Pentest Tips
search
⌘Ctrlk
Pentest Tips
  • ABOUT
  • Information Shares
  • CTF
    • Stego
    • Memory
  • Blue Team
    • Tools/Resources
    • One Liners
    • Threat Hunting
    • Scripts
    • Intrusion
  • Web
    • Resources
    • General Web
    • Subdomain Discovery
    • Content Discovery
    • MYSQL
    • Burpsuite
  • Network Exploitation
    • Resources
    • Kerberos
    • Network Based
    • Phishing
    • Metasploit
    • Weaponization
    • Password Cracking
    • Shell Upgrades
    • Linux PrivEsc
    • Windows PrivEsc
    • Windows Persistence
    • Exfiltration
  • Windows Internals
    • Kernal
  • Recon
    • Nmap
    • OSINT
    • SMB Enumeration
    • LDAP
    • Physical
  • Malware
    • Obfuscation
  • Scripting
    • Bash Basics
    • Powershell Basics
  • Cloud
    • AWS
  • Game Hacking
    • Resources
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
githubEdit
  1. Web

Resources

  • OWASP Favicon DB: https://wiki.owasp.org/index.php/OWASP_favicon_databasearrow-up-right

  • Find Sites Tech Stack: https://www.wappalyzer.com/arrow-up-right

  • Fuff, Fast Fuzzer: https://github.com/ffuf/ffufarrow-up-right

  • Command Injection Cheatsheet: https://github.com/payloadbox/command-injection-payload-listarrow-up-right

  • File Format Magic Numbers: https://en.wikipedia.org/wiki/List_of_file_signaturesarrow-up-right

  • List of MiME Media Types: https://www.iana.org/assignments/media-types/media-types.xhtmlarrow-up-right


hashtag
BurpSuite Extensions

This is a GitHub Infoshare that lists a ton of useful burp suite extensions https://github.com/snoopysecurity/awesome-burp-extensionsarrow-up-right


hashtag
Web Recon

  • URL Gatherer: https://github.com/hakluke/hakrawlerarrow-up-right

  • Find attack surfaces: https://github.com/michenriksen/aquatonearrow-up-right

  • Http probe: https://github.com/tomnomnom/httprobearrow-up-right

  • Check valid sites httpx: https://github.com/projectdiscovery/httpxarrow-up-right

  • Asset Discovery: [https://github.com/OWASP/Amass]

  • Site Rep and info: https://urlscan.io/arrow-up-right

PreviousIntrusionchevron-leftNextGeneral Webchevron-right

Last updated 3 years ago

  • BurpSuite Extensions
  • Web Recon