-
Notifications
You must be signed in to change notification settings - Fork 23
/
hunt_archive
190 lines (166 loc) · 1.39 KB
/
hunt_archive
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
HUNT Params Archvive (2016)
Issues
# Insecure Direct Object Reference
Check Location
Request: true
Response: false
Detail: Description of the issue
Params:
id
user
account
number
order
no
doc
key
email
group
profile
edit
report
# OS Command Injection
Check Location
Request: true
Response: false
Params:
daemon
upload
dir
execute
download
log
ip
cli
cmd
# File Inclusion and Path Traversal
Check Location
Request: true
Response: false
Params:
file
document
folder
root
path
pg
style
pdf
template
php_path
doc
# SQL Injection
Check Location
Request: true
Response: false
Params:
id
select
report
role
update
query
user
name
sort
where
search
params
process
row
view
table
from
sel
results
sleep
fetch
order
keyword
column
field
delete
string
number
filter
# Server Side Request Forgery
Check Location
Request: true
Response: false
Params:
dest
redirect
uri
path
continue
url
window
next
data
reference
site
html
val
validate
domain
callback
return
page
feed
host
port
to
out
view
dir
show
navigation
open
# Server Side Template Injection
Check Location
Request: true
Response: false
Params:
template
preview
id
view
activity
name
content
redirect
# Debug and Logic Parameters
Check Location
Request: true
Response: false
Params:
access
admin
dbg
debug
edit
grant
test
alter
clone
create
delete
disable
enable
exec
execute
load
make
modify
rename
reset
shell
toggle
adm
root
cfg
config
adm
root
cfg
config