A short list of endpoints to look out for while pentesting



/admin/.json

/system/console

/dav/crx.default

/crx

/bin/crxde/logs

/jcr:system/jcr:versionStorage.json

/jcr_system/jcr_versionStorage.json

/libs/wcm/core/content/siteadmin.html

/libs/collab/core/content/admin.html

/libs/cq/ut/content/dumplibs.html

/var/linkchecker.html

/etc/linkchecker.html

/home/users/a/admin/profile.json /home/users/a/admin/profile.xml

/libs/cq/core/content/login.json

/content/../libs/foundation/components/text/text.jsp /content/../libs/foundation/components/text/text.jsp

/apps/sling/config/org.apache.felix.webconsole.internal.servlet.OsgiManager.config/jcr%3acontent/jcrdata

/libs/foundation/components/primary/cq/workflow/components/participants/json.GET.servlet

/content.pages.json

/content. Languages.json /content.blueprint.json /content.-1.json

/content.10.json

/content.infinity.json

/content.tidy.json

/content.tidy.-1.blubber.json

/content/dam.tidy. -100.json.

/content/content/geometrixx.sitemap.txt

/content/add_valid_page.query.json?statement //*

/content/add_valid_page.qu65ry.js6Fn?statement-//*

/content/add_valid_page.query.json?statement-//*

#/letransportPassword 20|20@transportUrt%201%200transportUser) /content/add_valid_path_to_a_page/ jcr_content.json

/content/add_valid_path_to_a_page/jcr:content.json

/content/add_valid_path_to_a_page/ jcr_content.feed

/content/add_valid_path_to_a_page/jcr:content.feed

/content/add_valid_path_to_a_page/pagename. jcr_content.feed

/content/add_valid_path_to_a_page/pagename.jcr:content.feed

/content/add_valid_path_to_a_page/pagename.docview.xml

/content/add_valid_path_to_a_page/pagename.docview.json

/content/add_valid_path_to_a_page/pagename.sysview.xml

/etc.xml

/content.feed.xml

/content.rss.xml

/content.feed.html

/content/add_valid_page.html?debug-layout

/projects

/tagging

/etc/replication.html

/etc/cloudservices.html

/welcome

Comments