offsecnotes
Star
offsecnotes
by frankheat
Android
Vulnerabilities
Bypass Binary Protections
Security Misconfiguration
Insecure Data Storage
Intent Attack Surface
Deep link
Task Hijacking
Tapjacking
Exploiting exported Activities
Reverse Engineering
APK Building
Reversing
Analyze native libraries
Frida
Installation & Commands
frida-trace
Working with java code
Working with native code
Network Interception
ADB
Framework
Debug application code
Web
Vulnerabilities
API Security Testing
Authentication
Broken Access Control (BAC)
Business logic vulnerabilities
Clickjacking
CORS
CSRF
File upload vulnerabilities
GraphQL API
Host header injection
HTTP request smuggling
Information disclosure
Insecure deserialization
JWT
NoSQL injection
OAuth 2.0
OS command injection
Path traversal
Prototype pollution
Race conditions
SQL injection
SSRF
SSTI
Web cache deception
Web cache poisoning
Web LLM
WebSockets
XSS
XXE
Web security
General Obfuscation
Javascript & Obfuscation
Methods & Headers
Web cache
OAuth
SOP, CORS, Pre-flight
Automation
Network
Information Gathering
Network Services Exploitation
Post-Exploitation & Commands
Privilege Escalation
Misc
Password Cracking
Burp Suite
AV Evasion
CTF Methodology
References