This page does NOT pretend to replace AWAE/OSWE arrow-up-rightcontent, this is a compilation of the best (public|my own) resources I have come up with.
AWAE LIST:
Persistent Cross-Site Scripting
Session Hijacking
.NET Deserialization
Data Exfiltration
Bypassing File Extension Filters
Magic Hashes
Bypassing REGEX restrictions
Cross-Site Request Forgery
Type Juggling
Blind SQL Injection
Bypassing File Upload Restrictions
Loose Comparisons
Bypassing Character Restrictions
PERSONAL LIST:
Blind Time-Based & Boolean SQL Injection + Bypassing Character Restrictions
MySQL
PostgreSQL
Deserialization
PHP
Java
.NET
XSS
Reflected
Stored
Filter Bypass
Loose Comparison
REGEX
File Upload Restrictions Bypass
File Extension Filters Bypass
Great people I have learnt a ton from: @secgusarrow-up-right, @julianjmarrow-up-right, @cynopsarrow-up-right, @devploitarrow-up-right, @oreosarrow-up-right, @rmartinsantaarrow-up-right.
Mentioned people: @Takitoarrow-up-right, ITasahobbyarrow-up-right.
(CTF) Platforms I have enjoyed (and I'm enjoying) the most.
Last updated 5 years ago