InInfoSec Write-upsbyNitin yadav·Aug 8The WAF Blocked My XSS — So I Rotated What It Was ReadingWhat’s up everyone! Nitin here 👋
Panos Sakalakis·Mar 28How I bulk deleted all my Facebook and X posts (and why)I created my Facebook and X accounts when I was young and stupid. I needed a fresh start, but I wasn’t expecting the solution to take so…A response icon3
InInfoSec Write-upsbyAlvin Ferdiansyah·Jun 27Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…One click, eight seconds, nine webhook hits. It started with a single bracket character that broke an Akamai WAF rule.A response icon2
Ahmad Mugh33ra·May 16Escalating Self-Stored XSS to Complete Admin ATOWhy This Target?A response icon1
Pstar7·2d agoMenfess di Apk“X” Bisa Diupload Otomatis, Tapi Kenapa Nggak Bisa Dihapus Otomatis?Tadi aku habis upload menfess di Draft Anak Unpad atau yang biasa disebut DAU. Prosesnya cepat. Tinggal otorisasi akun, top up token, satu…
Jojo Mensah·Sep 13I built an open-source personal web memory for coding agentsI kept saving things I knew I would need later: a GitHub repository, a Reddit answer, a post on X, a useful article, a small code pattern…
Mohammed ElKhateb·Sep 11🔐 One Parameter. One Script Tag. One CVE.> 🧠 TL;DR — I found a reflected XSS in TechStore v1.0. One GET parameter, `id`, gets dropped straight into the page with no encoding and…
Jessica Shrestha·Sep 11Learn Cross Site Scripting (XSS) With Me as a BeginnerLet’s start from learning what XSS actually is, its type such as reflected, stored, DOM based, mutated XSS….wait wait wait what was that?