Skip to main content

Image Migration Note

The following pages had image references in GitBook content. Dummy SVG placeholders were added under each page assets/ folder, and these should be replaced with your real images.

CVE-2016-10033: PHPMailer RCE

Page: notes/Web Hacking/code-execution/cve-2016-10033-phpmailer-rce.md

  • Original: ../../.gitbook/assets/image (16).png
  • Placeholder: code-execution/assets/todo-image-01.svg

CVE-2018-11235: Git Submodule RCE

Page: notes/Web Hacking/code-execution/cve-2018-11235-git-submodule-rce.md

  • Original: ../../.gitbook/assets/image (2) (1).png
  • Placeholder: code-execution/assets/todo-image-01.svg

LaTeX --shell-escape Command Execution

Page: notes/Web Hacking/code-execution/latex-shell-escape-command-execution.md

  • Original: ../../.gitbook/assets/image (28).png
  • Placeholder: code-execution/assets/todo-image-01.svg

Cross Site Request Forgery (CSRF)

Page: notes/Web Hacking/cross-site-request-forgery-csrf/index.md

  • Original: ../../.gitbook/assets/image (1) (1) (1) (1) (1) (1).png
  • Placeholder: cross-site-request-forgery-csrf/assets/todo-image-01.svg
  • Original: https://vulnerable-website.com/email/change?email=pwned@evil-user.net
  • Placeholder: cross-site-request-forgery-csrf/assets/todo-image-03.svg

XSS Include (XSSi)

Page: notes/Web Hacking/cross-site-scripting-xss/xss-include-xssi.md

  • Original: ../../.gitbook/assets/image (1) (1) (1) (1) (1) (1) (1).png
  • Placeholder: cross-site-scripting-xss/assets/todo-image-01.svg

CBC-MAC I

Page: notes/Web Hacking/cryptographic-failure/cbc-mac-i.md

  • Original: ../../.gitbook/assets/image (2) (1) (1).png
  • Placeholder: cryptographic-failure/assets/todo-image-01.svg
  • Original: ../../.gitbook/assets/image (2) (1) (1) (1).png
  • Placeholder: cryptographic-failure/assets/todo-image-02.svg
  • Original: ../../.gitbook/assets/image (3).png
  • Placeholder: cryptographic-failure/assets/todo-image-03.svg
  • Original: ../../.gitbook/assets/image (24).png
  • Placeholder: cryptographic-failure/assets/todo-image-04.svg

Cipher Block Chaining (CBC)

Page: notes/Web Hacking/cryptographic-failure/cipher-block-chaining-cbc.md

  • Original: ../../.gitbook/assets/image (18).png
  • Placeholder: cryptographic-failure/assets/todo-image-01.svg
  • Original: ../../.gitbook/assets/image (19).png
  • Placeholder: cryptographic-failure/assets/todo-image-02.svg

Electronic Code Book (ECB)

Page: notes/Web Hacking/cryptographic-failure/electronic-code-book-ecb.md

  • Original: ../../.gitbook/assets/image (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png
  • Placeholder: cryptographic-failure/assets/todo-image-01.svg

GCM Nonce Reuse

Page: notes/Web Hacking/cryptographic-failure/gcm-nonce-reuse.md

  • Original: ../../.gitbook/assets/image (29).png
  • Placeholder: cryptographic-failure/assets/todo-image-01.svg
  • Original: ../../.gitbook/assets/image (30).png
  • Placeholder: cryptographic-failure/assets/todo-image-02.svg

Length Extension Attack

Page: notes/Web Hacking/file-inclusion/length-extension-attack.md

  • Original: ../../.gitbook/assets/image (1) (1).png
  • Placeholder: file-inclusion/assets/todo-image-01.svg

File Upload

Page: notes/Web Hacking/file-upload/index.md

  • Original: ../../.gitbook/assets/image (10).png
  • Placeholder: file-upload/assets/todo-image-01.svg

CVE-2015-3224: Rails RCE (Web Console)

Page: notes/Web Hacking/framework-specific/ruby-on-rails/cve-2015-3224-rails-rce-web-console.md

  • Original: ../../../.gitbook/assets/image (1) (1) (1).png
  • Placeholder: framework-specific/ruby-on-rails/assets/todo-image-01.svg

CVE-2019-5418: Ruby on Rails Accept Header File Disclosure to RCE

Page: notes/Web Hacking/framework-specific/ruby-on-rails/cve-2019-5418-ruby-on-rails-accept-header-file-disclosure-to-rce.md

  • Original: ../../../.gitbook/assets/image (1).png
  • Placeholder: framework-specific/ruby-on-rails/assets/todo-image-01.svg
  • Original: ../../../.gitbook/assets/image.png
  • Placeholder: framework-specific/ruby-on-rails/assets/todo-image-02.svg

Insecure Deserialization

Page: notes/Web Hacking/insecure-deserialization/index.md

  • Original: ../../.gitbook/assets/image (13).png
  • Placeholder: insecure-deserialization/assets/todo-image-01.svg

Xstream Vulnerability in Jenkins (CVE-2016-0792)

Page: notes/Web Hacking/insecure-deserialization/xstream-vulnerability-in-jenkins-cve-2016-0792.md

  • Original: ../../.gitbook/assets/image (15).png
  • Placeholder: insecure-deserialization/assets/todo-image-01.svg
  • Original: ../../.gitbook/assets/image (14).png
  • Placeholder: insecure-deserialization/assets/todo-image-02.svg

JWT Attacks

Page: notes/Web Hacking/jwt-attacks/index.md

  • Original: ../../.gitbook/assets/image (2) (1) (1) (1) (1) (1).png
  • Placeholder: jwt-attacks/assets/todo-image-01.svg
  • Original: ../../.gitbook/assets/image (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png
  • Placeholder: jwt-attacks/assets/todo-image-02.svg
  • Original: ../../.gitbook/assets/image (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png
  • Placeholder: jwt-attacks/assets/todo-image-03.svg
  • Original: ../../.gitbook/assets/image (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png
  • Placeholder: jwt-attacks/assets/todo-image-04.svg
  • Original: ../../.gitbook/assets/image (21).png
  • Placeholder: jwt-attacks/assets/todo-image-05.svg
  • Original: ../../.gitbook/assets/image (22).png
  • Placeholder: jwt-attacks/assets/todo-image-06.svg
  • Original: ../../.gitbook/assets/image (4).png
  • Placeholder: jwt-attacks/assets/todo-image-07.svg

Embedded JWK Trust Bypass (node-jose)

Page: notes/Web Hacking/jwt-attacks/embedded-jwk-trust-bypass-node-jose.md

  • Original: ../../.gitbook/assets/image (1) (1) (1) (1) (1) (1) (1) (1).png
  • Placeholder: jwt-attacks/assets/todo-image-01.svg
  • Original: ../../.gitbook/assets/image (1) (1) (1) (1) (1) (1) (1) (1) (1).png
  • Placeholder: jwt-attacks/assets/todo-image-02.svg

JKU Header Bypass

Page: notes/Web Hacking/jwt-attacks/jku-header-bypass.md

  • Original: ../../.gitbook/assets/image (27).png
  • Placeholder: jwt-attacks/assets/todo-image-01.svg

Server-Side Template Injection (SSTI)

Page: notes/Web Hacking/server-side-template-injection-ssti/index.md

  • Original: ../../.gitbook/assets/image (2) (1) (1) (1) (1) (1) (1).png
  • Placeholder: server-side-template-injection-ssti/assets/todo-image-01.svg