ervinismu
Search
Search
Dark mode
Light mode
Explorer
Tag: Writeup
26 items with this tag.
Oct 23, 2025
About Me
Writeup
HackTheBox
PortSwigger
Oct 17, 2025
PortSwigger Lab: Web shell upload via Content-Type restriction bypass
PortSwigger
WebShell
RemoteCodeExecution
Writeup
BurpSuite
Oct 17, 2025
PortSwigger Lab: Web shell upload via path traversal
PortSwigger
WebSecurity
WebShell
PathTraversal
Writeup
PHP
BurpSuite
Oct 17, 2025
PortSwigger Lab: Basic SSRF against the local server
ServerSideRequestForgery
Writeup
PortSwigger
Oct 17, 2025
PortSwigger Lab: Blind SSRF with out-of-band detection (WIP)
BurpSuite
PortSwigger
ServerSideRequestForgery
OutOfBandDetection
Writeup
WorkInProgress
Oct 16, 2025
PortSwigger Lab: Stored XSS into anchor href attribute with double quotes HTML-encoded
PortSwigger
WebSecurity
Writeup
CrossSiteScripting
StoredXSS
XSS
HTMLEscape
Oct 14, 2025
PortSwigger Academy - Exploiting LLM APIs with excessive agency
PortSwigger
WebSecurity
LargeLanguageModel
Writeup
Oct 14, 2025
PortSwigger Lab: Username enumeration via different responses
BurpSuite
PortSwigger
AuthenticationVulnerabilities
Writeup
UsernameEnumeration
PasswordEnumeration
BruteForce
Enumeration
Oct 14, 2025
PortSwigger Lab: Username enumeration via subtly different responses
PortSwigger
BurpSuite
WebSecurity
Writeup
AuthenticationVulnerabilities
Enumeration
UsernameEnumeration
PasswordEnumeration
BruteForce
Oct 14, 2025
PortSwigger Lab: Remote code execution via polyglot web shell
PortSwigger
BurpSuite
RemoteCodeExecution
Writeup
ExifTool
PHP
WebShell
Oct 14, 2025
PortSwigger Lab: Remote code execution via web shell upload
PortSwigger
WebShell
RemoteCodeExecution
Writeup
PHP
BurpSuite
Oct 14, 2025
PortSwigger Lab: Web shell upload via extension blacklist bypass
PortSwigger
Writeup
WebShell
ApacheWebServer
PHP
BurpSuite
HTACCESS
Oct 14, 2025
PortSwigger Lab: Web shell upload via obfuscated file extension
PortSwigger
Writeup
WebShell
PHP
BurpSuite
Obfuscated
Oct 14, 2025
PortSwigger Lab: Basic SSRF against another back-end system
PortSwigger
BurpSuite
Writeup
ServerSideRequestForgery
Oct 14, 2025
PortSwigger Lab: SSRF with blacklist-based input filter.
PortSwigger
BurpSuite
ServerSideRequestForgery
Writeup
Oct 14, 2025
PortSwigger Lab: SSRF with filter bypass via open redirection vulnerability
PortSwigger
BurpSuite
Writeup
ServerSideRequestForgery
OpenRedirectionVulnerability
Oct 14, 2025
PortSwigger Lab: DOM XSS in AngularJS expression with angle brackets and double quotes HTML-encoded
PortSwigger
WebSecurity
XSS
CrossSiteScripting
DOMXSS
Writeup
WorkInProgress
Oct 14, 2025
PortSwigger Lab: DOM XSS in jQuery anchor href attribute sink using location.search source
PortSwigger
WebSecurity
DOMXSS
XSS
CrossSiteScripting
JQuery
WindowLocationSearch
Writeup
Oct 14, 2025
PortSwigger Lab: DOM XSS in jQuery selector sink using a hashchange event
PortSwigger
WebSecurity
CrossSiteScripting
XSS
DOMXSS
Writeup
Oct 14, 2025
PortSwigger Lab: DOM XSS in document.write sink using source location.search inside a select element
WorkInProgress
PortSwigger
WebSecurity
XSS
CrossSiteScripting
DOMXSS
Writeup
Oct 14, 2025
PortSwigger Lab: Reflected DOM XSS
PortSwigger
WebSecurity
DOMXSS
XSS
ReflectedXSS
CrossSiteScripting
WorkInProgress
Writeup
Oct 14, 2025
PortSwigger Lab: Reflected XSS into HTML context with nothing encoded
PortSwigger
Writeup
CrossSiteScripting
XSS
ReflectedXSS
Oct 14, 2025
PortSwigger Lab: Reflected XSS into attribute with angle brackets HTML-encoded
PortSwigger
WebSecurity
ReflectedXSS
XSS
CrossSiteScripting
Writeup
Sep 02, 2025
HackTheBox - nibbles
HackTheBox
Writeup
Nmap
NetCat
Sep 02, 2025
HackTheBox Writeup - getting started public exploit
HackTheBox
Writeup
Metasploit
WordPress
Sep 02, 2025
HackTheBox Writeup - getting started web enumeration
HackTheBox
Writeup
WordPress
WebEnumeration
GoBuster
WhatWeb