Skip to content

Instantly share code, notes, and snippets.

View ttonys's full-sized avatar
🎯
Focusing

tonys ttonys

🎯
Focusing
  • earth
  • earth
View GitHub Profile
.php
.html
.txt
.htm
.aspx
.asp
.js
.css
.pgsql.txt
.mysql.txt
@ttonys
ttonys / HttpMethods
Last active January 2, 2023 05:43
http请求方法, waf绕过测试
ACL
BASELINE-CONTROL
BIND
CHECKIN
CHECKOUT
COPY
LABEL
LINK
LOCK
MERGE
dest
redirect
uri
path
continue
url
window
next
data
reference
@ttonys
ttonys / open_redirect_keys
Created July 10, 2022 02:08
site:*example.com inurl:redirect
page
url
ret
r2
img
u
return
r
URL
next
@ttonys
ttonys / extensions.txt
Created May 5, 2022 15:22
可能泄露的拓展名
%-
%.
%.1
%.2
%.3
%.bac
%.backup
%.bak
%.cache
%.conf
@ttonys
ttonys / sensitive-fuzz
Last active February 21, 2023 02:39
敏感文件fuzz
!.gitignore
!.htaccess
!.htpasswd
%20../
%2e%2e//google.com
%2e%2e;test/
%3f/
%C0%AE%C0%AE%C0%AF
%ff/
..;/
@ttonys
ttonys / Generic keys
Last active May 5, 2022 15:23 — forked from h4x0r-dz/Generic keys
burp正则过滤security-key
(?i)((access_key|access_token|admin_pass|admin_user|algolia_admin_key|algolia_api_key|alias_pass|alicloud_access_key|amazon_secret_access_key|amazonaws|ansible_vault_password|aos_key|api_key|api_key_secret|api_key_sid|api_secret|api.googlemaps AIza|apidocs|apikey|apiSecret|app_debug|app_id|app_key|app_log_level|app_secret|appkey|appkeysecret|application_key|appsecret|appspot|auth_token|authorizationToken|authsecret|aws_access|aws_access_key_id|aws_bucket|aws_key|aws_secret|aws_secret_key|aws_token|AWSSecretKey|b2_app_key|bashrc password|bintray_apikey|bintray_gpg_password|bintray_key|bintraykey|bluemix_api_key|bluemix_pass|browserstack_access_key|bucket_password|bucketeer_aws_access_key_id|bucketeer_aws_secret_access_key|built_branch_deploy_key|bx_password|cache_driver|cache_s3_secret_key|cattle_access_key|cattle_secret_key|certificate_password|ci_deploy_password|client_secret|client_zpk_secret_key|clojars_password|cloud_api_key|cloud_watch_aws_access_key|cloudant_password|cloudflare_api_key|cloudflare_auth_k
@ttonys
ttonys / headers.txt
Last active January 2, 2023 05:42 — forked from iustin24/headers.txt
http请求头,用于缓存中毒测试
\
aacomtr_Gzip
aacomtr_Gzip_g
AA-Gzip
AB-API-Account-Access-Token
AB-API-Auth-Name
AB-API-Auth-Password
AB-API-Auth-Token-Facebook
AB-API-Community-ID
AB-API-Company-ID