22 тысяч подписчиков
108 видео
Finding & Exploiting an Unused API Endpoint | Web Security Academy | PortSwigger Labs | Owasp
Exploiting Server Side Parameter Pollution in a Query String | Web Security Academy | PortSwigger
Explopiting an API Endpoint Using Documentation | Web Security Academy | PortSwigger Labs | Owasp
Exploiting NoSQL Injection to Extract Data | Web Security Academy | PortSwigger Labs | Owasp
Exploiting NoSQL Operator Injection to Bypass Authentication | Web Security Academy | PortSwigger
Detecting NoSQL Injection | Web Security Academy | PortSwigger Labs | Owasp
Exploiting XXE to Retrieve Data By Repurposing A Local DTD | Web Security Academy | PortSwigger Lab
Exploiting XXE Via Image File Upload | Web Security Academy | PortSwigger Labs | Owasp
Exploiting XInclude to Retrieve Files | Web Security Academy | PortSwigger Labs | Owasp
Exploiting Blind XXE to Retrieve Data Via Error Messages | Web Security Academy | PortSwigger Labs
Exploiting Bling XXE to Exfiltrate Data Using A Malicious External DTD | Web Security Academy
Blind XXE With Out-Of-Band Interaction Via XML Parameter Entities | Web Security Academy
File Path Traversal, Traversal Sequence Stripped with Superfluous URL-Decode | Web Security Academy
SQL Injection Listing the Database Contents on Oracle | Web Security Academy | Portswigger Labs
Remote Code Execution via Polyglot Web Shell Upload | Web Security Academy | PortSwigger Labs
Visible Error-Based SQL Injection | Web Security Academy | Portswigger Labs
Reflected XSS into HTML context with most tags and attributes blocked | Web Security Academy
Web Shell Upload Via Race Condition | Web Security Academy | PortSwigger Labs | Owasp
Blind SQL Injection with Time Delays | Web Security Academy | Portswigger Labs
Reflected XSS protected by CSP, with CSP bypass | Web Security Academy | Port Swigger Labs
Bypassing Rate Limit Via Race Condition | Web Security Academy | PortSwigger Labs | Owasp
Authentication Bypass Via Information Disclosure | Web Security Academy | PortSwigger Labs | Owasp
Metasploitable 2 | Vulnhub CTF | Metasploit | 2023 Walkthrough | Hindi
Arbitrary object injection in PHP | Web Security Academy | Port Swigger Labs
SSRF with Filter Bypass Via Open Redirection Vulnerability | Web Security Academy | PortSwigger Labs
Exploiting Time-Sensitive Vulnerabilities | Web Security Academy | PortSwigger Labs | Owasp
Information Disclosure on Debug Pages | Web Security Academy | PortSwigger Labs | Owasp
Blind SQL Injection with Out-of-Band Data Exfiltration | Web Security Academy | Portswigger Labs
Reflected XSS into a JavaScript string with angle brackets HTML encoded | Web Security Academy
Inconsistent Security Control | Web Security Academy | PortSwigger Labs | Owasp
Blind OS Command Injection with Out-Of-band Data Exfiltration | Web Security Academy | PortSwigger
DOM XSS using web messages | Web Security Academy | PortSwigger Labs
Modifying serialized objects | Web Security Academy | Port Swigger Labs
SQL Injection UNION, Retrieving Data From Other Tables | Web Security Academy | Portswigger Labs
Unprotected Admin Functionality With Unpredictable URL | Web Security Academy | PortSwigger Labs
CSRF vulnerability with no defenses | Web Security Academy | Port Swigger Labs