HTML縮小的潛在XSS漏洞html
https://hackerone.com/reports/24684node
node.js 目錄遍歷nginx
https://hackerone.com/reports/358645git
--path-as-is Do not squash .. sequences in URL pathgithub
curl 中 --path-as-is 選項的意思是在不要壓縮URL路徑中的 .. 符號npm
serve包介紹:https://www.npmjs.com/package/servecookie
內容注入curl
https://hackerone.com/reports/144104xss
用戶或攻擊者可以將其文本注入錯誤頁面,而且能夠捕獲用戶訪問惡意站點。url
圖片xss
https://hackerone.com/reports/72526
"><img src="x" onerror=alert(cookie)>.png
header頭攻擊
https://hackerone.com/reports/137181
NGINX alias錯誤配置可任意讀取
https://hackerone.com/reports/317201
https://github.com/yandex/gixy/blob/master/docs/en/plugins/aliastraversal.md
https://www.leavesongs.com/PENETRATION/nginx-insecure-configuration.html