swisskyrepo/ payloadsallthethings
View on GitHubA list of useful payloads and bypass for Web Application Security and Pentest/CTF
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques!
You can also contribute with a :beers: IRL, or using the sponsor button.
An alternative display version is available at PayloadsAllTheThingsWeb.
Every section contains the following files, you can use the _template_vuln folder to create a new chapter:
You might also like the other projects from the AllTheThings family :
You want more? Check the Books and YouTube channel selections.
Be sure to read CONTRIBUTING.md
Thanks again for your contribution! :heart:
This project is proudly sponsored by these companies.
| Logo | Description | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | | | SerpApi is a real time API to access Google search results. It solves the issues of having to rent proxies, solving captchas, and JSON parsing. | | | ProjectDiscovery - Detect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives. | | | VAADATA - Ethical Hacking Services |
No comments yet. Set the tone — say what you would want to know.