Web Exploitation Last Resorts
Use these techniques if classic techniques do not work.
Getting usernames & passwords from webpages -
Looking for other valid subdomains
wfuzz -u https://streamio.htb -H "Host: FUZZ.streamio.htb" -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt --hh 315Looking for valid query parameters
wfuzz -u https://streamio.htb/admin/?FUZZ= -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -H "Cookie: PHPSESSID=jtde06u71uq4t7pvs59b8iis1o" --hh 1678
#Add cookie only if it is needed in that scenarioGetting metadata from documents -
exiftool <filename> #Run this on docx, pdf, etc.binwalk -e <filename>Creating wordlist with different tools -
Using cewl -
Using date (for brute-forcing dates) -
Gathering information from SSL Certificate -
Exploiting SSRF -
Last updated