ArticleCSRF where token validation depends on token being present
CSRF where token validation depends on token being present: To solve the lab, use your exploit server to host an HTML page that uses a CSRF attack to…
Practical security research, write-ups, guides, and lessons learned.
ArticleCSRF where token validation depends on token being present: To solve the lab, use your exploit server to host an HTML page that uses a CSRF attack to…
ArticleCSRF where token validation depends on request method: Exploit a CSRF weakness in the email change endpoint where token validation is only enforced f…
ArticleImmerse myself within Python: The last period of time I have started to look on so many different things • Security • python, security
Article2FA Broken Logic: Exploit a broken 2FA flow to log in as carlos starting from a valid session for wiener:peter. • PortSwigger • Authentication • mfa,…
ArticlePandora [Hack the box] [Blog] : started of with a nmap scan for • Security • nmap, private key
ArticlePaper [Hack the box] [BLOG]: regular scan • Security • nmap, security
Article[Red Team] Sektor 7 PE (Portable Executable): Quick notes from working through Sektor7 “Red Team” training — focusing on PE (Portable Executable) str…
Article[SQL Injection] Module 1: I have stepped further within Udemy I hopefully will complete alll the lessons very soon. In this module we started to look…
Article[Mutillidae] DOM XSS etc.: I have started the catch up all the definitions also catch up the fundamentals again. • Security • XSS • security, xss
ArticleBruteforce | Owasp Top 10: Capture my notes from practicing brute force techniques in Burp Suite, focusing on Intruder modes I actually used: Sniper…
ArticleBroken Authentication TryHackMe | Owasp Top 10 [Dragable & Resizeable ]: Now I am picking on the surface for Broken Authentication, this was quite go…
ArticleCommand Injection Part 2 TryHackMe | Owasp Top 10: Finally covered all the sessions of command injection for TryToHackMe though I didnt really learn…