Join
Knowledge

Writeups

How researchers found what they found: recon, analysis, proof of concept.

nyx0r.me · 5 days ago

AndroidHackingLab Challenges Walkthrough

This is a walkthrough for the most common android pentesting labs on MobileHackingLab.com explained step by step from reverse engineering the app, spotting the vulnerability in the source code and generating a PoC for exploiting the vulnera...

OWASP Mobile 1
0xsponge.medium.com · by 0xsponge · 1 week ago

Debugging Endpoints Nobody Bothers to Test Leads to Some Crits

By 0xsponge. Read the original on Medium. Most people's eyes slide straight past /cookie-policy/ on the way to the login flow, the file upload, the payment endpoint. This is about opening the debugger on that page anyway, out of stubbornnes...

5 min read · 4 weeks ago

Opening a coding agent in a folder the attacker chose

A crafted link can make a desktop app launch a coding-agent CLI inside a directory the attacker controls. The victim only has to click the app's normal "open in terminal?" prompt. Once the agent starts in that folder and the victim trusts i...

5
elkashawi.github.io · 1 month ago

Unauthenticated SSRF with Response Disclosure on a Secrets-Retrieval Gateway

Two endpoints, POST /get-secret1 and POST /get-secret3, on a target I’ll refer to as [REDACTED], took a JSON body with a field called gatewayHost. That field was meant to point at some internal secrets-retrieval service, but there was no va...

SSRF 2
hamzadzworm.medium.com · 1 month ago

Critical: Account Takeover via Interesting Logic Issue

External writeup by Hamzadzworm (abdelkader mouaz): an account takeover on a passwordless SaaS, chaining an email-uniqueness bypass (a trailing space) with a session-invalidation gap that spared business-mode sessions. The basis for the Nim...

1
medium.com · 1 month ago

CyberTalents — Evil Rick writeup

The write-up explains the Evil Rick challenge, which involves an insecure Python Pickle deserialization vulnerability. The researcher found hardcoded credentials hidden in the login page’s HTML comments, logged in, and discovered a remember...

CTF CyberTalents 2