QeeqBox
- 124 followers
- Washington, USA
- http://qeeqbox.com
Pinned
Repositories
- cross-site-request-forgery Public
A threat actor may trick an authenticated or trusted victim into transmitting unauthorized actions on their behalf
- captcha-bypass Public
A threat actor may bypass the Completely Automated Public Turing test to tell Computers and Humans Apart (captcha) by breaking the solving logic, human-assisted solving services, or utilizing automated technology
- horizontal-privilege-escalation Public
A threat actor may perform unauthorized functions belonging to another user with a similar privileges level
- vertical-privilege-escalation Public
A threat actor may perform unauthorized functions belonging to another user with a higher privileges level
- reflected-cross-site-scripting Public
A threat actor may inject malicious content into HTTP requests. The content will be reflected in the HTTP response and executed in the victim's browser
- stored-cross-site-scripting Public
An adversary may inject malicious content into a vulnerable target
-
- dom-based-cross-site-scripting Public
A threat actor may inject malicious content into HTTP requests. The content is not reflected in the HTTP response and executed in the victim's browser.
- credential-stuffing Public
A threat actor may guess the target credentials using a known username and password pairs gathered from previous brute-force attacks
- password-spraying Public
A threat actor may guess the target credentials using a single password with a large set of usernames against the target












