Dominique RIGHETTO
|
20cb80229b
|
Add ssh key file name
|
2022-08-02 06:19:51 +02:00 |
|
g0tmi1k
|
6d164b9672
|
Merge pull request #527 from soufianetahiri/master
Added actuator default paths and created new XSS fuzzing list
Source: https://docs.spring.io/spring-boot/docs/1.5.x/reference/html/production-ready-endpoints.html
|
2020-11-03 11:39:11 +00:00 |
|
Soufiane Tahiri
|
a8e73cb425
|
Added actuator default paths
Added actuator paths
|
2020-10-23 10:51:19 +02:00 |
|
Karim Kanso
|
607c3293b4
|
strip trailing whitespace
|
2020-05-27 14:26:51 +01:00 |
|
g0tmi1k
|
7148816422
|
Merge branch 'master' into master
|
2019-09-30 10:47:53 +01:00 |
|
Nikos Gk
|
dcf5d8162c
|
Update with missing common endpoints
Update list following discussion on Twitter: https://twitter.com/NahamSec/status/1177672652011343873
|
2019-09-28 19:20:35 +03:00 |
|
dotan3
|
95df7943d6
|
Add Laravel related urls
|
2019-09-25 11:32:24 +02:00 |
|
Eric Range
|
93e236b118
|
Update quickhits.txt
|
2019-08-13 10:21:15 +02:00 |
|
Eric Range
|
a71d0b11fd
|
new config file locations
config files for the "Damn Vulnerable Web Application (DVWA)" app.
|
2019-08-13 10:18:39 +02:00 |
|
Alexander Bridges
|
eae5072a6e
|
add bower.json dependencies file
Contains sensitive info
https://zellwk.com/blog/bower/
|
2019-07-05 18:53:08 +03:00 |
|
toxydose
|
6aa736a75a
|
ShoreTel Connect login page GHDB-ID:5172
|
2019-04-10 15:47:27 +03:00 |
|
toxydose
|
aac5204f75
|
add clientaccesspolicy.xml and crossdomain.xml files which are usually contains unsafe wildcarded configurations.
|
2018-12-02 02:23:41 +02:00 |
|
tomcodes
|
613af9601e
|
Add HashiCorp Vault GUI default URL to quickhits.txt
|
2018-11-21 16:11:47 +01:00 |
|
tomcodes
|
ff8406d36b
|
Add sonar-project.properties file to quickhits.txt
|
2018-11-21 15:54:22 +01:00 |
|
tomcodes
|
214a277412
|
Add AWS CodeDeploy appspec.yml file to quickhits.txt
|
2018-11-21 15:21:42 +01:00 |
|
Alexander Bridges
|
a53dae2a76
|
Add /wp-json/wp/v2/users
Add /wp-json/wp/v2/users WP REST API endpoint which exposes sensitive information - list of all WP users, which could be used for brute-force attacks.
|
2018-10-31 23:27:00 +02:00 |
|
Thomas Arthus
|
4f664bb240
|
Merge remote-tracking branch 'upstream/master'
|
2018-03-05 10:48:09 +01:00 |
|
g0tmi1k
|
25d4ac447e
|
rename 's/_/-/g'
|
2017-08-23 14:55:06 +01:00 |
|