9 тысяч подписчиков
287 видео
Exploiting XSS to perform CSRF (Video solution, Audio)
Reflected XSS protected by very strict CSP, with dangling markup attack (Video solution, Audio)
Unprotected admin functionality with unpredictable URL (Video solution)
CSRF where token validation depends on token being present (Video solution, Audio)
CSRF where token is duplicated in cookie (Audio, Explanations)
Blind OS command injection with out of band data exfiltration (Video solution, Audio)
SQL injection vulnerability allowing login bypass (Video solution, Audio)
Blind SQL injection with conditional responses (Video solution, Audio)
Reflected XSS protected by CSP, with dangling markup attack (Video solution, Audio)
Reflected XSS into a JavaScript string with angle brackets HTML encoded (Video solution)
SQL injection attack, listing the database contents on Oracle (Video solution)
Stored XSS into anchor href attribute with double quotes HTML-encoded (Video solution, Audio)
Reflected XSS into HTML context with nothing encoded (Video solution)
Blind OS command injection with out of band interaction (Video solution, Audio)
JWT Lab04
Blind SQL injection with time delays (Video solution, Audio)
Using PHAR deserialization to deploy a custom gadget chain (Video solution)
SQL injection attack, querying the database type and version on Oracle (Video solution)
Exploiting XXE to perform SSRF attacks (Video solution)
Reflected XSS into a template literal with angle brackets, single, ... (Video solution, Audio)
Manipulating WebSocket messages to exploit vulnerabilities (Video solution)
HTTP request smuggling, basic TE.CL vulnerability (Video solution, Audio)
SQL injection attack, listing the database contents on non-Oracle databases (Video solution, Audio)
Exploiting HTTP request smuggling to capture other users' requests (Video solution, Audio)
Blind SQL injection with out of band data exfiltration (Video solution)
Weak isolation on dual use endpoint (Video solution, Audio)
Stored XSS into onclick event with angle brackets ... (Video solution, Audio)
Authentication bypass via OAuth implicit flow (Video solution, Audio)
DOM XSS in AngularJS expression with angle brackets ... (Video solution, Audio)
JWT Lab01
Reflected XSS with AngularJS sandbox escape without strings (Video solution, Audio)
SQL injection vulnerability in WHERE clause allowing ... (Video solution & Audio)
Flawed enforcement of business rules (Video solution, Audio)
Source code disclosure via backup files (Video solution, Audio)
Exploiting cross-site scripting to steal cookies (Video solution, Audio)
Infinite money logic flaw (Video solution, Audio)
High level logic vulnerability (Video solution, Audio)
JWT Lab05
Low level logic flaw (Video solution, Audio)
JWT Lab07
CSRF where token validation depends on request method (Video solution, Audio)
JWT Lab08
CSRF where token is duplicated in cookie (Audio, Comments)
CSRF where token is tied to non-session cookie (Video solution, Audio)
SQL injection vulnerability allowing login bypass (Video solution)
Username enumeration via different responses (Video solution, Audio)
Inconsistent handling of exceptional input (Video solution, Audio)
Host header authentication bypass (Video solution, Audio)
Using application functionality to exploit insecure deserialization (Video solution)
Authentication bypass via flawed state machine (Video solution, Audio)
Web cache poisoning via an unkeyed query parameter (Video solution)