Все публикации

Lab Blind SQL injection with conditional responses

Lab SQL injection attack, listing the database contents on non Oracle databases

Lab Blind SQL injection with conditional errors

Lab Blind SQL injection with time delays and information retrieval

Lab Reflected XSS with some SVG markup allowed

Lab Forced OAuth profile linking

Lab Stored XSS into anchor href attribute with double quotes HTML encoded

Lab Reflected XSS into a JavaScript string with angle brackets and double quotes HTML encoded and

Lab Reflected XSS into a JavaScript string with single quote and backslash escaped

Lab Reflected XSS into a JavaScript string with angle brackets HTML encoded

Lab Reflected XSS into HTML context with all tags blocked except custom ones

Lab Reflected XSS into attribute with angle brackets HTML encoded

Lab Stored XSS into HTML context with nothing encoded

Lab Reflected XSS in canonical link tag

Lab Reflected XSS into HTML context with nothing encoded

Lab Exploiting Ruby deserialization using a documented gadget chain

Lab Exploiting PHP deserialization with a pre built gadget chain

Lab Exploiting Java deserialization with Apache Commons

Instalación Firefox Developer en KALI

Lab Stealing OAuth access tokens via an open redirect

Lab Stealing OAuth access tokens via a proxy page

Lab Exploiting HTTP request smuggling to perform web cache poisoning

Lab Exploiting HTTP request smuggling to perform web cache deception

Lab Exploiting HTTP request smuggling to deliver reflected XSS