Payloads
Professional probes across 42 vulnerability classes - detection first, then exploitation and WAF-bypass variants.
Payloads index
- PayloadsAllTheThings - The reference payload & bypass encyclopedia for nearly every web vuln class. Bookmark it, then come back here for quick probes.
- Polyglots - Single strings that fire across multiple contexts - ideal for one-shot fuzzing when you don't yet know the sink. The 0xsobky XSS polyglot survives most encoding contexts; the SQLi polyglot triggers error/union/boolean at once.
- Cross-Site Scripting (XSS) - Context-driven: pick by where your input lands. Start with a benign marker (vulnsXSS) to find reflection, then break the context - HTML body, attribute, JS string, URL, or SVG. Last entries are common WAF/filter bypasses.
- SQL Injection - Detection first (error/boolean/time), then extraction (union). Confirm and exploit with sqlmap once a candidate responds. Grouped: auth bypass, boolean, error, UNION, time-based, and a stacked/WAF variant.
- NoSQL Injection - MongoDB and friends. Use operator injection in JSON bodies and bracket notation in query strings to bypass auth or exfiltrate via boolean/regex conditions.
- Server-Side Template Injection - Detect the engine with the polyglot first, then use the engine-specific chain to reach RCE. Reflected 49 from {{7*7}} means Jinja2/Twig-family; 7777777 from {{7*'7'}} distinguishes them.
- Command Injection - Separators and substitution to break into OS command execution. Use OOB (interactsh) to confirm blind cases; the last entries bypass naive space/keyword filters.
- LFI / Path Traversal - Read local files, then escalate. PHP wrappers turn LFI into source disclosure or RCE (log poisoning, php://filter chains). Later entries defeat filters via encoding and traversal padding.
- Server-Side Request Forgery - Point the server inward. Cloud metadata endpoints leak credentials; the bypass block (decimal/hex IP, IPv6, enclosed-alphanumerics, DNS rebinding hosts) defeats common allow-list filters.
- XML External Entity - Classic file read via inline entity; blind exfiltration via an external DTD you host. Also works through SVG and Office (docx/xlsx) uploads. Avoid billion-laughs on prod - it's a DoS.
- Open Redirect - Escape allow-list redirect validation. Low impact alone, but chains into OAuth token theft and SSRF filter bypass. Test on redirect_uri, next, returnUrl, url, and dest params.
- CRLF / Header Injection - Inject %0d%0a to split responses - set cookies, poison caches, or land reflected XSS via an injected body. Test in params reflected into Location or Set-Cookie headers.
- Host Header Injection - Poison password-reset links and cache keys by overriding the Host the app trusts. Prime targets: reset emails, absolute URL generation, and unkeyed cache inputs.
- JWT Attacks - Probe weak verification. Confirm with jwt_tool. Try alg:none, RS256→HS256 key confusion, and kid path/SQL injection; crack HS256 secrets offline.
- GraphQL - Start with introspection to dump the schema; if it's off, use field-suggestion errors (clairvoyance) to rebuild it. Then hunt BOLA/BFLA on objects and mutations.
- Prompt Injection / LLM - Probes for LLM-backed features (chat, RAG, agents). Start with a benign marker to prove the model follows injected instructions, then escalate to system-prompt leak, insecure output handling (output → XSS/SSRF/command sink), and tool/agent abuse. Indirect probes go inside data the model ingests (docs, pages, emails, filenames). Keep PoCs benign - use OAST callbacks, never real exfil. See the /bypasses/ ai-guardrails sheet.
- Prototype Pollution - Client and server merge gadgets. Pollution without a sink is weak; pair with an XSS or RCE gadget.
- DOM Clobbering - Named HTML elements shadow JS globals (location, defaultValue, attributes) so sanitizer or URL checks read attacker HTML instead of the real object.
- CSRF - Minimal PoC shapes. Prefer a real state-changing URL from the target. JSON needs a content-type the browser will send without a preflight.
- WebSocket - Handshake and first-frame probes. Swap in a victim cookie / Origin to test CSWSH and channel IDORs.
- Cache poison / deception - Unkeyed header and path-deception probes. Confirm with a second client. Harmless markers only.
- HTTP request smuggling - Desync probes for CL.TE / TE.CL / HTTP/2 downgrade. Lab or authorized target only. Do not desync a production CDN for fun.
- Mass assignment - Extra keys on register / PATCH / GraphQL update. Prove the new field changes authz, not just the JSON echo.
- Insecure deserialization - Magic-byte fingerprints. Identify the stack before you generate a gadget. Prefer DNS/time detect over a shell.
- CSS injection / data exfil - When HTML is escaped but CSS is not. Attribute selectors can leak CSRF tokens and one-time codes a character at a time.
- SVG / XML XSS - Uploads and image viewers that serve SVG as image/svg+xml from a cookied origin. Also markup inside PDF/XML.
- OAuth / OIDC - redirect_uri tricks, implicit flow, mixed response_type, state CSRF. Pair with the OAuth playbook.
- Path normalization - Proxy vs app disagreements. 403 bypass, cache deception, and /static vs /account mapping.
- Unicode / overlong / homoglyph - Filters that work on UTF-8 after they already made a decision on bytes, or that treat lookalike domains as the allowlist host.
- MFA / OTP - Skip, tamper, and race probes. Do not brute a production OTP pool past the program's rate-limit rule.
- Blind SSRF with OAST - Confirm a suspected server-side URL fetch with a unique, callback-only endpoint you control. Use one request at a time, record the parameter and correlation ID, and stop after proof of fetch.
- Second-order canaries - A harmless marker helps trace data that is stored first and processed later by exports, notifications, dashboards, or integrations. Test only accounts and records you control.
- URL consumer probes - Map which product features consume a URL: previews, imports, avatars, webhooks, PDFs, and feeds. Start with an owned HTTPS endpoint that returns a small, benign response.
- Path normalization canaries - Compare harmless equivalent paths to find a proxy, cache, or router that interprets them differently. Never use this as an access-control bypass against data you do not own.
- HTTP parameter pollution canaries - Use two distinct benign values for a documented parameter to learn whether the edge, application, and downstream service choose first, last, merge, or reject duplicates.
- OAST correlation markers - A disciplined naming scheme turns callbacks into reproducible evidence. Encode the feature, parameter, attempt number, and a non-secret nonce in every controlled callback URL.
- Blind XXE with OAST - For an authorized XML parser assessment, use an external entity that resolves only to a controlled callback and proves parser behavior without reading local files or reaching internal networks.
- IDOR / object-ID canaries - Two-account object identifiers and verb swaps. Use records you created. The payload is the ID, not a dump.
- Clickjacking / UI redress - Frame an authenticated sensitive page. Proof is a framed screenshot of a state-changing UI you own, plus missing X-Frame-Options / CSP frame-ancestors.
- Upload type-confusion canaries - Tiny inert fixtures to see which signal the server trusts: extension, declared type, or magic bytes. Never upload executable or XSS-active content to a shared origin.
- SAML assertion probes - Lab or test-tenant only. Recipient, Audience, Destination, and comment wrapping. Pair with the XXE canary on the same ACS parser.
- Race / parallel-action probes - Two sessions you own, one unique action, one RTT. Measure leftover extra credit, not a drained victim.