Published index
Blog Archive
Every published cybersecurity article, lab note, and technical writeup in one crawlable archive.
- 203
- Entries
- 8
- Years
2026
1 entries2025
15 entries- SQL injection with filter bypass via XML encoding
- DOM XSS in jQuery anchor href attribute sink using location.search source
- Blind SQL injection with out-of-band data exfiltration
- Blind SQL injection with out-of-band interaction
- Blind SQL injection with time delays and information retrieval
- DOM XSS in innerHTML sink using source location.search
- Reflected XSS into HTML context with nothing encoded
- Stored XSS into HTML context with nothing encoded
- Deep dive: TCP, subnets, and Active Directory — the fundamentals a penetration tester must master
- Built a Microsoft 365 Email Viewer for my company
- Improvements during execution of my bug bounty framework
- A Busy Week Away from Pentesting and building
- Create a supported SFTP plugin for shutter
- Blind SQL injection with time delays
- WebSocket messages to exploit vulnerabilities
2024
1 entries2023
20 entries- Username enumeration via response timing
- Insecure Direct Object References
- Recon Quick Hits — knockpy, ffuf, amass
- Made Dreambooth and GPT4-client run on Kali Linux
- AI - Stable diffussion with dreambooth
- User ID controlled by param with password disclosure
- URL-based access control can be circumvented
- User ID controlled by request parameter with data leakage in redirect
- User ID controlled by request parameter, with unpredictable user IDs
- User role can be modified in user profile
- Unprotected Admin Functionality with Unpredictable URL
- User role controlled by request parameter
- Knowledge article about Access-control
- Unprotected admin functionality
- Python script to extract recursive folders
- Bounty Hunt Steps
- Started the journey on BugBounty
- What is Cross-site-scripting and how does it work?
- How does SQL Injection work also when does it occur?
- What is CORS and how does it work?
2022
132 entries- DOM XSS using web messages and a JavaScript URL
- Knowledge about DOM-based and sinks
- More knowledge about DOM
- WebListeners
- DOM XSS using web messages and a JavaScript URL
- CSRF with broken Referer validation
- CSRF where Referer validation depends on header being present
- CSRF where token is duplicated in cookie
- Learn about Sinks
- Knowledge about DOM-based stuff
- CSRF where token is tied to non-session cookie
- CSRF where token is duplicated in cookie
- CSRF where token is not tied to user session
- CSRF where token validation depends on request method
- CSRF vulnerability with no defenses
- CSRF where token validation depends on token being present
- Basic clickjacking with CSRF token protection
- Exploiting clickjacking vulnerability to trigger DOM-based XSS
- Clickjacking with form input data prefilled from a URL parameter
- Basic clickjacking with CSRF token protection
- Clickjacking with a frame buster script
- Exploiting XXE via image file upload
- Exploiting XXE to retrieve data by repurposing a local DTD
- Exploiting XInclude to retrieve files
- Exploiting blind XXE to retrieve data via error messages
- SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
- Exploiting blind XXE to exfiltrate data using a malicious external DTD
- Blind XXE with out-of-band interaction via XML parameter entities
- Blind XXE with out-of-band interaction
- Exploiting XXE to perform SSRF attacks
- What is XML and XXE and how does it work?
- Blind SQL injection with conditional responses Part#1
- Blind SQL injection with conditional responses part 2
- SQL injection attack, listing the database contents on Oracle
- SQL injection UNION attack, retrieving multiple values in a single column
- SQL injection vulnerability allowing login bypass
- SQL injection attack, listing the database contents on non-Oracle databases
- SQL injection UNION attack, determining the number of columns returned by the query
- SQL injection attack, querying the database type and version on Oracle
- HTB Academy - Web Enumeration
- HTB Academy - Get started
- HTB Academy Firewall and IDS/IPS Evasion - Medium Lab
- HTB Academy - Firewall and IDS/IPS Evasion - Hard Lab
- HTB Academy Firewall and IDS/IPS Evasion - Easy Lab
- HTB Academy - nmap scanning basics
- HTB Academy nmap network performance
- HTB Academy - NSE Scripts
- HTB Academy - Service Enumeration
- DOM XSS in jQuery anchor href attribute sink using location.search source
- What is httpOnly and how does it work?
- Same-orgin policy (SOP)
- DOM XSS sink using location.search
- How does sinks working with dom-based xss
- Stored XSS into HTML context with nothing encoded
- What is cross-site scripting and how does it work?
- Insecure direct object references
- HTB Academy - Create user
- HTB Academy - Active Direcotry
- HTB Academy - NTLM
- HTB Academy - Host Discovery nmap
- HTB Academy - Deobfuscation , Encode and decode
- HTB Academy - DNS
- HTB Academy Kerberos
- HTB Academy - LDAP
- HTB Academy - Curl
- HTB Academy - Web Requests
- HTB Academy broken web results challange #1
- HTB Academy Basic Auth challange
- HTB Academy broken API:s challange #3
- HTB Academy - Active Directory
- HTB Academy OSI-Model and Protocol breakdown
- HTB Academy Networking Primer - Layers 1-4
- HTB Academy - Wireshark #2
- HTB Academy - Network Wireshark and extract
- HTB Academy - Mac adddresses
- HTB Academy IP-protocols
- HTB Academy TCP-dump
- HTB Academy - Traffic analysis
- HTB Academy - The Analysis Process
- HTB Academy - Networking TCP/IP
- HTB Academy - Networking TCP/IP
- HTB Academy - Networking modules
- HTB Academy - Networking Proxies
- HTB Academy - Networking Topologies
- HTB Academy - Introduction to networking - overview
- DOM XSS in innerHTML sink using source location.search
- HTb Academy - Network Types
- CSRF where token is duplicated in cookie
- HTB Academy - Windows Sessions and Subsystem
- HTB Academy - Windows Services & Processes
- HTB Academy - File System
- HTB Academy - Operating System Structure
- HTB Academy - System Information
- HTB Academy - History and dir paths
- HTB Academy - Fundamentals - File Descriptors and Redirections
- HTB Academy - Fundamentals - Find Files and Directories
- HTB Academy - Filter Contents
- HTB Academy - Linux Security
- HTB Academy - Permission Management Quick Notes
- Reflected XSS into HTML context with most tags and attributes blocked
- Learn about Reflected XSS
- DOM XSS in document.write sink using source
- Stored XSS into HTML context with nothing encoded
- Reflected XSS into HTML context with nothing encoded
- Blind SQL injection with out-of-band data exfiltration rewritten
- Blind SQL injection with out-of-band interaction
- SQL injection with filter bypass via XML encoding
- Blind SQL injection with out-of-band data exfiltration
- SQL injection UNION attack, finding a column containing text
- SQL injection UNION attack, retrieving multiple values in a single column
- Blind SQL injection with conditional responses
- SQL injection vulnerability allowing login bypass
- SQL injection attack, querying the database type and version on MySQL and Microsoft
- Blind SQL injection with conditional errors
- SQL injection attack, listing the database contents on Oracle
- SQL injection UNION attack, retrieving data from other tables
- SQL injection UNION attack, determining the number of columns returned by the query
- Blind SQL injection with time delays
- Blind SQL injection with conditional responses Part#2
- CSRF - where token is tied to non-session cookie
- CSRF- Where Referer validation depends on header being present
- CSRF - where token is not tied to user session
- CSRF where token validation depends on token being present
- CSRF vulnerability with no defenses
- CSRF where token validation depends on request method
- Immerse myself within Python
- 2FA Broken Logic
- Pandora [Hack the box] - [Blog]
- Paper [Hack the box] [BLOG]
- [Red Team] Sektor 7 PE (Portable Executable)
- [SQL Injection] Module 1
- [Mutillidae] DOM XSS etc.
2021
7 entries2020
4 entries2019
23 entries- Hack The Box - Bank Root Flag
- Hack The Box - Bank user flag
- Hack The Box - Europa Part 2
- Hack The Box - Europa Part 1
- Hack The Box - Haircut Part 1
- Hack The Box - Sneaky
- Hack The Box - October Part 2
- Finally back hopefully! also made some improvements on xsisec.com
- Hack The Box - Apocalyst
- Hack The Box blue
- Hack The Box - Grandpa
- Hack The Box - Joker
- Hack The Box Tentan
- Hack The Box - Brainfuck
- BURP-Suite procedure for enumeration nested directories
- Hack The Box Beep
- another lesson of VIM
- Hack The Box - Optimum User Flag
- Spent some time to learn Protractor and some cool plugins
- Hack The Box - cronOS Complete
- Hack The Box Popcorn
- Hack The Box - Lame user and root
- Finally done with this project.