Pentesting notes
CtrlK
  • 🏠/home/kabaneridev/.pt-notes
  • πŸ†Certification Preparation
    • βœ…CPTS - Completed
    • πŸ“˜CWEE Preparation
      • Injection Attacks
        • Introduction
        • XPath Injection
        • LDAP Injection
        • HTML Injection in PDF Generators
        • NoSQL Injection
      • Attacking Authentication Mechanisms
      • Advanced XSS and CSRF Exploitation
      • [HTTPS/TLS Attacks]
    • βœ…PJPT - Completed
  • πŸ”§Core Knowledge Areas
    • πŸ”Information Gathering
    • 🐧Linux Privilege Escalation
    • πŸͺŸWindows Privilege Escalation
    • πŸ› οΈTools & Utilities
Powered by GitBook
On this page
  1. πŸ†Certification Preparation
  2. πŸ“˜CWEE Preparation

Injection Attacks

This module covers less common but impactful injection vulnerabilities beyond the usual SQLi, Command Injection, and XSS.

Table of Contents

  • Introduction to Injection Attacks

  • XPath Injection

    • Introduction

    • Authentication Bypass

    • Data Exfiltration

    • Advanced Data Exfiltration

    • Blind Exploitation

    • Prevention & Tools

  • LDAP Injection

    • Introduction

    • Authentication Bypass

    • Data Exfiltration & Blind Exploitation

    • Prevention

  • HTML Injection in PDF Generators

    • Introduction

    • Exploitation

    • Prevention

  • NoSQL Injection

    • Introduction

    • Bypassing Authentication

    • In-Band Data Extraction

    • Blind Data Extraction

    • Automating Blind Extraction

    • Server-Side JavaScript Injection

  • Skills Assessment (TBD)

PreviousCWEE PreparationNextIntroduction

Last updated 9 days ago