-
Notifications
You must be signed in to change notification settings - Fork 2
Home
These are resources, tools and attacks collected from the internet to help with appsec testing.
SQLZoo's SQL Injection walkthrough51
Websec.ca's SQLi mega-resource
Ferruh Mavituna's SQLi cheatsheet
PentestMonkey's mySQL injection cheatsheet
Reiners mySQL injection Filter Evasion Cheatsheet
EvilSQL's Error/Union/Blind MSSQL Cheatsheet
PentestMonkey's MSSQL SQLi injection Cheatsheet
PentestMonkey's Oracle SQLi Cheatsheet
PentestMonkey's Postgres SQLi Cheatsheet
Ruby on Rails (Active Record) SQL Injection Guide
PentestMonkey's Ingres SQL Injection Cheat Sheet
Pentestmonkey's DB2 SQL Injection Cheat Sheet
Pentestmonkey's Informix SQL Injection Cheat Sheet
Bobby-tables.com's guide to preventing SQLi in almost every language
OWASP's SQL Prevention Cheatsheet
preeny - Some helpful preload libraries for pwning stuff.
retire.js - discover vulnerable js versions
casperXSS - Reflective/DOM XSS
XSS Payloads - Payloads for using
https://github.com/PenturaLabs/Linux_Exploit_Suggester