Bypass SSRF filters using domain redirection and abusing Python PDB
Oct 15, 2022
·
9 min readSecret starts with analyzing web source to recover a secret token from older commit. The secret is …
Sep 28, 2022
·
12 min readBountyHunter features a website that is vulnerable to XXE attack. Exploiting it allows me to …
Nov 22, 2021
·
7 min readAnother late CTF writeups for H@cktivitycon 2021 web category.
Oct 09, 2021
·
11 min readSecond-order SQL injection
Sep 24, 2021
·
6 min readMoodle exploitation using CVEs
Sep 16, 2021
·
11 min readSSTI in Golang, abuse S3 bucket, and NGINX backdoor
Sep 12, 2021
·
15 min readChaining XSS, SSRF, and deserialization vulnerabilities to get RCE
Jun 09, 2021
·
13 min readPentesting against simulated AWS S3 Bucket
Apr 24, 2021
·
14 min readSQLi for login bypass and embed webshell to an image file
Apr 09, 2021
·
6 min read