Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Writeup of CWA-2023-004- 1491

CertiKPosted 2 Years Ago

Exploiting Misconfigured GitLab OIDC AWS IAM Roles- 1490

Nick FrichettePosted 2 Years Ago

Unauthenticated Access to GCP Dataproc Can Lead to Data Leak- 1489

Roi NisimiPosted 2 Years Ago

Persistent XSS on Microsoft Bing.com by poisoning Bingbot indexing- 1488

Supakiad S. (m3ez)Posted 2 Years Ago

Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN- 1487

Sudhanshu RajbharPosted 2 Years Ago

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default - 1486

flask-corsPosted 2 Years Ago

Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities- 1485

Yaniv Nizry - Sonar SourcePosted 2 Years Ago

Breaking Down Barriers: Exploiting Pre-Auth SQL Injection in WhatsUp Gold- 1484

SinSinologyPosted 2 Years Ago

Due to the use of msg.value in for loop, anyone can drain all the funds from the THORChain_Router contract- 1483

Code4RenaPosted 2 Years Ago

ThorChain will be informed wrongly about the unsuccessful ETH transfers due to the incorrect events emissions- 1482

Code4RenaPosted 2 Years Ago