Commit Graph

20 Commits

Author SHA1 Message Date
DoI
82438ac31c Standardize leading slases in web conent
Added bonus of moving ispsystem_billmanager_api.txt from CRLF to LF line
endings.
2023-05-18 23:55:53 +12:00
Krzysztof Zając
0665d0fe72 Fresher backups in Discovery/Web-Content/quickhits.txt 2022-11-25 13:32:56 +01:00
Dominique RIGHETTO
20cb80229b
Add ssh key file name 2022-08-02 06:19:51 +02:00
g0tmi1k
6d164b9672
Merge pull request #527 from soufianetahiri/master
Added actuator default paths and created new XSS fuzzing list

Source: https://docs.spring.io/spring-boot/docs/1.5.x/reference/html/production-ready-endpoints.html
2020-11-03 11:39:11 +00:00
Soufiane Tahiri
a8e73cb425
Added actuator default paths
Added actuator paths
2020-10-23 10:51:19 +02:00
Karim Kanso
607c3293b4 strip trailing whitespace 2020-05-27 14:26:51 +01:00
g0tmi1k
7148816422
Merge branch 'master' into master 2019-09-30 10:47:53 +01:00
Nikos Gk
dcf5d8162c
Update with missing common endpoints
Update list following discussion on Twitter: https://twitter.com/NahamSec/status/1177672652011343873
2019-09-28 19:20:35 +03:00
dotan3
95df7943d6 Add Laravel related urls 2019-09-25 11:32:24 +02:00
Eric Range
93e236b118
Update quickhits.txt 2019-08-13 10:21:15 +02:00
Eric Range
a71d0b11fd
new config file locations
config files for the "Damn Vulnerable Web Application (DVWA)" app.
2019-08-13 10:18:39 +02:00
Alexander Bridges
eae5072a6e
add bower.json dependencies file
Contains sensitive info
https://zellwk.com/blog/bower/
2019-07-05 18:53:08 +03:00
toxydose
6aa736a75a ShoreTel Connect login page GHDB-ID:5172 2019-04-10 15:47:27 +03:00
toxydose
aac5204f75 add clientaccesspolicy.xml and crossdomain.xml files which are usually contains unsafe wildcarded configurations. 2018-12-02 02:23:41 +02:00
tomcodes
613af9601e Add HashiCorp Vault GUI default URL to quickhits.txt 2018-11-21 16:11:47 +01:00
tomcodes
ff8406d36b Add sonar-project.properties file to quickhits.txt 2018-11-21 15:54:22 +01:00
tomcodes
214a277412 Add AWS CodeDeploy appspec.yml file to quickhits.txt 2018-11-21 15:21:42 +01:00
Alexander Bridges
a53dae2a76
Add /wp-json/wp/v2/users
Add /wp-json/wp/v2/users WP REST API endpoint which exposes sensitive information - list of all WP users, which could be used for brute-force attacks.
2018-10-31 23:27:00 +02:00
Thomas Arthus
4f664bb240 Merge remote-tracking branch 'upstream/master' 2018-03-05 10:48:09 +01:00
g0tmi1k
25d4ac447e rename 's/_/-/g' 2017-08-23 14:55:06 +01:00