linux-hardening/containers-namespaces/README.md· containers namespaceshacktricks/src/linux-hardening/containers-namespaces/container-security/README.md· container securityhacktricks/src/linux-hardening/containers-namespaces/container-security/assessment-and-hardening.md· assessment and hardeninghacktricks/src/linux-hardening/containers-namespaces/container-security/authorization-plugins.md· authorization pluginshacktricks/src/linux-hardening/containers-namespaces/container-security/distroless.md· distrolesshacktricks/src/linux-hardening/containers-namespaces/container-security/image-security-and-secrets.md· image security and secretshacktricks/src/linux-hardening/containers-namespaces/container-security/privileged-containers.md· privileged containershacktricks/src/linux-hardening/containers-namespaces/container-security/protections/README.md· protectionshacktricks/src/linux-hardening/containers-namespaces/container-security/protections/apparmor.md· apparmorhacktricks/src/linux-hardening/containers-namespaces/container-security/protections/capabilities.md· capabilitieshacktricks/src/linux-hardening/containers-namespaces/container-security/protections/cgroups.md· cgroupshacktricks/src/linux-hardening/containers-namespaces/container-security/protections/masked-paths.md· masked pathshacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/README.md· namespaceshacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/cgroup-namespace.md· cgroup namespacehacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/ipc-namespace.md· ipc namespacehacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/mount-namespace.md· mount namespacehacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/network-namespace.md· network namespacehacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/pid-namespace.md· pid namespacehacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/time-namespace.md· time namespacehacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/user-namespace.md· user namespacehacktricks/src/linux-hardening/containers-namespaces/container-security/protections/namespaces/uts-namespace.md· uts namespacehacktricks/src/linux-hardening/containers-namespaces/container-security/protections/no-new-privileges.md· no new privilegeshacktricks/src/linux-hardening/containers-namespaces/container-security/protections/read-only-paths.md· read only pathshacktricks/src/linux-hardening/containers-namespaces/container-security/protections/seccomp.md· seccomphacktricks/src/linux-hardening/containers-namespaces/container-security/protections/selinux.md· selinuxhacktricks/src/linux-hardening/containers-namespaces/container-security/runtime-api-and-daemon-exposure.md· runtime api and daemon exposurehacktricks/src/linux-hardening/containers-namespaces/container-security/runtimes-and-engines.md· runtimes and engineshacktricks/src/linux-hardening/containers-namespaces/container-security/sensitive-host-mounts.md· sensitive host mountshacktricks/src/linux-hardening/containers-namespaces/containerd-ctr-privilege-escalation.md· containerd ctr privilege escalationhacktricks/src/linux-hardening/containers-namespaces/runc-privilege-escalation.md· runc privilege escalationhacktricks/src/linux-hardening/interesting-files-permissions/README.md· interesting files permissionshacktricks/src/linux-hardening/interesting-files-permissions/ld.so.conf-example.md· ld.so.conf examplehacktricks/src/linux-hardening/interesting-files-permissions/linux-capabilities.md· linux capabilitieshacktricks/src/linux-hardening/interesting-files-permissions/nfs-no_root_squash-misconfiguration-pe.md· nfs no_root_squash misconfiguration pehacktricks/src/linux-hardening/interesting-files-permissions/selinux.md· selinuxhacktricks/src/linux-hardening/interesting-files-permissions/suid-sgid-and-acl-triage.md· suid sgid and acl triagehacktricks/src/linux-hardening/interesting-files-permissions/suid-shared-library-and-linker-abuse.md· suid shared library and linker abusehacktricks/src/linux-hardening/interesting-files-permissions/wildcards-spare-tricks.md· wildcards spare trickshacktricks/src/linux-hardening/interesting-files-permissions/write-to-root.md· write to roothacktricks/src/linux-hardening/linux-basics/README.md· linux basicshacktricks/src/linux-hardening/linux-basics/bypass-linux-restrictions/README.md· bypass linux restrictionshacktricks/src/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/README.md· bypass fs protections read only no exec distrolesshacktricks/src/linux-hardening/linux-basics/bypass-linux-restrictions/bypass-fs-protections-read-only-no-exec-distroless/ddexec.md· ddexechacktricks/src/linux-hardening/linux-basics/linux-environment-variables.md· linux environment variableshacktricks/src/linux-hardening/linux-basics/linux-privilege-escalation/README.md· linux privilege escalationhacktricks/src/linux-hardening/linux-basics/shell-startup-aliases-and-history.md· shell startup aliases and historyhacktricks/src/linux-hardening/linux-basics/useful-linux-commands.md· useful linux commandshacktricks/src/linux-hardening/main-system-information/README.md· main system informationhacktricks/src/linux-hardening/main-system-information/escaping-from-limited-bash.md· escaping from limited bashhacktricks/src/linux-hardening/main-system-information/filesystem-inodes-and-recovery.md· filesystem inodes and recoveryhacktricks/src/linux-hardening/main-system-information/filesystem-links-and-file-descriptors.md· filesystem links and file descriptorshacktricks/src/linux-hardening/main-system-information/kernel-lpe-cves/README.md· kernel lpe cveshacktricks/src/linux-hardening/main-system-information/kernel-lpe-cves/copy-fail-af_alg-splice-page-cache-overwrite-cve-2026-31431.md· copy fail af_alg splice page cache overwrite cve 2026 31431hacktricks/src/linux-hardening/main-system-information/kernel-lpe-cves/linux-ptrace-exit-race-pidfd_getfd-fd-theft.md· linux ptrace exit race pidfd_getfd fd thefthacktricks/src/linux-hardening/main-system-information/kernel-lpe-cves/posix-cpu-timers-toctou-cve-2025-38352.md· posix cpu timers toctou cve 2025 38352hacktricks/src/linux-hardening/main-system-information/kernel-lpe-cves/vmware-tools-service-discovery-untrusted-search-path-cve-2025-41244.md· vmware tools service discovery untrusted search path cve 2025 41244hacktricks/src/linux-hardening/main-system-information/kernel-modules-and-modprobe.md· kernel modules and modprobehacktricks/src/linux-hardening/main-system-information/kernel-vulnerability-assessment.md· kernel vulnerability assessmenthacktricks/src/linux-hardening/main-system-information/linux-privilege-escalation-checklist.md· linux privilege escalation checklisthacktricks/src/linux-hardening/main-system-information/sudo-command-abuse.md· sudo command abusehacktricks/src/linux-hardening/network-information/README.md· network informationhacktricks/src/linux-hardening/network-information/cisco-vmanage.md· cisco vmanagehacktricks/src/linux-hardening/network-information/local-network-and-socket-triage.md· local network and socket triagehacktricks/src/linux-hardening/network-information/socket-command-injection.md· socket command injectionhacktricks/src/linux-hardening/network-information/traffic-capture-and-firewall-egress.md· traffic capture and firewall egresshacktricks/src/linux-hardening/post-exploitation/README.md· post exploitationhacktricks/src/linux-hardening/post-exploitation/cloud-instance-metadata.md· cloud instance metadatahacktricks/src/linux-hardening/post-exploitation/trojanized-system-daemons-and-reverse-proxies.md· trojanized system daemons and reverse proxieshacktricks/src/linux-hardening/processes-crontab-systemd-dbus/README.md· processes crontab systemd dbushacktricks/src/linux-hardening/processes-crontab-systemd-dbus/cron-and-systemd-timers.md· cron and systemd timershacktricks/src/linux-hardening/processes-crontab-systemd-dbus/d-bus-enumeration-and-command-injection-privilege-escalation.md· d bus enumeration and command injection privilege escalationhacktricks/src/linux-hardening/processes-crontab-systemd-dbus/payloads-to-execute.md· payloads to executehacktricks/src/linux-hardening/processes-crontab-systemd-dbus/process-enumeration-and-service-paths.md· process enumeration and service pathshacktricks/src/linux-hardening/software-information/README.md· software informationhacktricks/src/linux-hardening/software-information/android-rooting-frameworks-manager-auth-bypass-syscall-hook.md· android rooting frameworks manager auth bypass syscall hookhacktricks/src/linux-hardening/software-information/databases-and-secret-material.md· databases and secret materialhacktricks/src/linux-hardening/software-information/electron-cef-chromium-debugger-abuse.md· electron cef chromium debugger abusehacktricks/src/linux-hardening/software-information/freeipa-pentesting.md· freeipa pentestinghacktricks/src/linux-hardening/software-information/local-web-and-auth-services.md· local web and auth serviceshacktricks/src/linux-hardening/software-information/logstash.md· logstashhacktricks/src/linux-hardening/software-information/pam-pluggable-authentication-modules.md· pam pluggable authentication moduleshacktricks/src/linux-hardening/software-information/splunk-lpe-and-persistence.md· splunk lpe and persistencehacktricks/src/linux-hardening/user-information/README.md· user informationhacktricks/src/linux-hardening/user-information/euid-ruid-suid.md· euid ruid suidhacktricks/src/linux-hardening/user-information/interesting-groups-linux-pe/README.md· interesting groups linux pehacktricks/src/linux-hardening/user-information/interesting-groups-linux-pe/lxd-privilege-escalation.md· lxd privilege escalationhacktricks/src/linux-hardening/user-information/linux-active-directory.md· linux active directoryhacktricks/src/linux-hardening/user-information/ssh-forward-agent-exploitation.md· ssh forward agent exploitationhacktricks/src/linux-hardening/user-information/user-and-session-triage.md· user and session triage
Windows y directorio
Entradas disponibles: 109.
hacktricks/src/windows-hardening/active-directory-methodology/README.md· active directory methodologyhacktricks/src/windows-hardening/active-directory-methodology/TimeRoasting.md· TimeRoastinghacktricks/src/windows-hardening/active-directory-methodology/abusing-ad-mssql.md· abusing ad mssqlhacktricks/src/windows-hardening/active-directory-methodology/acl-persistence-abuse/BadSuccessor.md· BadSuccessorhacktricks/src/windows-hardening/active-directory-methodology/acl-persistence-abuse/README.md· acl persistence abusehacktricks/src/windows-hardening/active-directory-methodology/acl-persistence-abuse/shadow-credentials.md· shadow credentialshacktricks/src/windows-hardening/active-directory-methodology/ad-certificates/README.md· ad certificateshacktricks/src/windows-hardening/active-directory-methodology/ad-certificates/account-persistence.md· account persistencehacktricks/src/windows-hardening/active-directory-methodology/ad-certificates/certificate-theft.md· certificate thefthacktricks/src/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation.md· domain escalationhacktricks/src/windows-hardening/active-directory-methodology/ad-certificates/domain-persistence.md· domain persistencehacktricks/src/windows-hardening/active-directory-methodology/ad-certificates.md· ad certificateshacktricks/src/windows-hardening/active-directory-methodology/ad-dns-records.md· ad dns recordshacktricks/src/windows-hardening/active-directory-methodology/ad-dynamic-objects-anti-forensics.md· ad dynamic objects anti forensicshacktricks/src/windows-hardening/active-directory-methodology/ad-information-in-printers.md· ad information in printershacktricks/src/windows-hardening/active-directory-methodology/adws-enumeration.md· adws enumerationhacktricks/src/windows-hardening/active-directory-methodology/asreproast.md· asreproasthacktricks/src/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse.md· badsuccessor dmsa migration abusehacktricks/src/windows-hardening/active-directory-methodology/bloodhound.md· bloodhoundhacktricks/src/windows-hardening/active-directory-methodology/constrained-delegation.md· constrained delegationhacktricks/src/windows-hardening/active-directory-methodology/custom-ssp.md· custom ssphacktricks/src/windows-hardening/active-directory-methodology/dcshadow.md· dcshadowhacktricks/src/windows-hardening/active-directory-methodology/dcsync.md· dcsynchacktricks/src/windows-hardening/active-directory-methodology/diamond-ticket.md· diamond tickethacktricks/src/windows-hardening/active-directory-methodology/dsrm-credentials.md· dsrm credentialshacktricks/src/windows-hardening/active-directory-methodology/external-forest-domain-one-way-outbound.md· external forest domain one way outboundhacktricks/src/windows-hardening/active-directory-methodology/external-forest-domain-oneway-inbound.md· external forest domain oneway inboundhacktricks/src/windows-hardening/active-directory-methodology/golden-dmsa-gmsa.md· golden dmsa gmsahacktricks/src/windows-hardening/active-directory-methodology/golden-ticket.md· golden tickethacktricks/src/windows-hardening/active-directory-methodology/kerberoast.md· kerberoasthacktricks/src/windows-hardening/active-directory-methodology/kerberos-authentication.md· kerberos authenticationhacktricks/src/windows-hardening/active-directory-methodology/kerberos-double-hop-problem.md· kerberos double hop problemhacktricks/src/windows-hardening/active-directory-methodology/lansweeper-security.md· lansweeper securityhacktricks/src/windows-hardening/active-directory-methodology/laps.md· lapshacktricks/src/windows-hardening/active-directory-methodology/ldap-signing-and-channel-binding.md· ldap signing and channel bindinghacktricks/src/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key.md· over pass the hash pass the keyhacktricks/src/windows-hardening/active-directory-methodology/pass-the-ticket.md· pass the tickethacktricks/src/windows-hardening/active-directory-methodology/password-spraying.md· password sprayinghacktricks/src/windows-hardening/active-directory-methodology/printers-spooler-service-abuse.md· printers spooler service abusehacktricks/src/windows-hardening/active-directory-methodology/printnightmare.md· printnightmarehacktricks/src/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges.md· privileged groups and token privilegeshacktricks/src/windows-hardening/active-directory-methodology/rdp-sessions-abuse.md· rdp sessions abusehacktricks/src/windows-hardening/active-directory-methodology/resource-based-constrained-delegation.md· resource based constrained delegationhacktricks/src/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets.md· sccm management point relay sql policy secretshacktricks/src/windows-hardening/active-directory-methodology/security-descriptors.md· security descriptorshacktricks/src/windows-hardening/active-directory-methodology/sid-history-injection.md· sid history injectionhacktricks/src/windows-hardening/active-directory-methodology/silver-ticket.md· silver tickethacktricks/src/windows-hardening/active-directory-methodology/skeleton-key.md· skeleton keyhacktricks/src/windows-hardening/active-directory-methodology/unconstrained-delegation.md· unconstrained delegationhacktricks/src/windows-hardening/authentication-credentials-uac-and-efs/README.md· authentication credentials uac and efshacktricks/src/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control.md· uac user account controlhacktricks/src/windows-hardening/authentication-credentials-uac-and-efs.md· authentication credentials uac and efshacktricks/src/windows-hardening/av-bypass.md· av bypasshacktricks/src/windows-hardening/basic-cmd-for-pentesters.md· basic cmd for pentestershacktricks/src/windows-hardening/basic-powershell-for-pentesters/README.md· basic powershell for pentestershacktricks/src/windows-hardening/basic-powershell-for-pentesters/powerview.md· powerviewhacktricks/src/windows-hardening/checklist-windows-privilege-escalation.md· checklist windows privilege escalationhacktricks/src/windows-hardening/cobalt-strike.md· cobalt strikehacktricks/src/windows-hardening/lateral-movement/README.md· lateral movementhacktricks/src/windows-hardening/lateral-movement/atexec.md· atexechacktricks/src/windows-hardening/lateral-movement/dcomexec.md· dcomexechacktricks/src/windows-hardening/lateral-movement/psexec-and-winexec.md· psexec and winexechacktricks/src/windows-hardening/lateral-movement/rdpexec.md· rdpexechacktricks/src/windows-hardening/lateral-movement/scmexec.md· scmexechacktricks/src/windows-hardening/lateral-movement/winrm.md· winrmhacktricks/src/windows-hardening/lateral-movement/wmiexec.md· wmiexechacktricks/src/windows-hardening/mythic.md· mythichacktricks/src/windows-hardening/ntlm/README.md· ntlmhacktricks/src/windows-hardening/ntlm/places-to-steal-ntlm-creds.md· places to steal ntlm credshacktricks/src/windows-hardening/protocol-handler-shell-execute-abuse.md· protocol handler shell execute abusehacktricks/src/windows-hardening/stealing-credentials/README.md· stealing credentialshacktricks/src/windows-hardening/stealing-credentials/credentials-mimikatz.md· credentials mimikatzhacktricks/src/windows-hardening/stealing-credentials/credentials-protections.md· credentials protectionshacktricks/src/windows-hardening/stealing-credentials/wts-impersonator.md· wts impersonatorhacktricks/src/windows-hardening/windows-local-privilege-escalation/README.md· windows local privilege escalationhacktricks/src/windows-hardening/windows-local-privilege-escalation/abusing-auto-updaters-and-ipc.md· abusing auto updaters and ipchacktricks/src/windows-hardening/windows-local-privilege-escalation/access-tokens.md· access tokenshacktricks/src/windows-hardening/windows-local-privilege-escalation/acls-dacls-sacls-aces.md· acls dacls sacls aceshacktricks/src/windows-hardening/windows-local-privilege-escalation/appenddata-addsubdirectory-permission-over-service-registry.md· appenddata addsubdirectory permission over service registryhacktricks/src/windows-hardening/windows-local-privilege-escalation/arbitrary-kernel-rw-token-theft.md· arbitrary kernel rw token thefthacktricks/src/windows-hardening/windows-local-privilege-escalation/com-hijacking.md· com hijackinghacktricks/src/windows-hardening/windows-local-privilege-escalation/create-msi-with-wix.md· create msi with wixhacktricks/src/windows-hardening/windows-local-privilege-escalation/dll-hijacking/README.md· dll hijackinghacktricks/src/windows-hardening/windows-local-privilege-escalation/dll-hijacking/advanced-html-staged-dll-sideloading.md· advanced html staged dll sideloadinghacktricks/src/windows-hardening/windows-local-privilege-escalation/dll-hijacking/windows-cpython-build-landmark-sys-path-hijacking.md· windows cpython build landmark sys path hijackinghacktricks/src/windows-hardening/windows-local-privilege-escalation/dll-hijacking/writable-sys-path-dll-hijacking-privesc.md· writable sys path dll hijacking priveschacktricks/src/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords.md· dpapi extracting passwordshacktricks/src/windows-hardening/windows-local-privilege-escalation/from-high-integrity-to-system-with-name-pipes.md· from high integrity to system with name pipeshacktricks/src/windows-hardening/windows-local-privilege-escalation/integrity-levels.md· integrity levelshacktricks/src/windows-hardening/windows-local-privilege-escalation/juicypotato.md· juicypotatohacktricks/src/windows-hardening/windows-local-privilege-escalation/kernel-race-condition-object-manager-slowdown.md· kernel race condition object manager slowdownhacktricks/src/windows-hardening/windows-local-privilege-escalation/leaked-handle-exploitation.md· leaked handle exploitationhacktricks/src/windows-hardening/windows-local-privilege-escalation/local-ntlm-reflection-via-smb-arbitrary-port.md· local ntlm reflection via smb arbitrary porthacktricks/src/windows-hardening/windows-local-privilege-escalation/msi-wrapper.md· msi wrapperhacktricks/src/windows-hardening/windows-local-privilege-escalation/named-pipe-client-impersonation.md· named pipe client impersonationhacktricks/src/windows-hardening/windows-local-privilege-escalation/notepad-plus-plus-plugin-autoload-persistence.md· notepad plus plus plugin autoload persistencehacktricks/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.md· privilege escalation abusing tokenshacktricks/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md· privilege escalation with autorun binarieshacktricks/src/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer.md· roguepotato and printspooferhacktricks/src/windows-hardening/windows-local-privilege-escalation/secure-desktop-accessibility-registry-propagation-regpwn.md· secure desktop accessibility registry propagation regpwnhacktricks/src/windows-hardening/windows-local-privilege-escalation/sedebug-+-seimpersonate-copy-token.md· sedebug + seimpersonate copy tokenhacktricks/src/windows-hardening/windows-local-privilege-escalation/seimpersonate-from-high-to-system.md· seimpersonate from high to systemhacktricks/src/windows-hardening/windows-local-privilege-escalation/semanagevolume-perform-volume-maintenance-tasks.md· semanagevolume perform volume maintenance taskshacktricks/src/windows-hardening/windows-local-privilege-escalation/service-triggers.md· service triggershacktricks/src/windows-hardening/windows-local-privilege-escalation/telephony-tapsrv-arbitrary-dword-write-to-rce.md· telephony tapsrv arbitrary dword write to rcehacktricks/src/windows-hardening/windows-local-privilege-escalation/uiaccess-admin-protection-bypass.md· uiaccess admin protection bypasshacktricks/src/windows-hardening/windows-local-privilege-escalation/windows-c-payloads.md· windows c payloadshacktricks/src/windows-hardening/windows-local-privilege-escalation/windows-kernel-rootkits-and-dkom.md· windows kernel rootkits and dkomhacktricks/src/windows-hardening/windows-local-privilege-escalation/windows-registry-hive-exploitation.md· windows registry hive exploitation
Binarios
Entradas disponibles: 105.
hacktricks/src/binary-exploitation/arbitrary-write-2-exec/README.md· arbitrary write 2 exechacktricks/src/binary-exploitation/arbitrary-write-2-exec/aw2exec-__malloc_hook.md· aw2exec __malloc_hookhacktricks/src/binary-exploitation/arbitrary-write-2-exec/aw2exec-__printf_arginfo_table.md· aw2exec __printf_arginfo_tablehacktricks/src/binary-exploitation/arbitrary-write-2-exec/aw2exec-got-plt.md· aw2exec got plthacktricks/src/binary-exploitation/arbitrary-write-2-exec/aw2exec-sips-icc-profile.md· aw2exec sips icc profilehacktricks/src/binary-exploitation/arbitrary-write-2-exec/www2exec-.dtors-and-.fini_array.md· www2exec .dtors and .fini_arrayhacktricks/src/binary-exploitation/arbitrary-write-2-exec/www2exec-atexit.md· www2exec atexithacktricks/src/binary-exploitation/array-indexing.md· array indexinghacktricks/src/binary-exploitation/basic-stack-binary-exploitation-methodology/README.md· basic stack binary exploitation methodologyhacktricks/src/binary-exploitation/basic-stack-binary-exploitation-methodology/elf-tricks.md· elf trickshacktricks/src/binary-exploitation/basic-stack-binary-exploitation-methodology/tools/README.md· toolshacktricks/src/binary-exploitation/basic-stack-binary-exploitation-methodology/tools/pwntools.md· pwntoolshacktricks/src/binary-exploitation/chrome-exploiting.md· chrome exploitinghacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/README.md· common binary protections and bypasseshacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/aslr/README.md· aslrhacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/aslr/ret2plt.md· ret2plthacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/aslr/ret2ret.md· ret2rethacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/cet-and-shadow-stack.md· cet and shadow stackhacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/libc-protections.md· libc protectionshacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/memory-tagging-extension-mte.md· memory tagging extension mtehacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/no-exec-nx.md· no exec nxhacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/pie/README.md· piehacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/pie/bypassing-canary-and-pie.md· bypassing canary and piehacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/relro.md· relrohacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/stack-canaries/README.md· stack canarieshacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/stack-canaries/bf-forked-stack-canaries.md· bf forked stack canarieshacktricks/src/binary-exploitation/common-binary-protections-and-bypasses/stack-canaries/print-stack-canary.md· print stack canaryhacktricks/src/binary-exploitation/common-exploiting-problems-unsafe-relocation-fixups.md· common exploiting problems unsafe relocation fixupshacktricks/src/binary-exploitation/common-exploiting-problems.md· common exploiting problemshacktricks/src/binary-exploitation/format-strings/README.md· format stringshacktricks/src/binary-exploitation/format-strings/format-strings-arbitrary-read-example.md· format strings arbitrary read examplehacktricks/src/binary-exploitation/format-strings/format-strings-template.md· format strings templatehacktricks/src/binary-exploitation/freebsd-ptrace-rfi-vm_map-prot_exec-bypass-ps5.md· freebsd ptrace rfi vm_map prot_exec bypass ps5hacktricks/src/binary-exploitation/integer-overflow-and-underflow.md· integer overflow and underflowhacktricks/src/binary-exploitation/ios-exploiting/CVE-2020-27950-mach_msg_trailer_t.md· CVE 2020 27950 mach_msg_trailer_thacktricks/src/binary-exploitation/ios-exploiting/CVE-2021-30807-IOMobileFrameBuffer.md· CVE 2021 30807 IOMobileFrameBufferhacktricks/src/binary-exploitation/ios-exploiting/README.md· ios exploitinghacktricks/src/binary-exploitation/ios-exploiting/imessage-media-parser-zero-click-coreaudio-pac-bypass.md· imessage media parser zero click coreaudio pac bypasshacktricks/src/binary-exploitation/ios-exploiting/ios-corellium.md· ios corelliumhacktricks/src/binary-exploitation/ios-exploiting/ios-example-heap-exploit.md· ios example heap exploithacktricks/src/binary-exploitation/ios-exploiting/ios-physical-uaf-iosurface.md· ios physical uaf iosurfacehacktricks/src/binary-exploitation/ios-exploiting/webkit-dfg-store-barrier-uaf-angle-oob.md· webkit dfg store barrier uaf angle oobhacktricks/src/binary-exploitation/ios-exploiting/xnu-vm-map-cow-vnode-toctou.md· xnu vm map cow vnode toctouhacktricks/src/binary-exploitation/libc-heap/README.md· libc heaphacktricks/src/binary-exploitation/libc-heap/bins-and-memory-allocations.md· bins and memory allocationshacktricks/src/binary-exploitation/libc-heap/double-free.md· double freehacktricks/src/binary-exploitation/libc-heap/fast-bin-attack.md· fast bin attackhacktricks/src/binary-exploitation/libc-heap/gnu-obstack-function-pointer-hijack.md· gnu obstack function pointer hijackhacktricks/src/binary-exploitation/libc-heap/heap-memory-functions/README.md· heap memory functionshacktricks/src/binary-exploitation/libc-heap/heap-memory-functions/free.md· freehacktricks/src/binary-exploitation/libc-heap/heap-memory-functions/heap-functions-security-checks.md· heap functions security checkshacktricks/src/binary-exploitation/libc-heap/heap-memory-functions/malloc-and-sysmalloc.md· malloc and sysmallochacktricks/src/binary-exploitation/libc-heap/heap-memory-functions/unlink.md· unlinkhacktricks/src/binary-exploitation/libc-heap/heap-overflow.md· heap overflowhacktricks/src/binary-exploitation/libc-heap/house-of-einherjar.md· house of einherjarhacktricks/src/binary-exploitation/libc-heap/house-of-force.md· house of forcehacktricks/src/binary-exploitation/libc-heap/house-of-lore.md· house of lorehacktricks/src/binary-exploitation/libc-heap/house-of-orange.md· house of orangehacktricks/src/binary-exploitation/libc-heap/house-of-rabbit.md· house of rabbithacktricks/src/binary-exploitation/libc-heap/house-of-roman.md· house of romanhacktricks/src/binary-exploitation/libc-heap/house-of-spirit.md· house of spirithacktricks/src/binary-exploitation/libc-heap/large-bin-attack.md· large bin attackhacktricks/src/binary-exploitation/libc-heap/off-by-one-overflow.md· off by one overflowhacktricks/src/binary-exploitation/libc-heap/overwriting-a-freed-chunk.md· overwriting a freed chunkhacktricks/src/binary-exploitation/libc-heap/tcache-bin-attack.md· tcache bin attackhacktricks/src/binary-exploitation/libc-heap/unlink-attack.md· unlink attackhacktricks/src/binary-exploitation/libc-heap/unsorted-bin-attack.md· unsorted bin attackhacktricks/src/binary-exploitation/libc-heap/use-after-free/README.md· use after freehacktricks/src/binary-exploitation/libc-heap/use-after-free/first-fit.md· first fithacktricks/src/binary-exploitation/libc-heap/virtualbox-slirp-nat-packet-heap-exploitation.md· virtualbox slirp nat packet heap exploitationhacktricks/src/binary-exploitation/linux-kernel-exploitation/adreno-a7xx-sds-rb-priv-bypass-gpu-smmu-kernel-rw.md· adreno a7xx sds rb priv bypass gpu smmu kernel rwhacktricks/src/binary-exploitation/linux-kernel-exploitation/af-unix-msg-oob-uaf-skb-primitives.md· af unix msg oob uaf skb primitiveshacktricks/src/binary-exploitation/linux-kernel-exploitation/arm64-static-linear-map-kaslr-bypass.md· arm64 static linear map kaslr bypasshacktricks/src/binary-exploitation/linux-kernel-exploitation/futex-pi-uaf-pipe-buffer-workqueue-usermodehelper.md· futex pi uaf pipe buffer workqueue usermodehelperhacktricks/src/binary-exploitation/linux-kernel-exploitation/ksmbd-streams_xattr-oob-write-cve-2025-37947.md· ksmbd streams_xattr oob write cve 2025 37947hacktricks/src/binary-exploitation/linux-kernel-exploitation/pixel-bigwave-bigo-job-timeout-uaf-kernel-write.md· pixel bigwave bigo job timeout uaf kernel writehacktricks/src/binary-exploitation/linux-kernel-exploitation/posix-cpu-timers-toctou-cve-2025-38352.md· posix cpu timers toctou cve 2025 38352hacktricks/src/binary-exploitation/qemu-kvm-vm-escape-chains.md· qemu kvm vm escape chainshacktricks/src/binary-exploitation/rop-return-oriented-programing/README.md· rop return oriented programinghacktricks/src/binary-exploitation/rop-return-oriented-programing/brop-blind-return-oriented-programming.md· brop blind return oriented programminghacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2csu.md· ret2csuhacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2dlresolve.md· ret2dlresolvehacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2esp-ret2reg.md· ret2esp ret2reghacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2lib/README.md· ret2libhacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2lib/one-gadget.md· one gadgethacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2lib/ret2lib-printf-leak-arm64.md· ret2lib printf leak arm64hacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2lib/rop-leaking-libc-address/README.md· rop leaking libc addresshacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2lib/rop-leaking-libc-address/rop-leaking-libc-template.md· rop leaking libc templatehacktricks/src/binary-exploitation/rop-return-oriented-programing/ret2vdso.md· ret2vdsohacktricks/src/binary-exploitation/rop-return-oriented-programing/rop-syscall-execv/README.md· rop syscall execvhacktricks/src/binary-exploitation/rop-return-oriented-programing/rop-syscall-execv/ret2syscall-arm64.md· ret2syscall arm64hacktricks/src/binary-exploitation/rop-return-oriented-programing/srop-sigreturn-oriented-programming/README.md· srop sigreturn oriented programminghacktricks/src/binary-exploitation/rop-return-oriented-programing/srop-sigreturn-oriented-programming/srop-arm64.md· srop arm64hacktricks/src/binary-exploitation/stack-overflow/README.md· stack overflowhacktricks/src/binary-exploitation/stack-overflow/pointer-redirecting.md· pointer redirectinghacktricks/src/binary-exploitation/stack-overflow/ret2win/README.md· ret2winhacktricks/src/binary-exploitation/stack-overflow/ret2win/ret2win-arm64.md· ret2win arm64hacktricks/src/binary-exploitation/stack-overflow/stack-pivoting.md· stack pivotinghacktricks/src/binary-exploitation/stack-overflow/stack-shellcode/README.md· stack shellcodehacktricks/src/binary-exploitation/stack-overflow/stack-shellcode/stack-shellcode-arm64.md· stack shellcode arm64hacktricks/src/binary-exploitation/stack-overflow/uninitialized-variables.md· uninitialized variableshacktricks/src/binary-exploitation/stack-overflow/windows-seh-overflow.md· windows seh overflowhacktricks/src/binary-exploitation/vmware-workstation-pvscsi-lfh-escape.md· vmware workstation pvscsi lfh escapehacktricks/src/binary-exploitation/windows-exploiting-basic-guide-oscp-lvl.md· windows exploiting basic guide oscp lvlhacktricks/src/binary-exploitation/windows-vectored-overloading.md· windows vectored overloading
Hardware y firmware
Entradas disponibles: 9.
hacktricks/src/hardware-physical-access/escaping-from-gui-applications.md· escaping from gui applicationshacktricks/src/hardware-physical-access/firmware-analysis/README.md· firmware analysishacktricks/src/hardware-physical-access/firmware-analysis/android-mediatek-secure-boot-bl2_ext-bypass-el3.md· android mediatek secure boot bl2_ext bypass el3hacktricks/src/hardware-physical-access/firmware-analysis/bootloader-testing.md· bootloader testinghacktricks/src/hardware-physical-access/firmware-analysis/firmware-integrity.md· firmware integrityhacktricks/src/hardware-physical-access/firmware-analysis/mediatek-xflash-carbonara-da2-hash-bypass.md· mediatek xflash carbonara da2 hash bypasshacktricks/src/hardware-physical-access/firmware-analysis/synology-encrypted-archive-decryption.md· synology encrypted archive decryptionhacktricks/src/hardware-physical-access/firmware-analysis/uefi-ifr-nvram-security-setting-patching.md· uefi ifr nvram security setting patchinghacktricks/src/hardware-physical-access/physical-attacks.md· physical attacks