ervinismu
Search
Search
Dark mode
Light mode
Explorer
Tag: PortSwigger
28 items with this tag.
Oct 23, 2025
About Me
Writeup
HackTheBox
PortSwigger
Oct 17, 2025
PortSwigger Lab: Web shell upload via Content-Type restriction bypass
PortSwigger
WebShell
RemoteCodeExecution
Writeup
BurpSuite
Oct 17, 2025
PortSwigger Lab: Web shell upload via path traversal
PortSwigger
WebSecurity
WebShell
PathTraversal
Writeup
PHP
BurpSuite
Oct 17, 2025
PortSwigger Lab: Basic SSRF against the local server
ServerSideRequestForgery
Writeup
PortSwigger
Oct 17, 2025
PortSwigger Lab: Blind SSRF with out-of-band detection (WIP)
BurpSuite
PortSwigger
ServerSideRequestForgery
OutOfBandDetection
Writeup
WorkInProgress
Oct 16, 2025
PortSwigger Lab: Stored XSS into anchor href attribute with double quotes HTML-encoded
PortSwigger
WebSecurity
Writeup
CrossSiteScripting
StoredXSS
XSS
HTMLEscape
Oct 14, 2025
PortSwigger Academy - Exploiting LLM APIs with excessive agency
PortSwigger
WebSecurity
LargeLanguageModel
Writeup
Oct 14, 2025
PortSwigger Lab: Username enumeration via different responses
BurpSuite
PortSwigger
AuthenticationVulnerabilities
Writeup
UsernameEnumeration
PasswordEnumeration
BruteForce
Enumeration
Oct 14, 2025
PortSwigger Lab: Username enumeration via subtly different responses
PortSwigger
BurpSuite
WebSecurity
Writeup
AuthenticationVulnerabilities
Enumeration
UsernameEnumeration
PasswordEnumeration
BruteForce
Oct 14, 2025
PortSwigger Academy - Cross Origin Resource Sharing
PortSwigger
WebSecurity
CrosOriginResourceSharing
Oct 14, 2025
PortSwigger Academy - File upload vulnerabilities
PortSwigger
WebSecurity
FileUploadVulnerability
Oct 14, 2025
PortSwigger Academy - Exploring GraphQL Vulnerabilities
GraphQL
WebSecurity
RestAPI
PortSwigger
CrossSiteRequestForgery
DanielOfService
Oct 14, 2025
PortSwigger Academy - Path Traversal
PortSwigger
WebSecurity
PathTraversal
Oct 14, 2025
PortSwigger Lab: Remote code execution via polyglot web shell
PortSwigger
BurpSuite
RemoteCodeExecution
Writeup
ExifTool
PHP
WebShell
Oct 14, 2025
PortSwigger Lab: Remote code execution via web shell upload
PortSwigger
WebShell
RemoteCodeExecution
Writeup
PHP
BurpSuite
Oct 14, 2025
PortSwigger Lab: Web shell upload via extension blacklist bypass
PortSwigger
Writeup
WebShell
ApacheWebServer
PHP
BurpSuite
HTACCESS
Oct 14, 2025
PortSwigger Lab: Web shell upload via obfuscated file extension
PortSwigger
Writeup
WebShell
PHP
BurpSuite
Obfuscated
Oct 14, 2025
PortSwigger Lab: Basic SSRF against another back-end system
PortSwigger
BurpSuite
Writeup
ServerSideRequestForgery
Oct 14, 2025
PortSwigger Academy - Server-side request forgery attack
ServerSideRequestForgery
PortSwigger
WebSecurity
Oct 14, 2025
PortSwigger Lab: SSRF with blacklist-based input filter.
PortSwigger
BurpSuite
ServerSideRequestForgery
Writeup
Oct 14, 2025
PortSwigger Lab: SSRF with filter bypass via open redirection vulnerability
PortSwigger
BurpSuite
Writeup
ServerSideRequestForgery
OpenRedirectionVulnerability
Oct 14, 2025
PortSwigger Lab: DOM XSS in AngularJS expression with angle brackets and double quotes HTML-encoded
PortSwigger
WebSecurity
XSS
CrossSiteScripting
DOMXSS
Writeup
WorkInProgress
Oct 14, 2025
PortSwigger Lab: DOM XSS in jQuery anchor href attribute sink using location.search source
PortSwigger
WebSecurity
DOMXSS
XSS
CrossSiteScripting
JQuery
WindowLocationSearch
Writeup
Oct 14, 2025
PortSwigger Lab: DOM XSS in jQuery selector sink using a hashchange event
PortSwigger
WebSecurity
CrossSiteScripting
XSS
DOMXSS
Writeup
Oct 14, 2025
PortSwigger Lab: DOM XSS in document.write sink using source location.search inside a select element
WorkInProgress
PortSwigger
WebSecurity
XSS
CrossSiteScripting
DOMXSS
Writeup
Oct 14, 2025
PortSwigger Lab: Reflected DOM XSS
PortSwigger
WebSecurity
DOMXSS
XSS
ReflectedXSS
CrossSiteScripting
WorkInProgress
Writeup
Oct 14, 2025
PortSwigger Lab: Reflected XSS into HTML context with nothing encoded
PortSwigger
Writeup
CrossSiteScripting
XSS
ReflectedXSS
Oct 14, 2025
PortSwigger Lab: Reflected XSS into attribute with angle brackets HTML-encoded
PortSwigger
WebSecurity
ReflectedXSS
XSS
CrossSiteScripting
Writeup