z3nsh3ll

Broken Authentication - Offline Password Cracking

Using Double URL Encoding to Bypass Security Mechanisms for a Directory Traversal Attack

Broken Authentication - 2FA Broken Logic - SOLVE WITH BURP COMMUNITY EDITION

Broken Authentication - Password Reset Poisoning via Middleware

Directory Traversal - Exploiting Non-Recursive Sanitization

Blind SQL Injection - How Does It Work?

Using Custom HTML Tags to Run an XSS Attack

DOM XSS vs Reflected XSS - What's the Difference?

DOM Vulnerabilities - DOM XSS Using Web Messages

Why you should never use eval() in JavaScript. Reflected DOM XSS Attack.

SQL Injection - Blind SQL Injection With Time Delays

This XSS attack is both stored AND DOM based - here's why....

Using Floats in CSS - Core CSS Mastery 5.1

XSS - What is a 'Sink' in Cross Site Scripting?

Reflected XSS Protected by Very Strict CSP with Dangling Markup Attack

DOM Based XSS Attack Demonstration

What is File Path Traversal? Stealing the contents of the /etc/passwd file...

Reflected XSS in canonical link tag

SQL Injection Vulnerability Allowing Login Bypass

What is Reflected XSS? (Cross Site Scripting)

Blind SQL Injection With Conditional Errors - Administrator Password Stolen

Final Tips - Core CSS Mastery 6.5

Broken Access Control - Multi-step Process with no Access Control on One Step

DOM Vulnerabilities - DOM-based Cookie Manipulation