【漏洞总结】常见漏洞总结归纳自学路线图

admin 2024年4月14日20:51:48评论4 views字数 2515阅读8分23秒阅读模式

常见漏洞总结归纳自学路线图

SQL注入漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/sql-injectionhttps://portswigger.net/web-security/all-labs#sql-injectionhttps://github.com/Audi-1/sqli-labshttps://github.com/sqlmapproject/sqlmaphttps://www.acunetix.com/websitesecurity/sql-injection/

目录遍历漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/file-path-traversalhttps://portswigger.net/web-security/all-labs#path-traversal

命令执行漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/os-command-injectionhttps://portswigger.net/web-security/all-labs#os-command-injection

暴力猜解漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/logic-flawshttps://portswigger.net/web-security/all-labs#business-logic-vulnerabilities

信息泄露漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/information-disclosurehttps://portswigger.net/web-security/all-labs#information-disclosure

越权漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/access-controlhttps://portswigger.net/web-security/access-control/security-models

文件上传漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/file-uploadhttps://portswigger.net/web-security/all-labs#file-upload-vulnerabilitieshttps://github.com/c0ny1/upload-labs

竞争条件漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/race-conditionshttps://portswigger.net/web-security/all-labs#race-conditions

SSRF服务器端请求伪造漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/ssrfhttps://portswigger.net/web-security/all-labs#server-side-request-forgery-ssrf

XXE(XML实体注入)漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/xxehttps://github.com/c0ny1/xxe-lab

XSS跨站脚本攻击漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/cross-site-scriptinghttps://portswigger.net/web-security/all-labs#cross-site-scriptinghttps://www.acunetix.com/websitesecurity/cross-site-scripting/

CSRF跨站请求伪造漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/csrfhttps://portswigger.net/web-security/all-labs#cross-site-request-forgery-csrf

CORS跨域资源读取漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/corshttps://portswigger.net/web-security/all-labs#cross-origin-resource-sharing-cors

点击劫持

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/clickjackinghttps://portswigger.net/web-security/all-labs#clickjacking

Web LLM attacks大模型攻击

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/llm-attackshttps://portswigger.net/web-security/all-labs#web-llm-attackshttps://mp.weixin.qq.com/mp/appmsgalbum?__biz=Mzg2NzY0MzM3Ng==&action=getalbum&album_id=3312413957536366597&scene=173&subscene=227&sessionid=1713083860&enterid=1713083865&from_msgid=2247483997&from_itemidx=1&count=3&nolastread=1#wechat_redirect

Host Header Attack host头攻击漏洞

【漏洞总结】常见漏洞总结归纳自学路线图

【漏洞总结】常见漏洞总结归纳自学路线图

https://portswigger.net/web-security/host-headerhttps://portswigger.net/web-security/all-labs#http-host-header-attacks

原文始发于微信公众号(利刃信安):【漏洞总结】常见漏洞总结归纳自学路线图

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2024年4月14日20:51:48
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   【漏洞总结】常见漏洞总结归纳自学路线图http://cn-sec.com/archives/2657002.html

发表评论

匿名网友 填写信息