Published index

Blog Archive

Every published cybersecurity article, lab note, and technical writeup in one crawlable archive.

199
Entries
8
Years

2026

1 entries
  1. Running ComfyUI on AMD GPUs with ROCm (Pop!_OS / Ubuntu)

2025

15 entries
  1. SQL injection with filter bypass via XML encoding
  2. DOM XSS in jQuery anchor href attribute sink using location.search source
  3. Blind SQL injection with out-of-band data exfiltration
  4. Blind SQL injection with out-of-band interaction
  5. Blind SQL injection with time delays and information retrieval
  6. DOM XSS in innerHTML sink using source location.search
  7. Reflected XSS into HTML context with nothing encoded
  8. Stored XSS into HTML context with nothing encoded
  9. Deep dive: TCP, subnets, and Active Directory — the fundamentals a penetration tester must master
  10. Built a Microsoft 365 Email Viewer for my company
  11. Improvements during execution of my bug bounty framework
  12. A Busy Week Away from Pentesting and building
  13. Create a supported SFTP plugin for shutter
  14. Blind SQL injection with time delays
  15. WebSocket messages to exploit vulnerabilities

2024

1 entries
  1. Android HTTPS Interception with Genymotion + Burp – Walkthrough

2023

20 entries
  1. Username enumeration via response timing
  2. Insecure Direct Object References
  3. Recon Quick Hits — knockpy, ffuf, amass
  4. Made Dreambooth and GPT4-client run on Kali Linux
  5. AI - Stable diffussion with dreambooth
  6. User ID controlled by param with password disclosure
  7. URL-based access control can be circumvented
  8. User ID controlled by request parameter with data leakage in redirect
  9. User ID controlled by request parameter, with unpredictable user IDs
  10. User role can be modified in user profile
  11. Unprotected Admin Functionality with Unpredictable URL
  12. User role controlled by request parameter
  13. Knowledge article about Access-control
  14. Unprotected admin functionality
  15. Python script to extract recursive folders
  16. Bounty Hunt Steps
  17. Started the journey on BugBounty
  18. What is Cross-site-scripting and how does it work?
  19. How does SQL Injection work also when does it occur?
  20. What is CORS and how does it work?

2022

128 entries
  1. DOM XSS using web messages and a JavaScript URL
  2. Knowledge about DOM-based and sinks
  3. More knowledge about DOM
  4. WebListeners
  5. DOM XSS using web messages and a JavaScript URL
  6. CSRF with broken Referer validation
  7. CSRF where Referer validation depends on header being present
  8. CSRF where token is duplicated in cookie
  9. Learn about Sinks
  10. Knowledge about DOM-based stuff
  11. CSRF where token is tied to non-session cookie
  12. CSRF where token is duplicated in cookie
  13. CSRF where token validation depends on request method
  14. CSRF where token is not tied to user session
  15. CSRF vulnerability with no defenses
  16. CSRF where token validation depends on token being present
  17. Basic clickjacking with CSRF token protection
  18. Exploiting clickjacking vulnerability to trigger DOM-based XSS
  19. SQL injection UNION attack, retrieving multiple values in a single column
  20. SQL injection attack, querying the database type and version on Oracle
  21. Clickjacking with form input data prefilled from a URL parameter
  22. Basic clickjacking with CSRF token protection
  23. Clickjacking with a frame buster script
  24. Exploiting XXE via image file upload
  25. Exploiting XXE to retrieve data by repurposing a local DTD
  26. Exploiting XInclude to retrieve files
  27. Exploiting blind XXE to retrieve data via error messages
  28. SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
  29. Exploiting blind XXE to exfiltrate data using a malicious external DTD
  30. Blind XXE with out-of-band interaction via XML parameter entities
  31. Blind XXE with out-of-band interaction
  32. Exploiting XXE to perform SSRF attacks
  33. What is XML and XXE and how does it work?
  34. Blind SQL injection with conditional responses Part#1
  35. Blind SQL injection with conditional responses part 2
  36. SQL injection attack, listing the database contents on Oracle
  37. SQL injection attack, listing the database contents on non-Oracle databases
  38. SQL injection UNION attack, determining the number of columns returned by the query
  39. HTB Academy - Web Enumeration
  40. HTB Academy - Get started
  41. HTB Academy Firewall and IDS/IPS Evasion - Medium Lab
  42. HTB Academy - Firewall and IDS/IPS Evasion - Hard Lab
  43. HTB Academy Firewall and IDS/IPS Evasion - Easy Lab
  44. HTB Academy - nmap scanning basics
  45. HTB Academy nmap network performance
  46. HTB Academy - NSE Scripts
  47. HTB Academy - Service Enumeration
  48. DOM XSS in jQuery anchor href attribute sink using location.search source
  49. What is httpOnly and how does it work?
  50. Same-orgin policy (SOP)
  51. DOM XSS sink using location.search
  52. How does sinks working with dom-based xss
  53. Stored XSS into HTML context with nothing encoded
  54. What is cross-site scripting and how does it work?
  55. Insecure direct object references
  56. HTB Academy - Active Directory
  57. HTB Academy - Create user
  58. HTB Academy - NTLM
  59. HTB Academy - Host Discovery nmap
  60. HTB Academy - Deobfuscation , Encode and decode
  61. HTB Academy - DNS
  62. HTB Academy Kerberos
  63. HTB Academy - LDAP
  64. HTB Academy - Curl
  65. HTB Academy - Web Requests
  66. HTB Academy broken web results challange #1
  67. HTB Academy Basic Auth challange
  68. HTB Academy broken API:s challange #3
  69. HTB Academy - Active Directory
  70. HTB Academy OSI-Model and Protocol breakdown
  71. HTB Academy Networking Primer - Layers 1-4
  72. HTB Academy - Wireshark #2
  73. HTB Academy - Network Wireshark and extract
  74. HTB Academy - Mac adddresses
  75. HTB Academy IP-protocols
  76. HTB Academy TCP-dump
  77. HTB Academy - Traffic analysis
  78. HTB Academy - The Analysis Process
  79. HTB Academy - Networking TCP/IP
  80. HTB Academy - Networking modules
  81. HTB Academy - Networking Proxies
  82. HTB Academy - Networking Topologies
  83. HTB Academy - Introduction to networking - overview
  84. DOM XSS in innerHTML sink using source location.search
  85. HTb Academy - Network Types
  86. CSRF where token is duplicated in cookie
  87. HTB Academy - Windows Sessions and Subsystem
  88. HTB Academy - Windows Services & Processes
  89. HTB Academy - File System
  90. HTB Academy - Operating System Structure
  91. HTB Academy - History and dir paths
  92. HTB Academy - System Information
  93. HTB Academy - Fundamentals - File Descriptors and Redirections
  94. HTB Academy - Fundamentals - Find Files and Directories
  95. HTB Academy - Filter Contents
  96. HTB Academy - Linux Security
  97. HTB Academy - Permission Management Quick Notes
  98. Reflected XSS into HTML context with most tags and attributes blocked
  99. Learn about Reflected XSS
  100. DOM XSS in document.write sink using source
  101. Stored XSS into HTML context with nothing encoded
  102. Reflected XSS into HTML context with nothing encoded
  103. Blind SQL injection with out-of-band data exfiltration rewritten
  104. Blind SQL injection with out-of-band interaction
  105. SQL injection with filter bypass via XML encoding
  106. Blind SQL injection with out-of-band data exfiltration
  107. SQL injection UNION attack, finding a column containing text
  108. Blind SQL injection with conditional responses
  109. SQL injection vulnerability allowing login bypass
  110. SQL injection attack, querying the database type and version on MySQL and Microsoft
  111. Blind SQL injection with conditional errors
  112. SQL injection attack, listing the database contents on Oracle
  113. SQL injection UNION attack, retrieving data from other tables
  114. SQL injection UNION attack, determining the number of columns returned by the query
  115. Blind SQL injection with time delays
  116. Blind SQL injection with conditional responses Part#2
  117. CSRF - where token is tied to non-session cookie
  118. CSRF- Where Referer validation depends on header being present
  119. CSRF - where token is not tied to user session
  120. CSRF where token validation depends on token being present
  121. CSRF where token validation depends on request method
  122. Immerse myself within Python
  123. 2FA Broken Logic
  124. Pandora [Hack the box] - [Blog]
  125. Paper [Hack the box] [BLOG]
  126. [Red Team] Sektor 7 PE (Portable Executable)
  127. [SQL Injection] Module 1
  128. [Mutillidae] DOM XSS etc.

2021

7 entries
  1. Bruteforce | Owasp Top 10
  2. Broken Authentication TryHackMe | Owasp Top 10 [Dragable & Resizeable ]
  3. Command Injection Part 2 TryHackMe | Owasp Top 10
  4. Command Injection Part 1 TryHackMe | Owasp Top 10
  5. Hack The Box - Help
  6. Hack The Box Explore user-flag
  7. Hack The Box - CAP root flag

2020

4 entries
  1. Reported my first Bug Bounty finding
  2. Hack The Box Wall User and Root flag
  3. Hack The Box - Luke User and Root flag
  4. Hack The Box - Calamity user flag

2019

23 entries
  1. Hack The Box - Bank Root Flag
  2. Hack The Box - Bank user flag
  3. Hack The Box - Europa Part 2
  4. Hack The Box - Europa Part 1
  5. Hack The Box - Haircut Part 1
  6. Hack The Box - Sneaky
  7. Hack The Box - October Part 2
  8. Finally back hopefully! also made some improvements on xsisec.com
  9. Hack The Box - Apocalyst
  10. Hack The Box blue
  11. Hack The Box - Grandpa
  12. Hack The Box - Joker
  13. Hack The Box Tentan
  14. Hack The Box - Brainfuck
  15. BURP-Suite procedure for enumeration nested directories
  16. Hack The Box Beep
  17. another lesson of VIM
  18. Hack The Box - Optimum User Flag
  19. Spent some time to learn Protractor and some cool plugins
  20. Hack The Box - cronOS Complete
  21. Hack The Box Popcorn
  22. Hack The Box - Lame user and root
  23. Finally done with this project.