Sec-88
Ctrlk
  • 🧑Whoami
  • 🕸️Web-AppSec
    • Industry Based Checklist
    • Services Based Pentest Checklist
    • Features Abuse
    • Reconnaissance
    • XSS-HTML Injection
    • Improper Authentication
    • OAUTH Misconfigurations
    • Broken Access Control
    • Subdomain Enumeration
    • Fingerprinting
    • Dorking
    • Auth0 Misconfigurations
    • Broken Link Injection
    • Command Injection
    • CORS
    • CRLF
    • CSRF
    • Host Header Attacks
    • HTTP request smuggling
    • JSON Request Testing
    • LFI
    • No Rate Limit
    • Parameters Manual Testing
    • Open Redirect
    • Registration & Takeover Bugs
    • Remote Code Execution (RCE)
    • Session Fixation
    • SQL Injection
    • SSRF
    • SSTI
    • Subdomain Takeover
    • Web Caching Vulnerabilities
    • WebSockets
    • XXE
    • Cookie Based Attacks
    • CMS
    • XSSI (Cross Site Script Inclusion)
    • NoSQL injection
    • Local VS Remote Session Fixation
    • Protection
    • Hacking IIS Applications
    • Dependency Confusion
    • Attacking Secondary Context
    • Hacking Web Sockets
    • IDN Homograph Attack
    • DNS Rebinding Attack
    • LLM Hacking Checklist
    • Bypass URL Filtration
    • Cross-Site Path Traversal (CSPT)
    • PostMessage Security
    • Prototype Pollution
    • Tools-Extensions-Bookmarks
    • WAF Bypassing Techniques
    • SSL/TLS Certificate Lifecycle
    • Serialization in .NET
    • Client-Side Attacks
      • JavaScript Analysis
    • Bug Bounty Platforms/Programs
    • DNS Dangling / NS Takeover
    • X-Correlation Injection
    • DoS - Exploiting WAF Request Size Limits
    • Next.js middleware CP - DOS
    • Cache Poisoning Test Plan for Next.js
    • Nuxt CP - DOS
    • Next.js Middleware Bypass
    • Exploiting Parser Flaws for Access Bypasses
    • Session Puzzling Attack
    • ASP.NET Security Testing
  • ✉️API-Sec
  • 📱Android-AppSec
  • IOS-AppSec
  • 📶Network-Sec
  • 💻Desktop AppSec
  • ☁️Cloud Sec
  • 👨‍💻Programming
  • 🖥️Operating Systems
  • ✍️Write-Ups
Powered by GitBook
On this page

Was this helpful?

Edit
  1. 🕸️Web-AppSec

Client-Side Attacks

  • https://hackerone.com/reports/67386

  • https://hackerone.com/reports/332708

  • https://portswigger.net/web-security/dom-based

  • https://hackerone.com/bobrov

  • https://github.com/BlackFan/content-type-research

  • https://github.com/BlackFan/client-side-prototype-pollution

PreviousSerialization in .NETNextJavaScript Analysis

Last updated 9 months ago

Was this helpful?