|
main menu
user menu
|
you are not logged in
posts tagged #web
-
June 30, 2026
JWT: when the public key becomes the secret
-
February 20, 2026
SQL injection: from UNION to blind time-based
-
February 14, 2026
XSS: stored, reflected and DOM-based
-
February 8, 2026
CSRF: making the victim's browser act
-
February 2, 2026
SSRF: turning the server into a proxy
-
January 27, 2026
XXE: XML external entities
-
January 21, 2026
Path traversal and Local File Inclusion
-
January 15, 2026
Insecure deserialization: objects that run code
-
January 9, 2026
Command injection: from input to shell
-
January 3, 2026
SSTI: server-side template injection
-
December 28, 2025
IDOR/BOLA: when the ID is the only defence
-
December 16, 2025
OAuth 2.0: the recurring pitfalls
-
December 4, 2025
Session fixation: fixing the ID before login
-
October 29, 2025
Password reset poisoning: hijacking the link via Host header
-
December 15, 2024
HTTP request smuggling: disagreement on where a request ends
-
December 9, 2024
Web cache poisoning: poisoning what everyone is served
-
December 3, 2024
Subdomain takeover: the CNAME pointing to nothing
-
November 27, 2024
GraphQL abuse: introspection, batching, depth
-
November 21, 2024
File upload: from profile picture to webshell
-
November 15, 2024
Prototype pollution: poisoning Object.prototype
-
November 9, 2024
CORS misconfiguration: trusting the wrong Origin
-
November 3, 2024
Clickjacking: the click that was not for you
-
October 28, 2024
Open redirect: your domain sending users elsewhere
-
October 22, 2024
Race conditions and TOCTOU: the window between check and use
-
August 23, 2024
Log4Shell: when a log line becomes code execution
|
latest posts
your IP address:
216.73.216.108
visitor #0
MOTD:
Every abstraction leaks somewhere. Here we look at where.
|