PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
File Explorer
Download Latest Version (.zip)- main.html
- projectdiscovery.png
- serpapi.png
- talordata.png
- vaadata.png
- check-markdown.yml
- mkdocs-build.yml
- .markdownlint.json
- banner.png
- FUNDING.yml
- hopla_config.json
- BOOKS.md
- TWITTER.md
- YOUTUBE.md
- README.md
- mfa-bypass.md
- README.md
- MachineKeys.txt
- IIS-Machine-Keys.md
- README.md
- README.md
- README.md
- README.md
- README.md
- command-execution-unix.txt
- command_exec.txt
- README.md
- README.md
- crlfinjection.txt
- README.md
- CSRF-CheatSheet.png
- README.md
- README.md
- README.md
- Log4Shell.md
- README.md
- README.md
- README.md
- deep_traversal.txt
- directory_traversal.txt
- dotdotpwn.txt
- traversals-8-deep-exotic-encoding.txt
- README.md
- README.md
- README.md
- README.md
- README.md
- LFI2RCE.py
- phpinfolfi.py
- uploadlfi.py
- BSD-files.txt
- dot-slash-PathTraversal_and_LFI_pairing.txt
- JHADDIX_LFI.txt
- LFI-FD-check.txt
- LFI-WindowsFileCheck.txt
- Linux-files.txt
- List_Of_File_To_Include.txt
- List_Of_File_To_Include_NullByteAdded.txt
- Mac-files.txt
- php-filter-iconv.txt
- simple-check.txt
- Traversal.txt
- Web-files.txt
- Windows-files.txt
- LFI-to-RCE.md
- README.md
- Wrappers.md
- README.md
- htb-help.png
- README.md
- iframe.html
- window_location_js.html
- README.md
- README.md
- README.md
- node-serialize.js
- ruby-serialize.yaml
- Ruby_universal_gadget_generate_verify.rb
- NETNativeFormatters.png
- DotNET.md
- Java.md
- Node.md
- PHP.md
- Python.md
- README.md
- Ruby.md
- idor.png
- README.md
- springboot_actuator.txt
- README.md
- README.md
- github-dorks.txt
- Bazaar.md
- Git.md
- Mercurial.md
- README.md
- Subversion.md
- README.md
- README.md
- README.md
- LDAP_attributes.txt
- LDAP_FUZZ.txt
- LDAP_FUZZ_SMALL.txt
- README.md
- README.md
- Active Directory Attack.md
- Bind Shell Cheatsheet.md
- Cloud - AWS Pentest.md
- Cloud - Azure Pentest.md
- Cobalt Strike - Cheatsheet.md
- Container - Docker Pentest.md
- Container - Kubernetes Pentest.md
- Escape Breakout.md
- Hash Cracking.md
- HTML Smuggling.md
- Initial Access.md
- Linux - Evasion.md
- Linux - Persistence.md
- Linux - Privilege Escalation.md
- Metasploit - Cheatsheet.md
- Methodology and enumeration.md
- MSSQL Server - Cheatsheet.md
- Network Discovery.md
- Network Pivoting Techniques.md
- Office - Attacks.md
- Powershell - Cheatsheet.md
- Reverse Shell Cheatsheet.md
- Source Code Management.md
- Vulnerability Reports.md
- Web Attack Surface.md
- Windows - AMSI Bypass.md
- Windows - Defenses.md
- Windows - Download and Execute.md
- Windows - DPAPI.md
- Windows - Mimikatz.md
- Windows - Persistence.md
- Windows - Privilege Escalation.md
- Windows - Using credentials.md
- MongoDB.txt
- NoSQL.txt
- README.md
- README.md
- Open-Redirect-payloads.txt
- open_redirect_wordlist.txt
- openredirects.txt
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- SAML-xml-flaw.png
- XSLT1.jpg
- README.md
- ssi_esi.txt
- README.md
- ip.py
- SSRF_expect.svg
- ssrf_ffmpeg.avi
- ssrf_iframe.svg
- ssrf_svg_css_import.svg
- ssrf_svg_css_link.svg
- ssrf_svg_css_xmlstylesheet.svg
- ssrf_svg_image.svg
- ssrf_svg_use.svg
- SSRF_url.svg
- aws-cli.jpg
- Parser and Curl less than 7.54.png
- SSRF_Parser.png
- SSRF_PDF.png
- SSRF_stream.png
- WeakParser.jpg
- README.md
- SSRF-Advanced-Exploitation.md
- SSRF-Cloud-Instances.md
- serverside.png
- technique_Boolean-Based.png
- technique_Error-Based.png
- technique_Polyglot-Based.png
- technique_Rendered.png
- technique_Time-Based.png
- template-library.jpg
- ssti.fuzz
- ASP.md
- Elixir.md
- Java.md
- JavaScript.md
- PHP.md
- Python.md
- README.md
- Ruby.md
- PostgreSQL_cmd_exec.png
- Unicode_SQL_injection.png
- wildcard_underscore.jpg
- Auth_Bypass.txt
- Auth_Bypass2.txt
- FUZZDB_MSSQL-WHERE_Time.txt
- FUZZDB_MSSQL.txt
- FUZZDB_MSSQL_Enumeration.txt
- FUZZDB_MySQL-WHERE_Time.txt
- FUZZDB_MYSQL.txt
- FUZZDB_MySQL_ReadLocalFiles.txt
- FUZZDB_Oracle.txt
- FUZZDB_Postgres_Enumeration.txt
- Generic_ErrorBased.txt
- Generic_Fuzz.txt
- Generic_TimeBased.txt
- Generic_UnionSelect.txt
- payloads-sql-blind-MSSQL-INSERT
- payloads-sql-blind-MSSQL-WHERE
- payloads-sql-blind-MySQL-INSERT
- payloads-sql-blind-MySQL-ORDER_BY
- payloads-sql-blind-MySQL-WHERE
- SQL-Injection
- SQLi_Polyglots.txt
- BigQuery Injection.md
- Cassandra Injection.md
- DB2 Injection.md
- MSSQL Injection.md
- MySQL Injection.md
- OracleSQL Injection.md
- PostgreSQL Injection.md
- README.md
- SQLite Injection.md
- SQLmap.md
- README.md
- table_representing_behavior_of_PHP_with_loose_type_comparisons.png
- README.md
- .htaccess
- .htaccess_phpinfo
- .htaccess_rce_files
- .htaccess_shell
- README.md
- web.config
- python-admin-__init__.py.zip
- python-conf-__init__.py.zip
- python-config-__init__.py.zip
- python-controllers-__init__.py.zip
- python-generate-init.py
- python-login-__init__.py.zip
- python-models-__init__.py.zip
- python-modules-__init__.py.zip
- python-scripts-__init__.py.zip
- python-settings-__init__.py.zip
- python-tests-__init__.py.zip
- python-urls-__init__.py.zip
- python-utils-__init__.py.zip
- python-view-__init__.py.zip
- uwsgi.ini
- gen_avi_bypass.py
- gen_xbin_avi.py
- read_passwd.avi
- read_passwd_bypass.mp4
- read_shadow.avi
- read_shadow_bypass.mp4
- etc_passwd.zip
- generate.sh
- passwd
- eicar.txt
- extensions.lst
- shell.asa
- shell.ashx
- shell.asmx
- shell.asp
- shell.aspx
- shell.cer
- shell.soap
- shell.xamlx
- xss.html
- extensions.lst
- php-script-tag.php
- phpinfo.jpg.php
- phpinfo.phar
- phpinfo.php
- phpinfo.php3
- phpinfo.php4
- phpinfo.php5
- phpinfo.php7
- phpinfo.php8
- phpinfo.phpt
- phpinfo.pht
- phpinfo.phtml
- shell.gif^shell.php
- shell.jpeg.php
- shell.jpg.php
- shell.jpg^shell.php
- shell.pgif
- shell.phar
- shell.php
- shell.php3
- shell.php4
- shell.php5
- shell.php7
- shell.phpt
- shell.pht
- shell.phtml
- shell.png.php
- shell.png^shell.php
- tiny.php
- file-upload-mindmap.png
- JettyShell.xml
- createBulletproofJPG.py
- createCompressedPNG_110x110.php
- createGIFwithGlobalColorTable.php
- createPNGwithPLTE.php
- GIF_exploit.gif
- JPG_exploit-55.jpg
- PNG_110x110_resize_bypass_use_LFI.png
- PNG_32x32_resize_bypass_use_LFI.png
- convert_local_etc_passwd.svg
- convert_local_etc_passwd_html.svg
- ghostscript_rce_curl.jpg
- imagemagick_CVE-2022-44268_convert_etc_passwd.png
- imagemagick_ghostscript_cmd_exec.pdf
- imagemagik_ghostscript_reverse_shell.jpg
- imagetragik1_payload_imageover_file_exfiltration_pangu_wrapper.jpg
- imagetragik1_payload_imageover_file_exfiltration_text_wrapper.jpg
- imagetragik1_payload_imageover_reverse_shell_devtcp.jpg
- imagetragik1_payload_imageover_reverse_shell_netcat_fifo.png
- imagetragik1_payload_imageover_wget.gif
- imagetragik1_payload_url_bind_shell_nc.mvg
- imagetragik1_payload_url_curl.png
- imagetragik1_payload_url_portscan.jpg
- imagetragik1_payload_url_remote_connection.mvg
- imagetragik1_payload_url_reverse_shell_bash.mvg
- imagetragik1_payload_url_touch.jpg
- imagetragik1_payload_xml_reverse_shell_nctraditional.xml
- imagetragik1_payload_xml_reverse_shell_netcat_encoded.xml
- imagetragik2_burpcollaborator_passwd.jpg
- imagetragik2_centos_id.jpg
- imagetragik2_ubuntu_id.jpg
- imagetragik2_ubuntu_shell.jpg
- imagetragik2_ubuntu_shell2.jpg
- Build_image_to_LFI.py
- CVE-2021-22204_exiftool_echo.jpg
- CVE-2021-22204_exiftool_revshell.jpg
- PHP_exif_phpinfo.jpg
- PHP_exif_system.gif
- PHP_exif_system.jpg
- PHP_exif_system.png
- exec.shtml
- include.shtml
- index.stm
- README.md
- README.md
- wcd.jpg
- param_miner_lowercase_headers.txt
- README.md
- ws-harness.py
- sqlmap.png
- websocket-harness-start.png
- WebsocketHarness.jpg
- README.md
- README.md
- README.md
- enum-system-version-vendor.xsl
- file-write.xsl
- rce-dotnet-2.xsl
- rce-dotnet.xsl
- rce-java-1.xsl
- rce-java-2.xsl
- rce-php-assert.xsl
- rce-php-file-create.xsl
- rce-php-file-read.xsl
- rce-php-meterpreter.xsl
- rce-php-scandir.xsl
- read-and-ssrf.xsl
- system-properties.xml
- system-properties.xsl
- xxe.xsl
- README.md
- InsecureFlashFile.swf
- JupyterNotebookXSS.ipynb
- mouseover-xss-ecs.jpeg
- onclick-xss-ecs.jpeg
- payload_in_all_known_exif_corrupted.jpg
- payload_in_all_known_exif_corrupted.png
- payload_in_all_known_metadata.jpg
- payload_in_all_known_metadata.png
- payload_text_xss.png
- SVG_XSS1.svg
- SVG_XSS2.svg
- SVG_XSS3.svg
- SVG_XSS_green_triangle.svg
- SVG_XSS_nested_img_xlink.svg
- SVG_XSS_nested_svg.svg
- SVG_XSS_nested_use_xlink.svg
- SVG_XSS_red_lightning.svg
- SWF_XSS.swf
- xml.xsd
- xss.cer
- xss.dtd
- xss.htm
- xss.html.demo
- xss.hxt
- xss.mno
- xss.rdf
- xss.svgz
- xss.url.url
- xss.vml
- xss.wsdl
- xss.xht
- xss.xhtml
- xss.xml
- xss.xsd
- xss.xsf
- xss.xsl
- xss.xslt
- xss_comment_exif_metadata_double_quote.png
- xss_comment_exif_metadata_single_quote.png
- DwrkbH1VAAErOI2.jpg
- 0xcela_event_handlers.txt
- BRUTELOGIC-XSS-JS.txt
- BRUTELOGIC-XSS-STRINGS.txt
- IntrudersXSS.txt
- JHADDIX_XSS.txt
- jsonp_endpoint.txt
- MarioXSSVectors.txt
- port_swigger_xss_cheatsheet_event_handlers.txt
- RSNAKE_XSS.txt
- xss_alert.txt
- xss_alert_identifiable.txt
- xss_payloads_quick.txt
- XSS_Polyglots.txt
- xss_swf_fuzz.txt
- XSSDetection.txt
- 1 - XSS Filter Bypass.md
- 2 - XSS Polyglot.md
- 3 - XSS Common WAF Bypass.md
- 4 - CSP Bypass.md
- 5 - XSS in Angular.md
- README.md
- Classic XXE - etc passwd.xml
- Classic XXE B64 Encoded.xml
- Classic XXE.xml
- Deny Of Service - Billion Laugh Attack
- XXE OOB Attack (Yunusov, 2013).xml
- XXE PHP Wrapper.xml
- xml-attacks.txt
- XXE_Fuzzing.txt
- README.md
- README.md
- .gitignore
- .pre-commit-config.yaml
- CONTRIBUTING.md
- custom.css
- DISCLAIMER.md
- LICENSE
- mkdocs.yml
- README.md
// repository documentation
Was this content helpful?
(0 ratings)
