Bypass SSRF filters using domain redirection and abusing Python PDB
Oct 15, 2022
·
9 min readSSTI in Golang, abuse S3 bucket, and NGINX backdoor
Sep 12, 2021
·
15 min readDeserialization attack on YAML and reversing web assembly
Aug 06, 2021
·
9 min readFriendly PHP insecure deserialization attack and race condition
Jun 14, 2021
·
11 min readChaining XSS, SSRF, and deserialization vulnerabilities to get RCE
Jun 09, 2021
·
13 min readDC-9 from VulnHub features a website that is vulnerable to SQL injection.
I’m …
Jun 02, 2021
·
9 min readExploiting an insecure deserialization on Jackson library and how to mitigate it
May 09, 2021
·
9 min readPentesting against simulated AWS S3 Bucket
Apr 24, 2021
·
14 min readExploiting OpenNetAdmin vulnerability and sudo nano
Apr 02, 2021
·
6 min read