ArticleHTB Academy - Linux Security
HTB Academy Linux Security: Harden a Linux host quickly and safely by applying high‑impact controls: timely patching, host firewalling, MAC (SELinux/…
Practical security research, write-ups, guides, and lessons learned.
ArticleHTB Academy Linux Security: Harden a Linux host quickly and safely by applying high‑impact controls: timely patching, host firewalling, MAC (SELinux/…
ArticleHTB Academy Permission Management Quick Notes: Clean, copy pasteable reminders for changing ownership and permissions, plus a short note on SUID/SGID…
ArticleReflected XSS into HTML context with most tags and attributes blocked: Perform a reflected XSS in the search feature that is protected by a WAF, and…
ArticleLearn about Reflected XSS: Reflected XSS — HTML Context (ENHANCED) Goal: Understand and exploit reflected XSS when attacker input is inserted into an…
ArticleDOM XSS in document.write sink using source: Exploit a DOM based cross site scripting (XSS) vulnerability caused by the app writing location.search d…
ArticleStored XSS into HTML context with nothing encoded: Submit a blog comment that executes alert() when any user views the post (stored/persistent XSS).…
ArticleReflected XSS into HTML context with nothing encoded: This lab contains a simple reflected cross site scripting vulnerability in the search functiona…
ArticleBlind SQL injection with out of band data exfiltration rewritten: Exploit a blind SQL injection in a tracking cookie to trigger out‑of‑band (OOB) DNS…
ArticleBlind SQL injection with out of band interaction: This lab contains a blind SQL injection vulnerability. The application uses a tracking cookie for a…
ArticleSQL injection with filter bypass via XML encoding: Exploit a SQL injection vulnerability in the stock check feature to extract the admin user’s crede…
ArticleBlind SQL injection with out of band data exfiltration: Exploit a blind SQL injection in the TrackingId cookie to trigger out‑of‑band (OAST) DNS call…
ArticleSQL injection UNION attack, finding a column containing text: Exploit a SQL injection in the product category filter to perform a UNION based attack…