New Writeup❗️
Date: Wed, 13 Jul 2022 17:35:39 GMT
Title: Useful Offensive Snippets
Link: https://medium.com/p/823a322669f7
Date: Wed, 13 Jul 2022 17:35:39 GMT
Title: Useful Offensive Snippets
Link: https://medium.com/p/823a322669f7
Medium
Useful Offensive Snippets
I will update this post regularly, I am starting with a few of my most commonly used snippets.
New Writeup❗️
Date: Tue, 15 Dec 2020 15:14:37 GMT
Title: SolarWinds what probably (most-likely) happened…
Link: https://medium.com/p/ec4e588ce5da
Date: Tue, 15 Dec 2020 15:14:37 GMT
Title: SolarWinds what probably (most-likely) happened…
Link: https://medium.com/p/ec4e588ce5da
Medium
SolarWinds what probably (most-likely) happened…
TL;DR
New Writeup❗️
Date: Sat, 05 Dec 2020 10:56:20 GMT
Title: File descriptors — pwnable.kr
Link: https://medium.com/p/cfd20596a3d6
Date: Sat, 05 Dec 2020 10:56:20 GMT
Title: File descriptors — pwnable.kr
Link: https://medium.com/p/cfd20596a3d6
Medium
File descriptors — pwnable.kr
Firstly I want to say that I highly recommend https://pwnable.kr/play.php to learn exploit development, the site is full of nice and easy…
New Writeup❗️
Date: Sat, 09 May 2020 14:56:20 GMT
Title: LEVEL 01 — IO WARGAME
Link: https://medium.com/p/f7993deec7b6
Date: Sat, 09 May 2020 14:56:20 GMT
Title: LEVEL 01 — IO WARGAME
Link: https://medium.com/p/f7993deec7b6
Medium
LEVEL 01 — IO WARGAME
Hi everyone, it’s been some time since I last posted but I was just playing IO WARGAME and decided to write some up some solutions in the…
New Writeup❗️
Date: Tue, 26 Mar 2019 15:53:52 GMT
Title: Days 83, 84, 85 & 86 on https://labs.p64cyber.com
Link: https://medium.com/p/a9afa78806ab
Date: Tue, 26 Mar 2019 15:53:52 GMT
Title: Days 83, 84, 85 & 86 on https://labs.p64cyber.com
Link: https://medium.com/p/a9afa78806ab
Medium
Days 83, 84, 85 & 86 on https://labs.p64cyber.com
As you should know by now, this blog has moved but incase you have missed it, check back to the site daily: https://labs.p64cyber.com
New Writeup❗️
Date: Fri, 22 Mar 2019 18:47:08 GMT
Title: Day 82: Hunting for Vulnerabilities in Android Apps with Burp and APK Tools
Link: https://medium.com/p/8b84bc189603
Date: Fri, 22 Mar 2019 18:47:08 GMT
Title: Day 82: Hunting for Vulnerabilities in Android Apps with Burp and APK Tools
Link: https://medium.com/p/8b84bc189603
Medium
Day 82: Hunting for Vulnerabilities in Android Apps with Burp and APK Tools
https://labs.p64cyber.com/hunting-for-vulnerabilities-in-android-apps-with-burp-and-apk-tools/
New Writeup❗️
Date: Thu, 21 Mar 2019 19:45:51 GMT
Title: Day 80: P64 is the new Medium
Link: https://medium.com/p/d69e833d3ace
Date: Thu, 21 Mar 2019 19:45:51 GMT
Title: Day 80: P64 is the new Medium
Link: https://medium.com/p/d69e833d3ace
Medium
Day 80: P64 is the new Medium
Today I am sharing more than one post, the new site, P64. Over time P64 will become the number one online offensive security resource, it…
New Writeup❗️
Date: Wed, 20 Mar 2019 12:48:30 GMT
Title: Day 80: Becoming a Version Detection Ninja with GIT
Link: https://medium.com/p/6fe5d26b75f6
Date: Wed, 20 Mar 2019 12:48:30 GMT
Title: Day 80: Becoming a Version Detection Ninja with GIT
Link: https://medium.com/p/6fe5d26b75f6
Medium
Day 80: Becoming a Version Detection Ninja with GIT
“Day 80: Becoming a Version Detection Ninja with GIT” is published by Diddy Doodat.
New Writeup❗️
Date: Tue, 19 Mar 2019 21:17:56 GMT
Title: Day 79: FTP Pentest Guide
Link: https://medium.com/p/5106967bd50a
Date: Tue, 19 Mar 2019 21:17:56 GMT
Title: Day 79: FTP Pentest Guide
Link: https://medium.com/p/5106967bd50a
Medium
Day 79: FTP Pentest Guide
Today I have created a guide that will be constantly added to, it’s aim is to be the best FTP resource for pentesters.
New Writeup❗️
Date: Mon, 18 Mar 2019 16:27:53 GMT
Title: Day 78: HTB
Link: https://medium.com/p/3a289e9b329e
Date: Mon, 18 Mar 2019 16:27:53 GMT
Title: Day 78: HTB
Link: https://medium.com/p/3a289e9b329e
Medium
Day 78: HTB
Have you heard about Hack the Box? I hope so, it’s literally so damn good words can’t express how thankful I am to the creators. If you…
New Writeup❗️
Date: Tue, 09 Feb 2021 17:59:56 GMT
Title: Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
Link: https://medium.com/p/4a5d60fec610
Date: Tue, 09 Feb 2021 17:59:56 GMT
Title: Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
Link: https://medium.com/p/4a5d60fec610
Medium
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
The Story of a Novel Supply Chain Attack
New Writeup❗️
Date: Wed, 08 Jan 2020 16:05:16 GMT
Title: The Bug That Exposed Your PayPal Password
Link: https://medium.com/p/539fc2896da9
Date: Wed, 08 Jan 2020 16:05:16 GMT
Title: The Bug That Exposed Your PayPal Password
Link: https://medium.com/p/539fc2896da9
Medium
The Bug That Exposed Your PayPal Password
And Credit Card Number Too
New Writeup❗️
Date: Mon, 30 Oct 2017 15:00:09 GMT
Title: How I hacked Google’s bug tracking system itself for $15,600 in bounties
Link: https://medium.com/p/58f86cc9f9a5
Date: Mon, 30 Oct 2017 15:00:09 GMT
Title: How I hacked Google’s bug tracking system itself for $15,600 in bounties
Link: https://medium.com/p/58f86cc9f9a5
Medium
How I hacked Google’s bug tracking system itself for $15,600 in bounties
Easy Bugs for Hard Cash
New Writeup❗️
Date: Wed, 14 Dec 2022 21:10:13 GMT
Title: Unprotected API endpoint at HAwebsso.nl
Link: https://medium.com/p/5f1951e212fe
Date: Wed, 14 Dec 2022 21:10:13 GMT
Title: Unprotected API endpoint at HAwebsso.nl
Link: https://medium.com/p/5f1951e212fe
Medium
Unprotected API endpoint at HAwebsso.nl
Background
As some might know, I work as a medical doctor (general practitioner) by day and as a security researcher by night. One of my…
As some might know, I work as a medical doctor (general practitioner) by day and as a security researcher by night. One of my…
New Writeup❗️
Date: Thu, 06 Aug 2020 12:44:49 GMT
Title: Blind SQL Injection at fasteditor.hema.com
Link: https://medium.com/p/6ac140c0d1a3
Date: Thu, 06 Aug 2020 12:44:49 GMT
Title: Blind SQL Injection at fasteditor.hema.com
Link: https://medium.com/p/6ac140c0d1a3
Medium
Blind SQL Injection at fasteditor.hema.com
A full write-up that explains the discovery and exploitation of a blind SQL injection bug.
🗿1
New Writeup❗️
Date: Thu, 06 Aug 2020 12:21:53 GMT
Title: Reflected XSS at fotoservice.hema.nl
Link: https://medium.com/p/af344ef63433
Date: Thu, 06 Aug 2020 12:21:53 GMT
Title: Reflected XSS at fotoservice.hema.nl
Link: https://medium.com/p/af344ef63433
Medium
Reflected XSS at fotoservice.hema.nl
A full write-up that learns the reader how to find reflected XSS and open redirect bugs. Hema.nl was used as an real life example.
New Writeup❗️
Date: Tue, 12 May 2020 09:20:53 GMT
Title: Stored XSS in Paytium 3.0.13 WordPress Plugin
Link: https://medium.com/p/3157ee37eb8f
Date: Tue, 12 May 2020 09:20:53 GMT
Title: Stored XSS in Paytium 3.0.13 WordPress Plugin
Link: https://medium.com/p/3157ee37eb8f
Medium
Stored XSS in Paytium 3.0.13 WordPress Plugin
A full write up: How to find a stored XSS bug in a Wordpress plugin and create a proof of concept payload that hijacks the full…
New Writeup❗️
Date: Sat, 06 Apr 2019 12:40:26 GMT
Title: Email content spoofing at IKEA.com
Link: https://medium.com/p/ea76c17605ee
Date: Sat, 06 Apr 2019 12:40:26 GMT
Title: Email content spoofing at IKEA.com
Link: https://medium.com/p/ea76c17605ee
Medium
Email content spoofing at IKEA.com
IKEA.com did not check the fields being used in one of their email forms. This resulted in the creation of fully signed phishing email.
New Writeup❗️
Date: Thu, 04 Apr 2019 09:46:04 GMT
Title: Leaked Salesforce API access token at IKEA.com
Link: https://medium.com/p/132eea3844e0
Date: Thu, 04 Apr 2019 09:46:04 GMT
Title: Leaked Salesforce API access token at IKEA.com
Link: https://medium.com/p/132eea3844e0
Medium
Leaked Salesforce API access token at IKEA.com
A leaked Salesforce API key leads to a potential data leak at IKEA.com. A step by step write-up how this bug was found.
New Writeup❗️
Date: Sun, 07 Oct 2018 10:29:32 GMT
Title: Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
Link: https://medium.com/p/db6188acedd9
Date: Sun, 07 Oct 2018 10:29:32 GMT
Title: Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
Link: https://medium.com/p/db6188acedd9
Medium
Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
A full write-up how we created a phishing login on LinkedIn.com by manipulating Open Graph Tags used by their blogging platform.