PayloadsAllTheThings
A list of useful payloads
HOME
CATEGORIES
TAGS
ARCHIVES
ABOUT
Home
Archives
Archives
Cancel
Archives
2022
10
Jan
XSS Injection
10
Jan
XSS with Relative Path Overwrite - IE 8/9 and lower
10
Jan
XSS in Angular and AngularJS
10
Jan
PostgreSQL Injection
10
Jan
Oraclesql injection
10
Jan
Hql injection
2021
09
May
Command Injection
07
May
Bind Shell
06
May
Readme
06
May
Windows - Using credentials
06
May
Windows - Privilege Escalation
06
May
Windows - Mimikatz
06
May
Active Directory Attacks
01
May
AWS
26
Apr
Reverse Shell Cheat Sheet
25
Apr
XML External Entity
22
Apr
Office - Attacks
22
Apr
GraphQL Injection
15
Apr
Linux - Privilege Escalation
30
Mar
Upload Insecure Files
26
Mar
SQL injection
26
Mar
MSSQL Injection
25
Mar
Windows amsi bypass
25
Mar
Mssql server cheatsheet
24
Mar
Server Side Request Forgery
17
Mar
Csv Injection
22
Feb
Account takeover
03
Feb
Insecure Source Code Management
30
Jan
Cobalt strike cheatsheet
25
Jan
Api Key Leaks
20
Jan
Kubernetes
17
Jan
Request Smuggling
13
Jan
Escape breakout
09
Jan
Windows persistence
2020
23
Dec
Http Parameter Pollution
18
Dec
Insecure Deserialization
18
Dec
Aws Amazon Bucket S3
17
Dec
Network pivoting techniques
13
Dec
Tabnabbing
13
Dec
Methodology and enumeration
13
Dec
Container docker pentest
13
Dec
Cve Exploits
13
Dec
Cors Misconfiguration
12
Dec
File Inclusion
08
Dec
Type Juggling
26
Nov
Open Redirect
18
Nov
SQLite Injection
29
Oct
MYSQL Injection
28
Oct
Insecure Management Interface
25
Oct
Crlf Injection
18
Oct
Web Cache Deception
18
Oct
Network discovery
16
Oct
Metasploit cheatsheet
09
Oct
Directory Traversal
09
Oct
Cassandra Injection
23
Sep
Linux persistence
09
Sep
LDAP Injection
24
May
XPath Injection
24
May
NoSQL Injection
16
May
Azure
12
May
SAML Injetion
22
Apr
Insecure Direct Object References
17
Apr
JWT - JSON Web Token
11
Apr
Web Socket Attack
16
Mar
Miscellaneous tricks
26
Jan
Race Condition
2019
26
Dec
XSLT Injection
17
Dec
CSRF Injection
27
Sep
Subdomains Enumeration
13
May
OAuth
07
Mar
Koadic C3 COM Command & Control - JScript RAT
07
Mar
Windows - Download and execute methods
07
Mar
LaTex Injection
Trending Tags
Injection
Database
Server
Network
XSS
SQL
Windows
Exploits
Security
Shell
Trending Tags
Injection
Database
Server
Network
XSS
SQL
Windows
Exploits
Security
Shell