Web Cheat Sheet
Server version
- Check if are known vulnerabilities
- Get versions, application, services, technologies etc.
- Source code review
- HTTPS -->certificate --> usernames, mail, subdomains
- Web Application Firewall (WAF)whatweb -a 1 $URL
whatweb -a 3 $URL
whatweb -a 4 $URL
nuclei -ut && nuclei -target http://$IP
nikto --host $URL -C all -o recon/nikto.txt Content discovery
Do a recursive search (not every tool do this automatically)
See default pages
Use different wordlists
Check every file you found (php,bak, html, py, txt, etc.)
Check for WAFCommon Vulns
IDOR
SQLinjections
File upload
XML External Entity (XXE) and XSLT
Local File Inclusion
PHP Vulns
Last updated