-
Notifications
You must be signed in to change notification settings - Fork 25
/
Copy pathNuclei-Templates-Worth-Avoiding.txt
101 lines (101 loc) · 2.19 KB
/
Nuclei-Templates-Worth-Avoiding.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
- missing-csp
- deprecated-tls
- http-missing-security-headers
- tls-version
- addeventlistener-detect
- addeventlistener-message
- aem-misconfigs
- akamai-cache-detect
- apache-detect
- api-endpoints
- api-linkfinder
- apple-app-site-association
- Application-dos
- aspx-debug-mode
- aws-cloudfront-service
- azure-domain-tenant
- basic-auth-detect
- basic-auth-detection
- basic-cors-misconfig-flash
- caa-fingerprint
- cname-fingerprint
- cname-service
- cname-service-detection
- cors-misconfig
- credentials-disclosure
- credentials-disclosure-all
- deprecated-tls
- detect-all-takeovers
- detect-options-method
- detect-sentry
- developer-notes
- display-via-header
- dmarc-detect
- email-address-extraction
- email-extractor
- expired-ssl
- exposed-metrics
- Express-LFR-GET
- Express-LFR-json
- fastly-takeover
- fingerprinthub-web-fingerprints
- foulenzer-tech
- generic-tokens
- google-bucket-service
- google-frontend-httpserver
- gpc-json
- graphite-browser-default-credential
- hashicorp-consul-version
- header-reflection
- header-sqli
- http-missing-security-headers
- http-username-password
- insecure-crossdomain
- jira-unauthenticated-user-picker
- kubelet-metrics
- kubernetes-metrics
- Labda_403Bypass_slash
- Labda_403_Finder
- lvm-exporter-metrics
- metatag-cms
- mismatched-ssl
- missing-hsts
- missing-x-frame-options
- mx-fingerprint
- nameserver-detection
- nameserver-fingerprint
- nginx-version
- old-copyright
- openam-detect
- openresty-detect
- options-method
- possibility-of-webshell
- postgres-exporter-metrics
- puppetdb-detect
- request-based-interaction
- robots-txt
- robots-txt-endpoint
- s3-hunter
- search-field
- security-txt
- self-signed-ssl
- sitemap-detect
- ssl-dns-names
- ssl-issuer
- ssrf-by-proxy
- swagger-api
- swagger-version
- tabnabbing-check
- tech-detect
- tls-sni-proxy
- tls-version
- txt-fingerprint
- unauthenticated-varnish-cache-purge
- user-id-headers
- waf-detect
- wordpress-detect
- wp-admin-find
- wp-detect
- x-forwarded-for
- x-forwarded-host
- xss-deprecated-header