ArticleUser ID controlled by request parameter with data leakage in redirect
User ID controlled by request parameter with data leakage in redirect: This lab contains an access control vulnerability where sensitive information…
Practical security research, write-ups, guides, and lessons learned.
ArticleUser ID controlled by request parameter with data leakage in redirect: This lab contains an access control vulnerability where sensitive information…
ArticleUser ID controlled by request parameter, with unpredictable user IDs: This lab contains a blind SQL injection vulnerability. The application uses a t…
ArticleUser role can be modified in user profile: This lab contains an SQL injection vulnerability in the product category filter. • PortSwigger • Access co…
ArticleUnprotected Admin Functionality with Unpredictable URL: This lab has an unprotected admin panel, but its location is unpredictable. The hidden locati…
ArticleUser role controlled by request parameter: This lab has an admin panel at /admin, which identifies administrators using a forgeable cookie. • PortSwi…
ArticleKnowledge article about Access control: I wanted to make my knowledge more wide so I started ona new topic Access Control Access control vulnerabilit…
ArticleUnprotected admin functionality: This lab contains an unprotected admin panel. • PortSwigger • Access control vulnerabilities • admin panel, admin
ArticlePython script to extract recursive folders: sql • Other • other, python
ArticleBounty Hunt Steps: Identify valid sub domains of the target domain to help build a complete picture of the attack surface. • BugBounty • bugbounty, t…
ArticleStarted the journey on BugBounty: I have started more and more get into bug bounty its very fun also interesting. • BugBounty • bugbounty, tools
ArticleWhat is Cross site scripting and how does it work?: Cross Site Scripting (XSS) • Knowledge • XSS • knowledge, xss
ArticleHow does SQL Injection work also when does it occur?: SQL Injection (SQLi) • Knowledge • SQL injection • knowledge, sql injection