AKUMA
  • README 🥷🏽
  • Red Teaming 👹
    • Loading 50% 😒
  • 👿BLUE TEAM
    • YARA rules
  • 📦Containers
    • DOCKER
      • Docker Security & Pentesting
        • Commond Docker error
      • 8 Best Practices for Docker Host Security
  • Windows Hardening 🛡️
    • Windows Active Directory Pentesting
      • Dll Hijacking
      • MSDT - Microsoft Support Diagnostic Tool Vulnerability
      • AD Enumeration TOOL
      • AD Certificate Templates
      • Kerberos Delegation
    • Windows Security Controls
      • Applocker Basics
    • Powershell Cheat sheet
    • AMSI Bypass
  • Linux Hardening 🛡️
    • Page 1
  • Network Services Pentesting
    • Footprinting Cheat sheet
      • 21-FTP
      • 161-SNMP
      • 445-SMB-139
      • 2049-NFS
      • 53-DNS
      • 587-SMTP
      • 143-IMAP/POP3
    • Juicy Curl
  • Pentesting Web
    • 100 Web Vulnerabilities, categorized into various types
    • Deserialization
      • Node.js Deserialization
    • SHODAN DORK
    • Vulnerabilities PAYLOADS
      • Directory Traversal Payload
      • Html-Injection-Read-FIle
      • Html-Injection
      • OS-Command-Injection
      • SQL-Injection-Auth-Bypass
      • PHP-Code-Injection
      • SQL-Injection
      • SSRF Basic
      • SSRF
      • XML-External-Entity
      • XSLT (eXtensible Stylesheet Language Transformations)
      • XSS Cheat Sheet
        • XSS
        • XSS -
        • XSS-polyglots
        • Cloudflare's XSS protection
    • Base Information
      • File-Extension-Inclusion
        • File-Inclusion-Windows
        • File-Inclusion-Linux
        • File-Extension
      • Media-Type-(MIME)
      • Windows-Sensitive-Files
      • Linux-Sensitive-Files
      • Linux-Log-Files
  • Blogs
    • How I Passed HTB Certified Penetration Testing Specialist
    • A comparative analysis of Open Source Web Application vulnerability scanners (Rana Khalil)
    • Sean Metcalfe Path for AD
    • Secure Docker - HackerSploit
  • Projects
    • HOME LAB
      • HOME LAB Blogs | Active Directory
        • Active Directory Lab Setup - 101
        • Active Directory Lab Setup - 102
        • Active Directory Lab Setup [ AD Enumeration ] - 103
        • Active Directory Lab Setup [AD Attacks ] - 104
      • Home Lab | Splunk Setup & Configuration
    • HOSTING A WEBSITE AND HARDENING ITS SECURITY
  • CTF- Writeups/ Solutions
    • HTB - Advanced Labs
      • Fortress
        • Jet
        • Akerva
        • Context
        • Synacktv
        • Faraday
        • AWS
      • Endgames
        • Ascension
        • RPG
        • Hades
        • Xen
        • P.O.O.
    • idekCTF 2024 🚩
    • TFC CTF 2024 🏳
    • DeadSec CTF 2024 🏴
      • Bing2 (web)
      • Mic_check (misc)
      • Windows Server (OSINT)
    • ImaginaryCTF 2024 🚩
      • cartesian-1 [Forensics]
      • packed [FORENSICS]
      • bom [FORENSICS]
      • BANK [MISC]
    • NahamCon CTF 2024 🏳
      • all WARMUPs
      • Base3200
      • The Hacker Webstore
      • iDoor
      • All About Robots
      • Thomas DEVerson
      • Helpful Desk
      • Curly Fries
    • Cyber Apocalypse 2024: Hacker Royale 🏴
      • Unbreakable [MISC]
      • StopDropAndRoll [MISC]
      • Character [MISC]
      • Delulu [pwn]
      • Tutorial [pwn]
      • Maze [Hardware]
      • TimeKORP [web]
  • Tools
    • Content Discovery & Form Manipulation
      • ffuf
      • RustScan
      • Feroxbuster
      • Dirsearch
      • Gobuster
      • Wfuzz
      • Webshell
      • websocket
Powered by GitBook
On this page
  1. Pentesting Web
  2. Base Information
  3. File-Extension-Inclusion

File-Extension

.a
.access
.acgi
.action
.add
.adp
.ai
.ajax
.alt
.app
.apsx
.aquery
.asax
.asc
.ascx
.asf
.ashx
.asm
.asmx
.asp
.Asp
.ASP
.aspx
.Aspx
.ASPX
.assets
.asx
.at
.au
.avi
.AVI
.awm
.b
.back
.backup
.bad
.bak
.BAK
.bak2
.bat
.bck
.bhtml
.bin
.bk
.bkp
.blog
.bml
.bmp
.bok
.bsp
.btr
.bu
.bz2
.c
.C
.ca
.cab
.cache
.captcha
.cat
.cc
.cdr
.cer
.cfc
.cfg
.cfm
.CFM
.cfml
.cgi
.chm
.class
.cmd
.cms
.cn
.cnf
.co
.code
.com
.com,
.COM
.common
.conf
.config
.Config
.content
.contrib
.copy
.core
.count
.cp
.crt
.cs
.csi
.csp
.csproj
.css
.CSS
.csshandler
.csv
.cur
.custom
.cz
.d
.dat
.data
.db
.dbf
.dcr
.de
.deb
.default
.delete
.detail
.details
.dev
.dhtml
.dic
.dict
.diff
.dir
.disabled
.dist
.divx
.djvu
.dll
.dmg
.do
.doc
.DOC
.docx
.dot
.ds
.dta
.dtd
.dwf
.dwg
.dwt
.e
.ece
.edit
.edu
.egov
.email
.eml
.en
.enu
.eot
.ep
.epc
.epl
.eps
.epub
.err
.error
.errors
.es
.eu
.exclude
.exe
.EXE
.extract
.f4v
.faces
.fcgi
.feed
.fil
.file
.filemtime
.files
.filesize
.film
.fla
.flv
.fopen
.form
.fpl
.fr
.framework
.fread
.fsockopen
.functions
.g
.geo
.getimagesize
.GetMapImage
.gif
.Gif
.GIF
.git
.go
.gpx
.grp
.gz
.h
.hml
.hmtl
.home
.hqx
.ht
.hta
.htaccess
.htc
.htlm
.htm
.htm,
.HTM
.html
.html,
.Html
.HTML
.html1
.htmll
.htmls
.htx
.i
.ice
.ico
.ICO
.ics
.ida
.idq
.idx
.ihtml
.image
.images
.img
.implode
.inc
.include
.includes
.index
.inf
.info
.ini
.iso
.it
.j
.jad
.jar
.java
.jbf
.jhtml
.jnlp
.jp
.jpe
.jpeg
.Jpeg
.JPEG
.jpg
.Jpg
.JPG
.js
.JS
.js2
.jsf
.json
.jsp
.jspa
.jspf
.jspx
.kml
.kmz
.l
.lasso
.layer
.lbi
.lck
.LCK
.lib
.lic
.licx
.link
.list
.lnk
.load
.local
.lock
.log
.LOG
.login
.lst
.m
.m3u
.m4v
.main
.maninfo
.map
.master
.Master
.mbox
.mdb
.media
.menu
.mgi
.mhtml
.mi
.mid
.min
.mkdir
.mno
.mod
.mov
.MOV
.mp2
.mp3
.MP3
.mp4
.mpeg
.MPEG
.mpg
.mpl
.msg
.msi
.mso
.mspx
.mv
.mvc
.mysql
.net
.new
.nl
.nsf
.NSF
.num
.o
.ocx
.odt
.off
.ogg
.old
.OLD
.old2
.opendir
.opml
.org
.orig
.original
.oui
.out
.p
.p3p
.p7b
.pac
.pad
.page
.PAGE
.pages
.parse
.pd
.pdb
.pdf
.Pdf
.PDF
.pem
.pfx
.pgp
.pgsql
.pgt
.ph
.php
.PhP
.php,
.php
.php~
.PHP
.php1
.php2
.php3
.php4
.php5
.phpmailer
.phpp
.phps
.phtm
.phtml
.pl
.plx
.pm
.png
.PNG
.pnp
.po
.pop3
.popup
.portal
.pot
.pps
.ppt
.PPT
.pptx
.prep
.preview
.prg
.price
.print
.process
.prt
.ps
.psd
.psp
.psql
.pub
.pvk
.pwd
.py
.pyc
.q
.query
.r
.ra
.ram
.rar
.raw
.rb
.rc
.rdf
.read
.readme
.rec
.red
.reg
.require
.results
.resx
.rhtml
.rm
.rpm
.rss
.rtf
.ru
.run
.Run
.s
.s7
.sample
.sav
.save
.scc
.scripts
.sdb
.se
.sea
.seam
.search
.sema
.ser
.server
.session
.settings
.setup
.sh
.shop
.shtm
.shtml
.sis
.sit
.site
.sitemap
.sitx
.Skins
.sln
.smi
.smil
.smtp
.sql
.squery
.src
.srv
.ssf
.ssi
.start
.static
.ste
.stm
.store
.strpos
.suo
.svc
.svg
.svn
.swf
.SWF
.swi
.swp
.sxw
.t
.taf
.tar
.tcl
.tem
.temp
.template
.templates
.Templates
.test
.text
.tgz
.thtml
.tif
.tiff
.tmp
.tmpl
.top
.torrent
.tpl
.trck
.ttf
.TTF
.tv
.txt
.TXT
.types
.ua
.uk
.url
.us
.user
.v
.vb
.vbproj
.vbs
.vcf
.vcs
.view
.vm
.vorteil
.vspscc
.w
.war
.wav
.WAV
.wbp
.wci
.web
.Web
.webinfo
.wma
.wmf
.wml
.wmv
.WMV
.woa
.wpd
.ws
.wsdl
.wvx
.wws
.x
.xhtm
.xhtml
.xls
.XLS
.xlsx
.xml
.XML
.xpi
.xpml
.xsd
.xsl
.xslt
.xspf
.y
.Z
.zdat
.Zif
.zip
.Zip
.ZIP
.phar
.php7
.pht
.phP
.aac
.abw
.arc
.avif
.azw
.bz
.cda
.csh
.jpeg,
.jsonld
.mid,
.midi
.mjs
.mpkg
.odp
.ods
.oga
.ogv
.ogx
.opus
.otf
.tif,
.ts
.vsd
.weba
.webm
.webp
.woff
.woff2
.xul
.3gp
.3g2
.7z
PreviousFile-Inclusion-LinuxNextMedia-Type-(MIME)

Last updated 9 months ago