People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!
test.signup.[redacted].org, it always made a redirect to https://test.signup.[redacted].org/. When creating a malformed POST request with a Content-Length that had two spaces before the number, they noticed some weirdness. Given this weirdness, they were curious if they could poison the redirect on the domain with an attacker-controlled one when another GET request followed the malicious one.Send group was used. To test this further, they used a remote VPS and poisoned it simultaneously to demonstrate the impact.