• Stars
    star
    488
  • Rank 89,880 (Top 2 %)
  • Language
    PHP
  • Created almost 3 years ago
  • Updated over 2 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

開源的正體中文 Web Hacking 學習資源 - 程式安全 2021 Fall

How to Hack Websites

Videos

Topics

初章

Full slide

  • Web & Web security introduction [slide]
  • Access control & Bussiness logic
  • Recon & Information leak [slide]
  • Insecure Upload / Path traversal / LFI [slide]
  • Basic injection [slide]
    • Code injection
    • Command injection
    • SQL injection: Basic

續章

Full slide

  • SQL injection: Advanced
    • Union-based
    • Boolean-based
    • Other
  • Server-side request forgery (SSRF)
  • Insecure deserialization
    • Intro
    • Pickle

終章

Full slide

  • Insecure deserialization [slide]
    • PHP
    • POP Chain
    • Misc (Java, .NET etc.)
  • Frontend security: Basic [slide]
    • Same-origin policy
    • CSRF
    • XSS
  • Frontend security: Content Security Policy (CSP) [slide]
  • Frontend security: Advanced
  • Advanced injection
    • NoSQL injection
    • Server-side template injection (SSTI)
  • Misc
    • JavaScript prototype pollution [slide]
    • XXE

Labs

題目之後的 數字 代表的是 docker 對外通訊埠編號

  • Basic
    • Cat Shop 8100
  • SQL injection
    • Login me: Login bypass 8200
    • Login me again: UNION-based SQL injection 8201
  • Command injection
    • DNS tool 8300
    • DNS tool: WAF edition 8301
  • LFI
    • Meow site: Basic LFI 8400
    • HakkaMD: LFI to RCE 8401
  • SSRF
    • Web Preview Service: Use gopher:// to forge a request 8500
    • SSRFrog: Bypass blacklist 8501
  • Deserialization
    • Pickle 8600
    • Cat: Basic PHP unserialize 8601
    • Magic cat: POP chain 8602
  • SSTI
    • Jinja2 SSTI 8700
  • Frontend
    • XSS 8800

Homework

  • Imgura: Information Leak / Upload / LFI
  • DVD Screensaver: Path traversal / SQL injection / Signed Cookie
  • Profile Card: XSS / CSRF / CSP Bypass
  • Double SSTI: SSTI
  • Log me in: FINAL: SQL injection / Information Leak

More Repositories

1

PHPFuck

PHPFuck: ([+.^]) / Using only 7 different characters to write and execute php.
Python
386
star
2

Pickora

A toy compiler that can convert Python scripts 🐍 to pickle bytecode 🥒
Python
110
star
3

My-CTF-Challenges

🏴 🏴 🏴
Python
99
star
4

domain-obfuscator

Make your domain weird, but still works :/
JavaScript
81
star
5

FormosanLanguages.h

讓您輕鬆用原住民語寫程式!
C
58
star
6

emina-one

anime1.me 開站了!但本 app 還沒修好 / 一個 Anime1.me 的非官方 app (ˊ・ω・ˋ)
JavaScript
36
star
7

DOM-Clobber3r

Generate DOM clobbering attack vectors for you.
HTML
29
star
8

awesome-web-security-paper

📝 Web security related academic papers collection (just for myself).
20
star
9

NYCU-Advanced-UNIX-Programming-2021

大家快來抄作業 | 陽明交大高等 UNIX 程式設計
C++
20
star
10

NCTUwU

交大選課模擬器 / NCTU course selection simulator.
JavaScript
18
star
11

py-sandbox-escape

Jailbreaker!!!
Python
16
star
12

AnimateGamerPlus

方便使用巴哈動畫瘋的輔助瀏覽器外掛。
JavaScript
14
star
13

Taiwan-Tech-GPA-Saviour

拯救你ㄉGPA / 快速查詢台科歷年課程的成績分布
HTML
14
star
14

NTUSTapp

一個屬於台科人的 App。
JavaScript
13
star
15

genius-url

A URL builder for genius :D
Python
12
star
16

buddymeter-cheater

buddymeter.com 外掛。讓你能手動定義Buddy meter的分數,並能自動答對所有題目。
JavaScript
9
star
17

Imgura-Final-EOF2022

A&D challenge for AIS3 EOF CTF 2022 Final.
PHP
7
star
18

CTFd-Attack-and-Defense-Plugin

HTML
7
star
19

2015-winter-club-training

資安Demo@2015電資寒訓冬資戀
PHP
7
star
20

wikiart-downloader

Automatically download all the art works in WikiAart. / 自動化下載 www.wikiart.org 的所有畫作。
Python
6
star
21

taiwan-tech-empty-classroom

協助台科同學查詢目前的空教室。
HTML
5
star
22

taiwan-tech-scripts

給台科學生用的實用腳本 / Useful scripts for Taiwan Tech students.
HTML
5
star
23

107-SE-HW1

軟體工程作業 - phonebook
Java
4
star
24

CYSH-Web

嘉中簡化版校網(由於校網更新,現今部分功能失效)
JavaScript
3
star
25

me

About me.
HTML
2
star
26

course.taiwan-te.ch

Python
2
star
27

map2src

Convert source map to original JavaScript.
Python
2
star
28

crosslink-hacking

COOL!
1
star
29

Ptt-X

讓你直接在 ptt.cc 網頁上登入帳號,輕鬆瀏覽 Ptt
JavaScript
1
star
30

NTUST-CourseHelper

一個協助台科人選課的小工具。
JavaScript
1
star
31

Lab-of-Computer-Programming-Final

程式設計實習期末考題庫 個人解法
C++
1
star