Skip to content
Web Code Snippets

Web Code Snippets

Building blocks

Scaffolding (6)
Reusable exploit-script foundations: argument parsing, requests sessions, response validation, Boolean oracles, and command loops.
HTTP (14)
Sending requests the way a target expects them: query params, form and JSON bodies, multipart uploads, cookies, bearer tokens, and CSRF flows.
Output Parsing (13)
Extracting values from HTML, structured responses, generated files, and command output surrounded by markers.
Regex (3)
Pulling values out of text with regular expressions: capturing between fixed markers, non-greedy multiline capture with re.DOTALL, and collecting every match with findall.
Encodings (9)
Base64, URL, octal, hex and HTML codecs, nested payload strings, and JWT decode, tampering, and forge.
Utils (7)
Common transformations, random value generators, and file operations used across exploit scripts.
Subprocess (2)
Running blocking commands and retaining handles to long-running background processes.
WebSockets (3)
Synchronous and asyncio WebSocket clients, and a blind oracle that drives extraction over a single socket.
Concurrency (3)
Concurrent request execution for race conditions and finite-keyspace brute force.
Infra (6)
Background HTTP servers, callback capture, request-log parsing, and Ngrok and Cloudflare tunnels.
Debugging (2)
Runtime inspection for containerized applications through VS Code or the command line.
Frameworks and runtimes (5)
Framework and runtime behavior that affects exploit development.
OOB Exfil (4)
Hosted callback exfiltration with webhook.site: create inboxes, send command output, and poll captured data.
pwntools (1)
A reverse-shell listener that binds before the exploit trigger, waits for the callback, and opens an interactive session.
Archives (6)
Building and reading ZIP and TAR files, including Zip-Slip and symlink-traversal archives.
Chains (5)
End-to-end skeletons for SSRF scans, second-order injection, cache poisoning, renderer file reads, and arbitrary file write to hot-reload RCE.

Injection techniques

SQL Injection (16)
Dialect-specific SQL injection testing, blind extraction, and database execution primitives for H2, MSSQL, MySQL, PostgreSQL, and SQLite.
NoSQL Injection (4)
Operator and $regex boolean-blind exfiltration, server-side JavaScript injection, and time-based oracles for NoSQL backends.
XPath Injection (4)
XPath injection in Python: authentication bypass, in-band node dumping, and boolean and time-based blind extraction.
LDAP Injection (2)
Boolean-blind LDAP injection: bruteforcing a password and dumping arbitrary attributes one character at a time.
Regex Bypass (1)
Validation bypasses caused by regex anchors and multiline input.
Code Injection (10)
Server-side PHP, Python, and JavaScript code injection: manual source review, in-band output, blind oracles, and parser-specific bypasses.
Parameter Pollution (1)
Repeated HTTP parameters interpreted differently across frontend and backend parsers.
Prototype Pollution (1)
Node.js prototype-pollution payload shapes and child_process sink gadgets.
Deserialization (7)
Unsafe Java, PHP, and Python deserialization discovery, object lifecycle behavior, reconstruction hooks, gadget review, and payload generation.
LaTeX Injection (1)
Server-side LaTeX injection for local file read, including TeX hexadecimal notation for restricted input.
SSTI (7)
Server-side template injection testing and exploitation for Jinja2, Nunjucks, JsRender, Pug, Velocity, Thymeleaf, and Go html/template.
Command Injection (1)
Blind command injection with out-of-band exfiltration and an ${IFS} space-filter bypass.
XSS (1)
Browser-side data exfiltration through an HTTP callback.
XS-Leaks (1)
Cross-origin browser side channels that turn resource-loading behavior into Boolean oracles.