ArticleDOM XSS in jQuery anchor href attribute sink using location.search source
DOM XSS in jQuery anchor href attribute sink using location.search source: Exploit a DOM XSS in the feedback page to make the “back” link execute ale…
Practical security research, write-ups, guides, and lessons learned.
ArticleDOM XSS in jQuery anchor href attribute sink using location.search source: Exploit a DOM XSS in the feedback page to make the “back” link execute ale…
ArticleWhat is httpOnly and how does it work?: In the Lab 5 on portswigger DOM XSS in jQuery anchor href attribute sink using location.search source. I wasn…
ArticleSame orgin policy (SOP): sql • Knowledge • knowledge, same origin
ArticleDOM XSS sink using location.search: Exploit the search endpoint’s reflected output to achieve XSS by breaking out of the single‑quoted context and in…
ArticleHow does sinks working with dom based xss: Clarify what sources and sinks are in DOM based XSS, show practical examples for the three main sink categ…
ArticleStored XSS into HTML context with nothing encoded: Experiment with XSS filter evasion techniques to achieve JavaScript execution without user interac…
ArticleWhat is cross site scripting and how does it work?: Give a clear, practical overview of cross‑site scripting (XSS): what it is, how it works, the thr…
ArticleInsecure direct object references: The app stores chat logs as static files. Goal: retrieve user carlos’s password from his chat log, then log in as…
ArticleHTB Academy Active Direcotry : Built in AD Groups AD contains many default or built in security groups, some of which grant their members powerful ri…
ArticleHTB Academy Create user: New ADUser Name "Orion Starchaser" Accountpassword (ConvertTo SecureString AsPlainText (Read Host "Enter a secure password")…
ArticleHTB Academy NTLM: Give a practical, concise overview of NTLM/Net‑NTLM families (hashes & protocols), how they differ from Kerberos, what each looks l…
ArticleHTB Academy Host Discovery nmap: Fast, reliable host discovery during recon. These are my go‑to nmap one‑liners for ranges, lists, ad‑hoc targets, an…