⤷ Title: SSRF via Content-Type in Apache — Auditor | FahemSec
════════════════════════
𐀪 Author: Abdelrahman Radwan
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 17:28:34 GMT
════════════════════════
⌗ Tags: #ssrf #crlf_injection #apache
════════════════════════
𐀪 Author: Abdelrahman Radwan
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 17:28:34 GMT
════════════════════════
⌗ Tags: #ssrf #crlf_injection #apache
Medium
SSRF via Content-Type in Apache — Auditor | FahemSec
بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ
⤷ Title: Portswigger : SSRF Exploitation
════════════════════════
𐀪 Author: Sandeep Singh Sisodiya
════════════════════════
ⴵ Time: Fri, 23 Jan 2026 20:58:19 GMT
════════════════════════
⌗ Tags: #websecurity_testing #portswigger #cybersecurity #ssrf
════════════════════════
𐀪 Author: Sandeep Singh Sisodiya
════════════════════════
ⴵ Time: Fri, 23 Jan 2026 20:58:19 GMT
════════════════════════
⌗ Tags: #websecurity_testing #portswigger #cybersecurity #ssrf
Medium
Portswigger : SSRF Exploitation
Lab 1: Basic SSRF Against the Local Server
⤷ Title: 10-Year-Old Code Commit Just Gave Attackers Root on Thousands of Linux Boxes — CVE-2026–24061
════════════════════════
𐀪 Author: Lakshan Sameera
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 17:31:26 GMT
════════════════════════
⌗ Tags: #proof_of_concept #rce #telnet #cve202624061 #analysis
════════════════════════
𐀪 Author: Lakshan Sameera
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 17:31:26 GMT
════════════════════════
⌗ Tags: #proof_of_concept #rce #telnet #cve202624061 #analysis
Medium
10-Year-Old Code Commit Just Gave Attackers Root on Thousands of Linux Boxes — CVE-2026–24061
In the ever-evolving landscape of cybersecurity, legacy protocols continue to pose significant risks. CVE-2026–24061, a critical…
⤷ Title: Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
⌗ Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
⌗ Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
Medium
Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
Greetings, fellow cybersecurity enthusiasts and CTF players! In this writeup, we’ll walk through the solution of the “Smart Home” web…
⤷ Title: [Templates] — Exploiting PugJS Server-Side Template Injection to Remote Shell Access
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Fri, 23 Jan 2026 10:08:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #rce #pugjs_ssti #pug_template_injection #ssti
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Fri, 23 Jan 2026 10:08:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #rce #pugjs_ssti #pug_template_injection #ssti
Medium
[Templates] — Exploiting PugJS Server-Side Template Injection to Remote Shell Access
How unsafe Pug interpolation turns template rendering into code execution.
⤷ Title: 1. What Is Escaping?
════════════════════════
𐀪 Author: Reda Ouzidane
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 13:03:07 GMT
════════════════════════
⌗ Tags: #xss_bypass #xss_vulnerability #xss_attack #reflected_xss #stored_xss
════════════════════════
𐀪 Author: Reda Ouzidane
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 13:03:07 GMT
════════════════════════
⌗ Tags: #xss_bypass #xss_vulnerability #xss_attack #reflected_xss #stored_xss
Medium
1. What Is Escaping?
Escaping is the process of converting special characters into a representation that ensures they are interpreted as data, not executable…
⤷ Title: Vulnerabilidad XSS
════════════════════════
𐀪 Author: M4rc0sX
════════════════════════
ⴵ Time: Tue, 27 Jan 2026 19:18:55 GMT
════════════════════════
⌗ Tags: #stored_xss #xss_vulnerability #reflected_xss #xss_bypass #xss_attack
════════════════════════
𐀪 Author: M4rc0sX
════════════════════════
ⴵ Time: Tue, 27 Jan 2026 19:18:55 GMT
════════════════════════
⌗ Tags: #stored_xss #xss_vulnerability #reflected_xss #xss_bypass #xss_attack
Medium
Vulnerabilidad XSS
La vulnerabilidad consiste en inyectar código malicioso en una web, pudiendo así almacenarlo para que se ejecute cada vez que el usuario…
⤷ Title: Lab: URL normalisation |Portswigger
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Tue, 27 Jan 2026 07:28:44 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #portswigger #malicious_url #caches_normalization #url_normalisation
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Tue, 27 Jan 2026 07:28:44 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #portswigger #malicious_url #caches_normalization #url_normalisation
Medium
Lab: URL normalisation |Portswigger
This lab contains an XSS vulnerability that is not directly exploitable due to browser URL-encoding.To solve the lab, take advantage of the…
⤷ Title: Cross-Site Scripting (XSS): From Basics to Battle-Tested Defense
════════════════════════
𐀪 Author: Prateek Kumar
════════════════════════
ⴵ Time: Mon, 26 Jan 2026 17:15:20 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #sanitation #xss_attack #real_world_example #secure_coding
════════════════════════
𐀪 Author: Prateek Kumar
════════════════════════
ⴵ Time: Mon, 26 Jan 2026 17:15:20 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #sanitation #xss_attack #real_world_example #secure_coding
Medium
Cross-Site Scripting (XSS): From Basics to Battle-Tested Defense
Understanding XSS: A Clear, Practical Explanation
⤷ Title: XSS — Merry XSSMas
════════════════════════
𐀪 Author: ezemba fortune
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 12:37:50 GMT
════════════════════════
⌗ Tags: #xss_vulnerability
════════════════════════
𐀪 Author: ezemba fortune
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 12:37:50 GMT
════════════════════════
⌗ Tags: #xss_vulnerability
Medium
XSS — Merry XSSMas
Learn about types of XSS(Cross-Site Scripting) vulnerabilities and how to prevent them.
⤷ Title: MyExpense: 1 Lab WalkThrough
════════════════════════
𐀪 Author: Ankush Prasad Sah
════════════════════════
ⴵ Time: Wed, 21 Jan 2026 13:32:48 GMT
════════════════════════
⌗ Tags: #red_teaming #cybersecurity #sql #expenses #xss_vulnerability
════════════════════════
𐀪 Author: Ankush Prasad Sah
════════════════════════
ⴵ Time: Wed, 21 Jan 2026 13:32:48 GMT
════════════════════════
⌗ Tags: #red_teaming #cybersecurity #sql #expenses #xss_vulnerability
Medium
MyExpense: 1 Lab WalkThrough
Written By Ankush Prasad Sah
⤷ Title: How I Discovered the RXSS and Bypassed the WAF
════════════════════════
𐀪 Author: Hink_1250
════════════════════════
ⴵ Time: Wed, 21 Jan 2026 12:56:03 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #bypass #reflected_xss #xss_attack #xss_bypass
════════════════════════
𐀪 Author: Hink_1250
════════════════════════
ⴵ Time: Wed, 21 Jan 2026 12:56:03 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #bypass #reflected_xss #xss_attack #xss_bypass
Medium
💥 How I Discovered the RXSS and Bypassed the WAF
بسم الله والصلاة والسلام علي رسول الله صلي الله عليه وسلم
⤷ Title: DOM-Based Open Redirection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Tue, 20 Jan 2026 09:28:37 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #dom_xss #bug_bounty #open_redirect #xss_vulnerability
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Tue, 20 Jan 2026 09:28:37 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #dom_xss #bug_bounty #open_redirect #xss_vulnerability
Medium
DOM-Based Open Redirection
How unsafe JavaScript redirects turn trusted sites into attack vectors.
⤷ Title: How I hacked NASA with an RCE!!!
════════════════════════
𐀪 Author: Rubayet Hasan aka MR_Prey3r
════════════════════════
ⴵ Time: Sun, 25 Jan 2026 17:24:01 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #rce_vulnerability #bug_bounty_writeup #bug_bounty #penetration_testing
════════════════════════
𐀪 Author: Rubayet Hasan aka MR_Prey3r
════════════════════════
ⴵ Time: Sun, 25 Jan 2026 17:24:01 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #rce_vulnerability #bug_bounty_writeup #bug_bounty #penetration_testing
Medium
How I hacked NASA with an RCE!!!
A walkthrough to finding RCE on NASA’s public facing host
⤷ Title: FG-IR-25–084 (CVE-2025–25249) Teknik Analiz: cw_acd Heap Overflow ve RCE Tehdidi
════════════════════════
𐀪 Author: gökay.
════════════════════════
ⴵ Time: Tue, 20 Jan 2026 07:50:34 GMT
════════════════════════
⌗ Tags: #fortinet #fortigate #heap_overflow #cve #rce_vulnerability
════════════════════════
𐀪 Author: gökay.
════════════════════════
ⴵ Time: Tue, 20 Jan 2026 07:50:34 GMT
════════════════════════
⌗ Tags: #fortinet #fortigate #heap_overflow #cve #rce_vulnerability
Medium
FG-IR-25–084 (CVE-2025–25249) Teknik Analiz: cw_acd Heap Overflow ve RCE Tehdidi
Fortinet, FG-IR-25–084 bülteniyle FortiOS ve FortiSwitchManager ürünlerini etkileyen kritik (High) seviyeli bir zafiyeti (CVE-2025–25249)…
⤷ Title: SQL INTERSECT and EXCEPT Explained
════════════════════════
𐀪 Author: Quipoin
════════════════════════
ⴵ Time: Sat, 31 Jan 2026 05:05:08 GMT
════════════════════════
⌗ Tags: #sqlite #sqlalchemy #sql_injection #sql #sql_server
════════════════════════
𐀪 Author: Quipoin
════════════════════════
ⴵ Time: Sat, 31 Jan 2026 05:05:08 GMT
════════════════════════
⌗ Tags: #sqlite #sqlalchemy #sql_injection #sql #sql_server
Medium
SQL INTERSECT and EXCEPT Explained
When working with SQL, you often need to compare results of two queries.
For this purpose, SQL provides set operators.
For this purpose, SQL provides set operators.
⤷ Title: Blind SQL Injection Attacks
════════════════════════
𐀪 Author: Amrsmooke
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 12:37:20 GMT
════════════════════════
⌗ Tags: #sql_injection #hacking #cybersecurity #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Amrsmooke
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 12:37:20 GMT
════════════════════════
⌗ Tags: #sql_injection #hacking #cybersecurity #penetration_testing #bug_bounty
Medium
Blind SQL Injection Attacks
The Nature of “Blindness”
⤷ Title: Challenge Lab: SQL Basics (Basics)
════════════════════════
𐀪 Author: Jadem Yasser
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 04:59:25 GMT
════════════════════════
⌗ Tags: #hack_smarter #sql #sql_injection #sql_server #database
════════════════════════
𐀪 Author: Jadem Yasser
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 04:59:25 GMT
════════════════════════
⌗ Tags: #hack_smarter #sql #sql_injection #sql_server #database
Medium
Challenge Lab: SQL Basics (Basics)
Hack Smarter lab
⤷ Title: SQL Injection (SQLI)
════════════════════════
𐀪 Author: M4rc0sX
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 19:51:09 GMT
════════════════════════
⌗ Tags: #sql_injection_attack #blind_sql_injection #sql_injection
════════════════════════
𐀪 Author: M4rc0sX
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 19:51:09 GMT
════════════════════════
⌗ Tags: #sql_injection_attack #blind_sql_injection #sql_injection
Medium
SQL Injection (SQLI)
Esta vulnerabilidad utiliza las consultas SQL para obtener información de la base de datos y o hacer login sin contraseña.
⤷ Title: PortSwigger SQL Injection Labs — Part 1
════════════════════════
𐀪 Author: Emirkilicer
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 15:49:44 GMT
════════════════════════
⌗ Tags: #sql_injection #web_security #application_security #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Emirkilicer
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 15:49:44 GMT
════════════════════════
⌗ Tags: #sql_injection #web_security #application_security #cybersecurity #penetration_testing
Medium
PortSwigger SQL Injection Labs — Part 1
Introduction
⤷ Title: Technical Bug Bounty Methodology: Deep Recon, Automation and Human Insight
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 17:47:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #bug_bounty #bug_bounty_tips #bug_bounty_methodology
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 17:47:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #bug_bounty #bug_bounty_tips #bug_bounty_methodology
Medium
Technical Bug Bounty Methodology: Deep Recon, Automation and Human Insight
Introduction