ASP.NET Security Testing
Reference
ASP Fuzzing
Extensions.
Headers.
Example Findings
Tools
FFUF

Critical ASP Paths Often Overlooked by Pentesters.
Abusing ASP.NET_SessionId for Unauthorized Access.
Bypassing WAFs with ASP.NET Cookieless Sessions.
Bypass WAF-Blocked Endpoints Using (S(x))

Uncovering Secrets in ASP.NET JS Files.
Fuzzing For JS On ASP.NET
Critical JavaScript Filenames On ASP.NET
Breaking Auth with Unique Path Manipulation.

Last updated