 Dominique RIGHETTOandGitHub
|
ec5eaa9781
|
Add PSD2 SPU headers
Source: https://www.stet.eu/assets/files/PSD2/1-5-1-6/api-dsp2-stet-v1.5.1.6-part-3-interaction-examples.pdf
Section 6.1.1.2
|
2021-07-29 14:46:21 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
93674add0c
|
Add PSD2 PSU headers
Source: https://www.stet.eu/assets/files/PSD2/1-5-1-6/api-dsp2-stet-v1.5.1.6-part-1-framework.pdf
Section 3.6
|
2021-07-29 14:44:20 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
3eeb4e5292
|
Add Shibboleth.sso Metadata endpoint
Source: https://wiki.shibboleth.net/confluence/display/CONCEPT/MetadataForSP
|
2021-06-07 15:43:03 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
864faed87f
|
Add "oauth/token/info" endpoint
See https://docs.gitlab.com/ee/api/oauth2.html#retrieving-the-token-information
|
2021-05-28 15:44:59 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
56e23b6436
|
Add openid endpoints and metadata
See https://connect2id.com/products/server/docs/api
|
2021-05-28 15:20:54 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
0e471e3faf
|
Add oauth endpoints
See https://auth0.com/docs/protocols/protocol-oauth2#endpoints
|
2021-05-28 15:11:32 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
4a2ab64c10
|
Add security.txt at the root
|
2021-04-15 07:58:49 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
6715ca5d96
|
Add "contribute.json" file entry
|
2021-03-01 12:36:34 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
6400f4d31e
|
Change the url to google
|
2021-02-26 14:12:33 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
2afcf1217c
|
Add specific render endpoints
|
2021-02-21 18:55:29 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
5ce22e65b0
|
Added Assetnote Wordlists
See this discussion for explanation:
https://github.com/danielmiessler/SecLists/pull/546#issuecomment-777793718
|
2021-02-12 01:01:43 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
405cf59743
|
Add Microsoft Blazor client identifier
|
2021-01-24 08:58:00 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
38581fac54
|
Add ".well-known/jwks.json" path
Add path to the JSON Web Key Sets file.
This file is documented [here](https://auth0.com/docs/tokens/json-web-tokens/json-web-key-sets)
|
2020-12-27 16:35:37 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
fee58c17da
|
Add path to a common ManageEngine endpoint
Add path to a endpoint often exposed to anonymous user by ManageEngine products.
See https://www.manageengine.com/
|
2020-10-02 08:32:34 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
1361ac96c1
|
Fix typos
|
2020-09-14 14:30:00 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
1c2fb11278
|
Add file with special vars used by template engines
The objective is to identify the engine once an expression evaluation pattern was identified.
|
2020-09-14 14:28:12 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
234dfabf72
|
Add an expression using expression inlining for Thymeleaf
See https://www.thymeleaf.org/doc/tutorials/3.0/usingthymeleaf.html#expression-inlining
Added it because I have discovered that, when StringTemplateResolver is used, then expression like ${42*42} is not resolved
|
2020-09-13 11:04:15 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
ba87953a08
|
Add expression for Velocity engine
|
2020-09-13 09:33:41 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
00f10f8513
|
Add character that can break a MongoDB query when JS expression is used
|
2020-07-18 18:00:24 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
9763b2a76d
|
Add www folder
|
2020-05-23 11:37:49 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
6350b61e1d
|
Add missing ending /
|
2020-05-23 11:36:17 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
e790c509b8
|
Ass html folder
|
2020-05-23 11:34:37 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
984af30974
|
Add the expression for the Dust engine
|
2020-05-03 10:52:17 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
aecd8036ca
|
Add the expression for the doT engine
|
2020-05-03 10:30:48 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
611d47caf3
|
Add a version of the payload for CodeContext
Add the payload "42*42" to the fuzzing list in order to cover the "Code context" detection point mentioned in the https://portswigger.net/web-security/server-side-template-injection training
|
2020-04-25 09:13:06 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
1bd30300de
|
Add a initial collection of template engines expression
|
2020-04-18 17:16:20 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
cb37e5b03d
|
Create reverse-proxy-inconsistencies.txt
|
2020-01-22 09:03:34 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
44b3fdedf2
|
Add entries from a blog about content discovery in API
Blog url: https://blog.jonlu.ca/posts/experiments-and-growth-hacking
|
2020-01-03 16:22:45 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
f7314e9c34
|
Add entry from Portswigger WebAcademy
Entry found in labs from https://portswigger.net/web-security/access-control
|
2019-12-29 11:50:12 +01:00 |
|
 Dominique RIGHETTOandGitHub
|
9f94cae21b
|
Add local ports for scan
|
2019-10-21 17:49:56 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
5c917b1cba
|
Add dictionary for GraphQL
Help to detect GraphQL endpoint
|
2019-10-11 17:19:05 +02:00 |
|
 Dominique RIGHETTOandGitHub
|
b93f54f4fb
|
Add VIM and NANO backup file
|
2019-10-11 15:55:38 +02:00 |
|