Server Side Vulnerabilities
1. Server-Side Request Forgery (SSRF)
Exploitation:
Common Protocols for SSRF:
Advanced SSRF Bypass Techniques:
2. Server-Side Template Injection (SSTI)
Identifying SSTI:
Exploiting SSTI by Templating Engine:
Blind SSTI:
3. Server-Side Includes (SSI) Injection
SSI Directives:
4. XSLT Injection
Common XSLT Elements:
XSLT Injection Payloads:
Advanced XSLT Exploits:
5. Fuzzing & Reconnaissance Tools
Fuzzing with wfuzz:
Port Scanning:
Web Server Scanning:
Directory Bruteforce:
6. Defensive Measures
7. API Security Considerations
8. Modern Web Architecture & Vulnerabilities
Last updated