Temporary Advertisements:
Ad
Ad
Ad
What's the most common vulnerability you see in sites?
by earflaps - Sunday June 9, 2024 at 07:49 AM
#1
I'm not necessarily asking for the easiest (I.E Sql injection), just the most common you've seen appear when pen testing. Appreciate any responses <3
Tongue
Reply
#2
prolly no-rate limit which is useless jus spamming emails & it can be chained with other vulns and may or may not lead to account takeover + XSS(Cross-site scripting) + and API Vulnerabilities
https://www.vaadata.com/blog/api-penetra...box-tests/
https://academy.tcm-sec.com/p/hacking-apis
i suggest these resources if you want get into APIs Pentesting

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: See you on the other side.
Reply
#3
(Jun 09, 2024, 07:52 AM)SilentMastermind Wrote: prolly no-rate limit which is useless jus spamming emails & it can be chained with other vulns and may or may not lead to account takeover + XSS(Cross-site scripting) + and API Vulnerabilities
https://www.vaadata.com/blog/api-penetra...box-tests/
https://academy.tcm-sec.com/p/hacking-apis
i suggest these resources if you want get into APIs Pentesting

Is TCM Sec worth buying or are there alternatives? Ty also
Tongue
Reply
#4
(Jun 09, 2024, 11:00 AM)earflaps Wrote:
(Jun 09, 2024, 07:52 AM)SilentMastermind Wrote: prolly no-rate limit which is useless jus spamming emails & it can be chained with other vulns and may or may not lead to account takeover + XSS(Cross-site scripting) + and API Vulnerabilities
https://www.vaadata.com/blog/api-penetra...box-tests/
https://academy.tcm-sec.com/p/hacking-apis
i suggest these resources if you want get into APIs Pentesting

Is TCM Sec worth buying or are there alternatives? Ty also

from personal experience, i say yes theyre worth buying.
no prob<3

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: See you on the other side.
Reply
#5
PHP and XSS - 2 of the most flaws I have seen almost everywhere.
Reply
#6
Weak passwords.
Reply
#7
no IP blocking or rate limiting. so they will let you brute force a login page all day long without detecting it nor blocking you.
Reply
#8
XSS and SQL injec are well known
Reply
#9
I've seen alot of API shit since most API devs are paid like shit so they don't give a fuck to add some security
Reply
#10
(Jun 13, 2024, 04:31 AM)Egirl Wrote: I've seen alot of API shit since most API devs are paid like shit so they don't give a fuck to add some security

Appreciate it lmaoo
Tongue
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  A collection of deepweb sites [2025] dg7ka 185 13,853 5 hours ago
Last Post: ys88888
  FREE 3 UNCENSORED HACKING LLM QaboosbinSaidAlSaid 116 10,321 Yesterday, 02:40 PM
Last Post: adminx1
  CHATGPT jailbreak | DAN V14 Abandoned 51 9,942 Sep 26, 2026, 01:24 AM
Last Post: sybau012000
  Verified PP accounts with funds / PP Transfer Instant Reflection naomaanonymous 0 154 Sep 26, 2026, 12:55 AM
Last Post: naomaanonymous
  GTA5 2014-2015 prototype GameDriveOrg 0 165 Sep 25, 2026, 07:38 PM
Last Post: GameDriveOrg

Forum Jump:


 Users browsing this forum: 1 Guest(s)