Coder Social home page Coder Social logo

fuzz.txt's Introduction

fuzz.txt

There's Nothing so Permanent as Temporary

Any ideas?

fuzz.txt's People

Contributors

0x4380 avatar 0xn3va avatar act1on3 avatar alexlauerman avatar anio avatar atastycookie avatar attackercan avatar belove avatar bo0om avatar coreb1t avatar devpwn avatar himanshudas avatar imangazaliev avatar lebik avatar muellermartin avatar ngo avatar pansa avatar raiden-dev avatar rodnt avatar sab0tag3d avatar vladimir-ivanov-git avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

fuzz.txt's Issues

Add /debug/routes and /routes

Если загуглить как посмотреть все роуты ASP.NET, много рекомендаций в первой выдаче - создать новый роут /debug/routes или /routes, который их будет перечислять. Возможно, такие же "рекомендации" есть и для других фреймворков.

https://www.meziantou.net/list-all-routes-in-an-asp-net-core-application.htm
https://stackoverflow.com/questions/41908957/get-all-registered-routes-in-asp-net-core

Добавить:

debug/routes
routes

Two entries were detected by akamai

This was reported in danielmiessler/SecLists#943

Two entries in the list was caught by akamai waf

remote/fgt_lang?lang=/../../../../////////////////////////bin/sslvpnd
remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession

This is meant to be an informative notice so no immediate actions need to be taken.

.dmp and .sav

.dmp and .sav

.dmp is sometimes generated by windows unattended upgrade/migration scripts/tools

.sav commom for doze nimdas to name their +1 old backup of registry hives

.sys while you're at it.. pagefile(s)
.out

Add checks for Spring Boot Actuator

Consider adding checks for Spring Boot Actuator, which if openly accessible in production can be leveraged to run trace, dump memory, manipulate environment variables, etc. [1][2][3]

/actuator
/actuator/auditevents
/actuator/autoconfig
/actuator/beans
/actuator/caches
/actuator/conditions
/actuator/configprops
/actuator/env
/actuator/flyway
/actuator/health
/actuator/httptrace
/actuator/info
/actuator/integrationgraph
/actuator/loggers
/actuator/liquibase
/actuator/metrics
/actuator/mappings
/actuator/scheduledtasks
/actuator/sessions
/actuator/shutdown
/actuator/threaddump
/actuator/heapdump
/actuator/jolokia
/actuator/logfile
/actuator/prometheus

g

g

images

Any image file could be dangerous; people will click on to open.

PDFs are in themselves dangerous, esp if they execute scripts inside.

Suggest removing logout

Not sure if you want a PR for this, but I suggest removing potential logout URLs. They are a lot more problematic than useful in my opinion, and don't fit this targeted list well.

logout
logout.asp
logout/

Add fuzz.txt

Add fuzz.txt to the list. How is it dangerous? SkriptKiddies could use this to find out how the listed files are dangerous, and use them.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.