958 Commits

Author SHA1 Message Date
Jamie Scott
5b5cafaa47
Adding the not in operator
Adding the not in operator as another thing to check or test. It will equivalently act as { $ne: 1 } only it functions within an array.
2020-05-28 00:34:48 -07:00
Karim Kanso
607c3293b4 strip trailing whitespace 2020-05-27 14:26:51 +01:00
Karim Kanso
f20c12a4a6 added git attributes to keep line ends standardised 2020-05-27 14:16:24 +01:00
Karim Kanso
a3416ba706 standardisze line endings 2020-05-27 14:10:50 +01:00
g0tmi1k
9a14bdb7ca
Merge pull request #441 from cactuschibre/master
Reorder and add more Actuator endpoints

Source; https://apereo.github.io/cas/development/monitoring/Monitoring-Statistics.html
2020-05-27 10:42:10 +01:00
g0tmi1k
67bdc2032e
Merge pull request #434 from Kegn/patch-1
add nested traversal strings for /etc/passwd
2020-05-27 09:55:47 +01:00
g0tmi1k
67947cfae1
Merge pull request #435 from righettod/master
Add WWW and HTML folders
2020-05-27 09:54:21 +01:00
g0tmi1k
fdfd855ec5
Merge pull request #437 from guest20/patch-1
Rename Public-Source-Repo-Issues.txt to Public-Source-Repo-Issues.json
2020-05-27 09:44:27 +01:00
cactuschibre
017b233805
Reorder and add more Actuator endpoints 2020-05-26 16:28:58 +02:00
guest20
6ccd6853d4
Rename Public-Source-Repo-Issues.txt to Public-Source-Repo-Issues.json
This file is full of json, which might upset someone writing a script that assumes *.txt files are just url fragments....
2020-05-24 13:07:50 +02:00
Dominique RIGHETTO
9763b2a76d
Add www folder 2020-05-23 11:37:49 +02:00
Dominique RIGHETTO
6350b61e1d
Add missing ending / 2020-05-23 11:36:17 +02:00
Dominique RIGHETTO
e790c509b8
Ass html folder 2020-05-23 11:34:37 +02:00
kegan
54ac7074da
add nested traversal strings for /etc/passwd 2020-05-18 18:12:12 -05:00
MomIsBestFriend
e89ff1fbda Fixed typo in Discovery/Variables/secret-keywords.txt 2020-05-17 00:37:40 +03:00
g0tmi1k
a8df2a72c2
Merge pull request #431 from pbafe/master
Create Django.txt
2020-05-13 14:27:21 +01:00
pbafe
888cdaa13a
Create Django.txt
Updated on April 20th, the contents include all the files of Django between version 3.0.5 and 2.1
2020-05-09 10:53:35 +02:00
g0tmi1k
86c6e6314f
Merge pull request #430 from cnotin/patch-1
Add .well-known entries

Source: 
- https://gist.github.com/quickbreach/3bddfdf193b3d988b0e07d07dbac0da0
- https://www.iana.org/assignments/well-known-uris/well-known-uris.xhtml
- https://mercure.rocks/spec#discovery
2020-05-08 12:07:45 +01:00
g0tmi1k
47e882f5d9
Merge pull request #405 from soufianetahiri/patch-1
add swagger path
2020-05-08 12:06:57 +01:00
Clément Notin
123be76ca1
Add .well-known entries 2020-05-08 01:14:12 +02:00
g0tmi1k
442e31098e
Merge pull request #428 from g0tmi1k/misc
Add top domains + 2020.2 release
2020.2
2020-05-04 10:23:05 +01:00
g0t mi1k
7bc157fd55 2020.2 release 2020-05-04 10:22:21 +01:00
g0t mi1k
ff36e7e79f Add alexa domains
Source: https://support.alexa.com/hc/en-us/articles/200461990-Can-I-get-a-list-of-top-sites-from-an-API-
https://asciinema.org/a/9dwog4uqepaghpvyeginwckpn
2020-05-04 10:18:55 +01:00
g0t mi1k
fe8a8830c4 Add majestic domains
Source: https://blog.majestic.com/development/majestic-million-csv-daily/

$ wget http://downloads.majestic.com/majestic_million.csv
$ zip top-domains-majestic.csv.zip majestic_million.csv
2020-05-04 10:16:48 +01:00
g0t mi1k
cd715ee89c Update credit URLs 2020-05-04 10:10:52 +01:00
g0tmi1k
15b1fa3a65
Merge pull request #426 from righettod/master
Add the expression for the "doT.js" and the "dust.js" template engines

Source:

- https://github.com/epinna/tplmap/tree/master/plugins/engines
- https://olado.github.io/doT/index.html
- http://www.dustjs.com/
2020-05-04 10:07:21 +01:00
0verflowme
ffc8d2bf32
Update common.txt 2020-05-03 19:53:03 +05:30
Dominique RIGHETTO
984af30974
Add the expression for the Dust engine 2020-05-03 10:52:17 +02:00
Dominique RIGHETTO
aecd8036ca
Add the expression for the doT engine 2020-05-03 10:30:48 +02:00
g0tmi1k
09d5a27cf7
Merge pull request #421 from storenth/master
Update the fuzz-Bo0oM.txt with more ';'

Source: https://twitter.com/11xuxx/status/1247496768054591489
2020-04-29 17:52:49 +01:00
g0tmi1k
b0186b7875
Merge pull request #424 from Kadeeli/master
Close #423 (added dutch passwordlist)

Source: 
- https://www.dropbox.com/s/rbgmmtsqupawtfc/Dutch_passwordlist.txt?dl=0
- https://www.dropbox.com/s/z3d0di7to1yv3cc/Dutch_wordlist.txt?dl=0
2020-04-29 17:51:33 +01:00
Jony Schats
e0d074bb83 added dutch passwordlist 2020-04-29 12:21:51 -04:00
g0tmi1k
9e694f6ad8
Merge pull request #422 from Emoe/master
Added default Directory-Wordlist from Dirbuster

Source: https://sourceforge.net/projects/dirbuster/files/DirBuster%20Lists/Current/
2020-04-28 16:20:45 +01:00
Moritz
fbab21e873 Added default Directory-Wordlist from Dirbuster 2020-04-28 16:48:25 +02:00
Kirill Z
6466bd0ed2
Add more XSS 2020-04-27 20:19:33 +07:00
Kirill Z
561d6236c2
Update the fuzz-Bo0oM.txt with more ';' 2020-04-27 20:09:53 +07:00
g0tmi1k
91fc2a786a
Merge pull request #420 from haxxinen/patch-1
Create http-request-headers-fields-large.txt
2020-04-27 13:11:51 +01:00
Häxxi Häxxinen
bbb4d86ec1
Create http-request-headers-fields-large.txt
A complete list of useful HTTP request headers.
2020-04-27 13:58:14 +02:00
g0tmi1k
db59165670
Merge pull request #416 from righettod/master
Add a version of the payload for CodeContext

Source: https://portswigger.net/web-security/server-side-template-injection
2020-04-27 11:16:24 +01:00
g0tmi1k
82863eca3c
Merge pull request #418 from alisabzeghabaei/master
some new php backdoor names.

Source: https://github.com/JohnTroony/php-webshells
2020-04-27 11:14:45 +01:00
alisabzeghabaei
4efdac9a7e
some new php backdoor names.
new backdoor name added from https://github.com/JohnTroony/php-webshells repository.
2020-04-27 03:51:20 +04:30
muhammedck113
492d80186a
Update 10-million-password-list-top-100.txt 2020-04-26 20:19:21 +05:30
Dominique RIGHETTO
611d47caf3
Add a version of the payload for CodeContext
Add the payload "42*42" to the fuzzing list in order to cover the "Code context" detection point mentioned in the https://portswigger.net/web-security/server-side-template-injection training
2020-04-25 09:13:06 +02:00
g0tmi1k
9c54082eb2
Merge pull request #414 from CoccodrillooXDS/patch-1
Update names.txt
2020-04-20 11:28:37 +01:00
CoccodrillooXDS
0c14089536
Update names.txt
added "root" to the list as based on @unKn0wnUser453's issue (#408)
2020-04-20 11:54:05 +02:00
g0tmi1k
a7dbde1ec9
Merge pull request #412 from righettod/master
Collection of template engines expression

Source: https://github.com/expressjs/express/wiki#template-engines
2020-04-20 10:06:06 +01:00
g0tmi1k
b3b337e6f1
Merge pull request #390 from ipentest/add-ipentest
Added top 100 email domains to Seclists/Fuzzing

Source: https://email-verify.my-addr.com/list-of-most-popular-email-domains.php
2020-04-20 10:04:42 +01:00
Dominique RIGHETTO
1bd30300de
Add a initial collection of template engines expression 2020-04-18 17:16:20 +02:00
g0tmi1k
fa5ef9b567
Merge pull request #411 from pbafe/master
Create Drupal.txt
2020-04-16 20:14:16 +01:00
pbafe
5a8df75c4b
Create Drupal.txt 2020-04-16 20:33:25 +02:00