OS Command Execution with Web Application Firewall Bypass using wildcards aka globbing patterns


Backup File Artifact Checker (bfac)


Just want to say, I found value in this tool on an external blackbox penetration test where I found unaccessible (returned a 403) but to my surprise, was accessible! Since then, I always add ~ to the end of my file discovery phase!


Diggin’ Deep Into Newly Created Domains – Andrew Freebrey


