Pentesting notes
search
⌘Ctrlk
Pentesting notes
  • 🏠/home/kabaneridev/.pt-notes
  • πŸ†Certification Preparation
    • βœ…CPTS - Completed
    • πŸ“˜CWEE Preparation
      • Injection Attacks
      • Attacking Authentication Mechanisms
      • Advanced XSS and CSRF Exploitation
      • Abusing HTTP Misconfigurations
        • [Host Header Attacks]
        • [Web Cache Poisoning]
        • [Session Puzzling]
          • Introduction
          • Weak Session IDs
          • Common Session Variables - Auth Bypass
          • Common Session Variables - Account Takeover
          • Premature Session Population
          • Prevention
          • Skills Assessment
        • Skills Assessment
      • HTTP Attacks
      • HTTPS/TLS Attacks
      • Blind SQL Injection
      • Whitebox Pentesting
      • Modern Web Exploitation
      • [Deserialization Attacks]
    • βœ…PJPT - Completed
  • πŸ”§Core Knowledge Areas
    • πŸ”Information Gathering
    • 🐧Linux Privilege Escalation
    • πŸͺŸWindows Privilege Escalation
    • πŸ› οΈTools & Utilities
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. πŸ†Certification Preparationchevron-right
  2. πŸ“˜CWEE Preparationchevron-right
  3. Abusing HTTP Misconfigurations

[Session Puzzling]

Introductionchevron-rightWeak Session IDschevron-rightCommon Session Variables - Auth Bypasschevron-rightCommon Session Variables - Account Takeoverchevron-rightPremature Session Populationchevron-rightPreventionchevron-rightSkills Assessmentchevron-right
PreviousTools & Preventionchevron-leftNextIntroductionchevron-right

Last updated 1 month ago