🩸
Pentesting Notes
Ctrlk
  • ㊙️r3dcl1ff
    • 🔬Enumeration
    • 🧨Exploitation (deprecated node)
    • 🈲Privesc
    • 🖥️CLI-Fu
    • 🎯OSINT
    • 🛠️Tools
    • 🟦Active Directory
    • 🪓Sysadmin
    • 🗒️Pentesting Checklist(s)
    • 🕷️WebApp Pentest
      • Vuln scanners
      • Attack Surface Recon
      • Port scanning
      • Subdomain Bruteforcing + crawling
      • File inclusion
        • Liffy
        • LFISuite
        • CRLFI
        • LFI - Theory & basic commands
        • RFI - Theory & basic commands
        • one liners
        • HTTPX
        • Dorks
      • ⏪Traversal
      • Content Discovery
      • Fuzzing
      • Parameters
      • Open redirect
      • HTTP Request Smuggling
      • Server Side Request Forgery
      • 💉SQLi
      • XSS Cross Site Scripting
      • Links
      • Git
      • Text manipulation
      • CORS
      • CSRF Cross Site Request Forgery
      • Assorted
      • Screenshots
      • Command Injection
      • SSTI
      • IDOR
      • Bypass 40X
      • Subdomain Takeover
      • Headers Security
      • 🐝API pentesting
      • RCE
    • 🌩️Cloud
    • 🧠Threat Intel
    • 📟IoT / IIoT
    • 🏭ICS/OT - SCADA
    • 🩻Private Templates
    • 🐞BBP
    • 📱Mobile
  • Daily Syncs
    • Design Standups
  • Weekly Syncs
    • Company Weeklies
  • Other Regulars
    • Company Weeklies
Powered by GitBook
On this page
  1. ㊙️r3dcl1ff
  2. 🕷️WebApp Pentest

File inclusion

Tools and manual exploitation resources

LiffyLFISuiteCRLFILFI - Theory & basic commandsRFI - Theory & basic commandsone linersHTTPXDorks
PreviousjsubfinderNextLiffy

Last updated 2 years ago