daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

web-vulnerabilities-methodology.md (24309B)


      1 ---
      2 title: "Web Vulnerabilities Methodology"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/web-vulnerabilities-methodology.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/web-vulnerabilities-methodology.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Web Vulnerabilities Methodology
     14 
     15 Every web pentest has both obvious and hidden attack surfaces. This page is a checklist for confirming that the major vulnerability classes and application components have been reviewed.
     16 
     17 ## Proxies
     18 
     19 > [!TIP]
     20 > Modern **web applications** commonly use **intermediary proxies**, which may introduce exploitable parsing, caching, or routing behavior. These chains usually require both a proxy weakness and a compatible backend behavior.
     21 
     22 - [ ] [**Abusing hop-by-hop headers**](/hacktricks/pentesting-web/abusing-hop-by-hop-headers)
     23 - [ ] [**Cache Poisoning/Cache Deception**](cache-deception/index.html)
     24 - [ ] [**HTTP Connection Contamination**](/hacktricks/pentesting-web/http-connection-contamination)
     25 - [ ] [**HTTP Connection Request Smuggling**](/hacktricks/pentesting-web/http-connection-request-smuggling)
     26 - [ ] [**HTTP Request Smuggling**](/hacktricks/pentesting-web/http-request-smuggling/overview)
     27 - [ ] [**HTTP Response Smuggling / Desync**](/hacktricks/pentesting-web/http-response-smuggling-desync)
     28 - [ ] [**H2C Smuggling**](/hacktricks/pentesting-web/h2c-smuggling)
     29 - [ ] [**Server Side Inclusion/Edge Side Inclusion**](/hacktricks/pentesting-web/server-side-inclusion-edge-side-inclusion-injection)
     30 - [ ] [**Uncovering Cloudflare**](/hacktricks/network-services-pentesting/pentesting-web/uncovering-cloudflare)
     31 - [ ] [**XSLT Server Side Injection**](/hacktricks/pentesting-web/xslt-server-side-injection-extensible-stylesheet-language-transformations)
     32 - [ ] [**Proxy / WAF Protections Bypass**](/hacktricks/pentesting-web/proxy-waf-protections-bypass)
     33 
     34 ## **User input**
     35 
     36 > [!TIP]
     37 > Most of the web applications will **allow users to input some data that will be processed later.**\
     38 > Depending on the structure of the data the server is expecting some vulnerabilities may or may not apply.
     39 
     40 ### **Reflected Values**
     41 
     42 If the introduced data may somehow be reflected in the response, the page might be vulnerable to several issues.
     43 
     44 - [ ] [**Client Side Path Traversal**](/hacktricks/pentesting-web/client-side-path-traversal)
     45 - [ ] [**Client Side Template Injection**](/hacktricks/pentesting-web/client-side-template-injection-csti)
     46 - [ ] [**Command Injection**](/hacktricks/pentesting-web/command-injection)
     47 - [ ] [**CRLF**](/hacktricks/pentesting-web/crlf-0d-0a)
     48 - [ ] [**Dangling Markup**](dangling-markup-html-scriptless-injection/index.html)
     49 - [ ] [**File Inclusion/Path Traversal**](file-inclusion/index.html)
     50 - [ ] [**Open Redirect**](/hacktricks/pentesting-web/open-redirect)
     51 - [ ] [**Prototype Pollution to XSS**](deserialization/nodejs-proto-prototype-pollution/index.html#client-side-prototype-pollution-to-xss)
     52 - [ ] [**Server Side Inclusion/Edge Side Inclusion**](/hacktricks/pentesting-web/server-side-inclusion-edge-side-inclusion-injection)
     53 - [ ] [**Server Side Request Forgery**](ssrf-server-side-request-forgery/index.html)
     54 - [ ] [**Server Side Template Injection**](ssti-server-side-template-injection/index.html)
     55 - [ ] [**Reverse Tab Nabbing**](/hacktricks/pentesting-web/reverse-tab-nabbing)
     56 - [ ] [**XSLT Server Side Injection**](/hacktricks/pentesting-web/xslt-server-side-injection-extensible-stylesheet-language-transformations)
     57 - [ ] [**XSS**](xss-cross-site-scripting/index.html)
     58 - [ ] [**Abusing Service Workers**](/hacktricks/pentesting-web/xss-cross-site-scripting/abusing-service-workers)
     59 - [ ] [**WASM linear-memory XSS pivots**](/hacktricks/pentesting-web/xss-cross-site-scripting/wasm-linear-memory-template-overwrite-xss)
     60 - [ ] [**XSSI**](/hacktricks/pentesting-web/xssi-cross-site-script-inclusion)
     61 - [ ] [**XS-Search**](xs-search/index.html)
     62 
     63 Some of these vulnerabilities require special conditions, while others only require reflection in a dangerous context. The following page contains polyglots for quickly testing several classes:
     64 
     65 
     66 [Pocs And Polygloths Cheatsheet](/hacktricks/pentesting-web/pocs-and-polygloths-cheatsheet/overview)
     67 
     68 ### Modern client-side code execution pivots
     69 
     70 When a reflection bug lands in a **modern SPA**, spend a few extra minutes on the browser-managed primitives and native bridges the page already owns:
     71 
     72 - **Service workers**: inspect the active registration path, effective scope, and any `Service-Worker-Allowed` broadening. A low-impact HTML injection or DOM clobbering bug can become **origin-wide persistence** if the page registers a worker or feeds attacker-controlled values into `importScripts()`.<sup>[[3]](#references)</sup>
     73 - **WASM / Emscripten modules**: fuzz length, offset, and type conversions crossing the **JS ↔ WASM** boundary. In practice, a memory bug in linear memory may let you overwrite **trusted HTML templates or state objects** and upgrade a constrained client-side bug into DOM XSS.
     74 - **Generated clients**: minified bundles frequently disclose GraphQL persisted-query hashes, gRPC-Web method paths, `postMessage` handlers, WebSocket event names, and hidden admin routes even when the UI never exposes them.
     75 
     76 For deeper exploitation ideas, check [Abusing Service Workers](/hacktricks/pentesting-web/xss-cross-site-scripting/abusing-service-workers), [WebAssembly linear memory corruption to DOM XSS](/hacktricks/pentesting-web/xss-cross-site-scripting/wasm-linear-memory-template-overwrite-xss), and [Code Review Tooling](/hacktricks/network-services-pentesting/pentesting-web/code-review-tools).
     77 
     78 #### File System Access API: browser-native file read/write abuse
     79 
     80 Chromium-family browsers expose **`showOpenFilePicker()`**, **`showSaveFilePicker()`**, and **`showDirectoryPicker()`** to trusted pages in a **secure context** and after a **user gesture**.<sup>[[6]](#references)</sup><sup>[[7]](#references)</sup> If a target web app, phishing lure, or malicious dependency can convince the user to approve a directory with **read-write** access, the page can operate on the selected files **without dropping a native payload**.<sup>[[5]](#references)</sup>
     81 
     82 Practical abuse patterns:
     83 
     84 - Enumerate the selected directory with **`for await (const [name, handle] of dirHandle.entries())`** or `values()`, recurse into subdirectories, and filter by extension/MIME.
     85 - Read file contents with **`handle.getFile()`** and `text()`, `arrayBuffer()`, or `stream()`, then exfiltrate through `fetch`, XHR, or `sendBeacon`.
     86 - Overwrite files with **`createWritable()`** after a `queryPermission()` / `requestPermission({mode: 'readwrite'})` flow. This is the primitive that enables **browser-native ransomware** or destructive tampering.<sup>[[5]](#references)</sup><sup>[[9]](#references)</sup>
     87 - Check **IndexedDB** for serialized `FileSystemFileHandle` / `FileSystemDirectoryHandle` objects because legitimate apps often persist handles and later reuse them after `queryPermission()` / `requestPermission()` checks.
     88 - Review the UX around picker prompts: fake **AI upscalers**, editors, and media tools can plausibly ask for an input file first and an **output folder** second, making the write warning look legitimate.<sup>[[5]](#references)</sup>
     89 
     90 Important boundaries:
     91 
     92 - This is **not arbitrary disk access**. Chromium blocks or constrains many sensitive locations, but user-chosen media folders can still be high-value targets. In recent public research, **Pictures**, **Videos**, and Android **`DCIM`** roots were practical lure targets.<sup>[[5]](#references)</sup>
     93 - A normal web page still cannot become native malware: global keylogging, arbitrary desktop screenshots, and OS persistence remain outside the browser sandbox unless another vulnerability is present. The real primitive is **user-approved local file read/write**.
     94 - Browser support is concentrated in **Chromium**. Chrome shipped the API on desktop in **Chrome 86** and extended it to **Android/WebView in Chrome 132**; Firefox and Safari do not expose the same picker methods.<sup>[[8]](#references)</sup>
     95 
     96 ### **Search functionalities**
     97 
     98 If the functionality may be used to search some kind of data inside the backend, maybe you can (ab)use it to search arbitrary data.
     99 
    100 - [ ] [**File Inclusion/Path Traversal**](file-inclusion/index.html)
    101 - [ ] [**NoSQL Injection**](/hacktricks/pentesting-web/nosql-injection)
    102 - [ ] [**LDAP Injection**](/hacktricks/pentesting-web/ldap-injection)
    103 - [ ] [**ReDoS**](/hacktricks/pentesting-web/regular-expression-denial-of-service-redos)
    104 - [ ] [**SQL Injection**](sql-injection/index.html)
    105 - [ ] [**ORM Injection**](/hacktricks/pentesting-web/orm-injection)
    106 - [ ] [**RSQL Injection**](/hacktricks/pentesting-web/rsql-injection)
    107 - [ ] [**XPATH Injection**](/hacktricks/pentesting-web/xpath-injection)
    108 
    109 ### **Forms, WebSockets and PostMsgs**
    110 
    111 When a WebSocket sends messages or a form lets users perform actions, request-forgery and message-trust vulnerabilities may arise.
    112 
    113 - [ ] [**Cross Site Request Forgery**](/hacktricks/pentesting-web/csrf-cross-site-request-forgery)
    114 - [ ] [**Cross-site WebSocket hijacking (CSWSH)**](/hacktricks/pentesting-web/websocket-attacks)
    115 - [ ] [**Phone Number Injections**](/hacktricks/pentesting-web/phone-number-injections)
    116 - [ ] [**PostMessage Vulnerabilities**](postmessage-vulnerabilities/index.html)
    117 
    118 #### Cross-site WebSocket hijacking & localhost abuse
    119 
    120 WebSocket upgrades automatically forward cookies and do not block `ws://127.0.0.1`, so **any web origin can drive desktop IPC endpoints** that skip `Origin` validation. When you spot a launcher exposing a JSON-RPC-like API through a local agent:<sup>[[1]](#references)</sup>
    121 
    122 - Observe emitted frames to clone the `type`/`name`/`args` tuples required by each method.
    123 - Bruteforce the listening port directly from the browser (Chromium will handle ~16k failed upgrades) until a loopback socket answers with the protocol banner—Firefox tends to crash quickly under the same load.
    124 - Chain a *create → privileged action* pair: e.g., invoke a `create*` method that returns a GUID and immediately call the corresponding `*Launch*` method with attacker-controlled payloads.
    125 
    126 If you can pass arbitrary JVM flags (such as `AdditionalJavaArguments`), force an error with `-XX:MaxMetaspaceSize=<tiny>` and attach `-XX:OnOutOfMemoryError="<cmd>"` to run OS commands without touching application logic. See [WebSocket attacks](/hacktricks/pentesting-web/websocket-attacks#localhost-websocket-abuse--browser-port-discovery) for a walk-through.
    127 
    128 ### Installers / setup wizards / recovery leftovers
    129 
    130 First-run installers and recovery endpoints are often forgotten in production. If a live application still exposes paths such as `/install/`, `/setup/`, `/init/`, `/admin/install`, `/setup/setupadministrator.action`, or readable config files such as `/config/database.php`, treat them as **high-value takeover primitives** instead of low-value information leaks.<sup>[[2]](#references)</sup>
    131 
    132 Checks to perform:
    133 
    134 - Fuzz for installer and reconfiguration paths with `ffuf`, `dirsearch`, or wordlists containing `install`, `setup`, `wizard`, `init`, `upgrade`, `db`, `config`, and `admin`.
    135 - Open the wizard and determine whether it still accepts **database / SMTP / admin** parameters after deployment, or whether a server-side `setupComplete` / lock file can be flipped or bypassed.
    136 - If the installer accepts arbitrary DB settings, test whether the application will connect to an **attacker-controlled external DB** and bootstrap its schema there. This can yield **admin creation**, backend **state disclosure**, or application **DoS** if the remote DB later disappears.
    137 - After any successful reinitialization, revisit old authenticated tabs and test whether **pre-existing sessions remain valid** even after the backend DB/configuration is restored. PHP apps often keep session state outside MySQL, so restoring the DB may not revoke attacker sessions.
    138 - Review incident-response paths: password reset, admin creation, DB restore, installer rerun, maintenance exit. If none of them rotate session IDs or invalidate server-side session stores, keep testing for persistent dashboard access.
    139 
    140 Operational notes:
    141 
    142 - Outbound connectivity matters: if the web tier can reach arbitrary MySQL hosts, SSRF-style egress restrictions are missing and installer abuse becomes much easier.
    143 - Sudden `500` errors immediately after setup changes can indicate the application is still pointing to attacker-supplied infrastructure.
    144 - Framework/app-specific examples exist (for example Confluence setup reactivation admin creation), but the reusable technique is **production reinstallation / reinitialization abuse**.
    145 
    146 ### **HTTP Headers**
    147 
    148 Depending on the HTTP headers given by the web server some vulnerabilities might be present.
    149 
    150 - [ ] [**Clickjacking**](/hacktricks/pentesting-web/clickjacking)
    151 - [ ] [**Iframe Traps / Click Isolation**](/hacktricks/pentesting-web/iframe-traps)
    152 - [ ] [**Content Security Policy bypass**](content-security-policy-csp-bypass/index.html)
    153 - [ ] [**Cookies Hacking**](hacking-with-cookies/index.html)
    154 - [ ] [**CORS - Misconfigurations & Bypass**](/hacktricks/pentesting-web/cors-bypass)
    155 
    156 ### **Bypasses**
    157 
    158 There are several specific functionalities where some workarounds might be useful to bypass them
    159 
    160 - [ ] [**2FA/OTP Bypass**](/hacktricks/pentesting-web/2fa-bypass)
    161 - [ ] [**Bypass Payment Process**](/hacktricks/pentesting-web/bypass-payment-process)
    162 - [ ] [**Captcha Bypass**](/hacktricks/pentesting-web/captcha-bypass)
    163 - [ ] [**Account Takeover Playbooks**](/hacktricks/pentesting-web/account-takeover)
    164 - [ ] [**Login Bypass**](login-bypass/index.html)
    165 - [ ] [**Race Condition**](/hacktricks/pentesting-web/race-condition)
    166 - [ ] [**Rate Limit Bypass**](/hacktricks/pentesting-web/rate-limit-bypass)
    167 - [ ] [**Reset Forgotten Password Bypass**](/hacktricks/pentesting-web/reset-password)
    168 - [ ] [**Registration Vulnerabilities**](/hacktricks/pentesting-web/registration-vulnerabilities)
    169 
    170 ### **Structured objects / Specific functionalities**
    171 
    172 Some functionalities will require the **data to be structured in a very specific format** (like a language serialized object or XML). Therefore, it's easier to identify if the application might be vulnerable as it needs to be processing that kind of data.\
    173 Some **specific functionalities** may be also vulnerable if a **specific format of the input is used** (like Email Header Injections).
    174 
    175 - [ ] [**Deserialization**](deserialization/index.html)
    176 - [ ] [**Email Header Injection**](/hacktricks/pentesting-web/email-injections)
    177 - [ ] [**JWT Vulnerabilities**](/hacktricks/pentesting-web/hacking-jwt-json-web-tokens)
    178 - [ ] [**JSON / XML / YAML Hacking**](/hacktricks/pentesting-web/json-xml-yaml-hacking)
    179 - [ ] [**XML External Entity**](/hacktricks/pentesting-web/xxe-xee-xml-external-entity)
    180 - [ ] [**GraphQL Attacks**](/hacktricks/network-services-pentesting/pentesting-web/graphql)
    181 - [ ] [**gRPC-Web Attacks**](/hacktricks/pentesting-web/grpc-web-pentest)
    182 - [ ] [**SOAP/JAX-WS ThreadLocal Auth Bypass**](/hacktricks/pentesting-web/soap-jax-ws-threadlocal-auth-bypass)
    183 
    184 ### Files
    185 
    186 Functionalities that allow uploading files might be vulnerable to several issues.\
    187 Functionalities that generate files including user input might execute unexpected code.\
    188 Users that open files uploaded by users or automatically generated including user input might be compromised.
    189 
    190 - [ ] [**File Upload**](file-upload/index.html)
    191 - [ ] [**Formula Injection**](/hacktricks/pentesting-web/formula-csv-doc-latex-ghostscript-injection)
    192 - [ ] [**PDF Injection**](/hacktricks/pentesting-web/xss-cross-site-scripting/pdf-injection)
    193 - [ ] [**Server Side XSS**](/hacktricks/pentesting-web/xss-cross-site-scripting/server-side-xss-dynamic-pdf)
    194 
    195 ### **External Identity Management**
    196 
    197 - [ ] [**OAUTH to Account takeover**](/hacktricks/pentesting-web/oauth-to-account-takeover)
    198 - [ ] [**SAML Attacks**](saml-attacks/index.html)
    199 
    200 #### Passkeys / WebAuthn handoffs
    201 
    202 Passkeys are **origin-bound**, so the usual bug is not "steal the secret" but **abuse the workflow around the ceremony**:<sup>[[4]](#references)</sup>
    203 
    204 - Try **registration/login confusion**: start a WebAuthn ceremony in one account or browser, then complete it from another session and check whether the signed challenge is still bound to the correct user, RP, and browser state.
    205 - Treat **QR, device-code, wallet, and cross-device approvals** exactly like password-reset tokens: check replay, stale approvals, session swapping, and whether a completed ceremony authenticates a browser different from the one that initiated it.
    206 - If you already have **XSS or strong clickjacking** on the relying-party origin, test whether you can drive extension/browser UI to approve a legitimate passkey login for the victim without exposing the credential material.
    207 
    208 See [Account Takeover](/hacktricks/pentesting-web/account-takeover#qr--cross-device-login-flows) and [Clickjacking](/hacktricks/pentesting-web/clickjacking#browser-extensions-dom-based-autofill-clickjacking) for concrete attack patterns.
    209 
    210 ### **Other Helpful Vulnerabilities**
    211 
    212 These vulnerabilities might help to exploit other vulnerabilities.
    213 
    214 - [ ] [**Domain/Subdomain takeover**](/hacktricks/pentesting-web/domain-subdomain-takeover)
    215 - [ ] [**IDOR**](/hacktricks/pentesting-web/idor)
    216 - [ ] [**Mass Assignment (CWE-915)**](/hacktricks/pentesting-web/mass-assignment-cwe-915)
    217 - [ ] [**Parameter Pollution**](/hacktricks/pentesting-web/parameter-pollution)
    218 - [ ] [**Unicode Normalization vulnerability**](unicode-injection/index.html)
    219 
    220 ### **Web Servers & Middleware**
    221 
    222 Misconfigurations in the edge stack often unlock more impactful bugs in the application layer.
    223 
    224 - [ ] [**Apache**](/hacktricks/network-services-pentesting/pentesting-web/apache)
    225 - [ ] [**Nginx**](/hacktricks/network-services-pentesting/pentesting-web/nginx)
    226 - [ ] [**IIS**](/hacktricks/network-services-pentesting/pentesting-web/iis-internet-information-services)
    227 - [ ] [**Tomcat**](/hacktricks/network-services-pentesting/pentesting-web/tomcat/overview)
    228 - [ ] [**Spring Actuators**](/hacktricks/network-services-pentesting/pentesting-web/spring-actuators)
    229 - [ ] [**PUT Method / WebDAV**](/hacktricks/network-services-pentesting/pentesting-web/put-method-webdav)
    230 - [ ] [**Special HTTP Headers**](/hacktricks/network-services-pentesting/pentesting-web/special-http-headers)
    231 - [ ] [**WSGI Deployment**](/hacktricks/network-services-pentesting/pentesting-web/wsgi)
    232 - [ ] [**Werkzeug Debug Exposure**](/hacktricks/network-services-pentesting/pentesting-web/werkzeug)
    233 
    234 ### **Application Frameworks & Stacks**
    235 
    236 Framework-specific primitives frequently expose gadgets, dangerous defaults, or framework-owned endpoints.
    237 
    238 > [!TIP]
    239 > Always download the **front-end bundles and `*.map` files** before assuming a route or action is unreachable. Modern builds often leak **Next.js Server Actions**, GraphQL persisted-query hashes, tRPC router names, gRPC-Web paths, feature flags, and role strings that are perfect for low-privilege replay and authorization testing.
    240 
    241 - [ ] [**Django**](/hacktricks/network-services-pentesting/pentesting-web/django)
    242 - [ ] [**Flask**](/hacktricks/network-services-pentesting/pentesting-web/flask)
    243 - [ ] [**NodeJS / Express**](/hacktricks/network-services-pentesting/pentesting-web/nodejs-express)
    244 - [ ] [**Angular**](/hacktricks/network-services-pentesting/pentesting-web/angular)
    245 - [ ] [**Vue / Nuxt**](/hacktricks/network-services-pentesting/pentesting-web/vuejs)
    246 - [ ] [**Next.js**](/hacktricks/network-services-pentesting/pentesting-web/nextjs)
    247 - [ ] [**Laravel**](/hacktricks/network-services-pentesting/pentesting-web/laravel)
    248 - [ ] [**Symfony**](/hacktricks/network-services-pentesting/pentesting-web/symphony)
    249 
    250 Quick grep targets inside downloaded bundles:
    251 
    252 ```bash
    253 rg -n 'sourceMappingURL|createServerReference|Next-Action|queryHash|persistedQuery|grpc-web|protobuf|new WebSocket\(|postMessage\(' ./static ./dist ./_next ./assets 2>/dev/null
    254 ```
    255 
    256 Useful follow-up reading: [Code Review Tooling](/hacktricks/network-services-pentesting/pentesting-web/code-review-tools) and [Next.js](/hacktricks/network-services-pentesting/pentesting-web/nextjs#nextjs-server-actions-enumeration-hash-to-function-name-via-source-maps).
    257 
    258 ### **CMS, SaaS & Managed Platforms**
    259 
    260 High-surface products often ship with known exploits, weak plugins, or privileged admin endpoints.
    261 
    262 - [ ] [**WordPress**](/hacktricks/network-services-pentesting/pentesting-web/wordpress)
    263 - [ ] [**Joomla**](/hacktricks/network-services-pentesting/pentesting-web/joomla)
    264 - [ ] [**Drupal**](/hacktricks/network-services-pentesting/pentesting-web/drupal/overview)
    265 - [ ] [**Moodle**](/hacktricks/network-services-pentesting/pentesting-web/moodle)
    266 - [ ] [**Prestashop**](/hacktricks/network-services-pentesting/pentesting-web/prestashop)
    267 - [ ] [**Atlassian Jira**](/hacktricks/network-services-pentesting/pentesting-web/jira)
    268 - [ ] [**Grafana**](/hacktricks/network-services-pentesting/pentesting-web/grafana)
    269 - [ ] [**Rocket.Chat**](/hacktricks/network-services-pentesting/pentesting-web/rocket-chat)
    270 - [ ] [**Zabbix**](/hacktricks/network-services-pentesting/pentesting-web/zabbix)
    271 - [ ] [**Microsoft SharePoint**](/hacktricks/network-services-pentesting/pentesting-web/microsoft-sharepoint)
    272 - [ ] [**Sitecore**](/hacktricks/network-services-pentesting/pentesting-web/sitecore/overview)
    273 
    274 ### **APIs, Buckets & Integrations**
    275 
    276 Server-side helpers and third-party integrations can expose file parsing or storage-layer weaknesses.
    277 
    278 - [ ] [**Web API Pentesting**](/hacktricks/network-services-pentesting/pentesting-web/web-api-pentesting)
    279 - [ ] [**Storage Buckets & Firebase**](/hacktricks/network-services-pentesting/pentesting-web/buckets/overview)
    280 - [ ] [**Imagemagick Security**](/hacktricks/network-services-pentesting/pentesting-web/imagemagick-security)
    281 - [ ] [**Artifactory & Package Registries**](/hacktricks/network-services-pentesting/pentesting-web/artifactory-hacking-guide)
    282 - [ ] [**Code Review Tooling**](/hacktricks/network-services-pentesting/pentesting-web/code-review-tools)
    283 
    284 ### **Supply Chain & Identifier Abuse**
    285 
    286 Attacks that target build pipelines or predictable identifiers can become the initial foothold before exploiting traditional bugs.
    287 
    288 - [ ] [**Dependency Confusion**](/hacktricks/pentesting-web/dependency-confusion)
    289 - [ ] [**Timing Attacks**](/hacktricks/pentesting-web/timing-attacks)
    290 - [ ] [**UUID Insecurities**](/hacktricks/pentesting-web/uuid-insecurities)
    291 
    292 ### **Web3, Extensions & Tooling**
    293 
    294 Modern applications extend into browsers, wallets, and automation pipelines—keep these vectors in scope.
    295 
    296 - [ ] [**dApps / Decentralized Applications**](/hacktricks/pentesting-web/dapps-decentralizedapplications)
    297 - [ ] [**Browser Extension Pentesting**](/hacktricks/pentesting-web/browser-extension-pentesting-methodology/overview)
    298 - [ ] [**wfuzz Web Fuzzing**](/hacktricks/pentesting-web/web-tool-wfuzz)
    299 
    300 ## References
    301 
    302 - [1] [When WebSockets Lead to RCE in CurseForge](https://elliott.diy/blog/curseforge/)
    303 - [2] [I Accidentally Logged as Admin Into a Threat Actor Website](https://potato.id/en/posts/i-accidentally-logged-into-threat-actor-website)
    304 - [3] [Hijacking service workers via DOM Clobbering](https://portswigger.net/research/hijacking-service-workers-via-dom-clobbering)
    305 - [4] [Security advisory: Passkey Dialog Clickjacking Issue](https://support.dashlane.com/hc/en-us/articles/28598967624722-Security-advisory-Passkey-Dialog-Clickjacking-Issue)
    306 - [5] [Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique](https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/)
    307 - [6] [File System Access specification](https://wicg.github.io/file-system-access/)
    308 - [7] [The File System Access API: simplifying access to local files](https://developer.chrome.com/docs/capabilities/web-apis/file-system-access)
    309 - [8] [Chrome 132 release notes](https://developer.chrome.com/release-notes/132)
    310 - [9] [RøB: Ransomware over Modern Web Browsers](https://www.usenix.org/conference/usenixsecurity23/presentation/oz)