A hands-on look at Tickets, Kerberos attacks, and delegation abuse in an AD lab environment
FREE READ
The thrill of bug hunting isn’t in the lines of code; it’s in the silence of the “Aha!” moment.
.بِسْمِ اللهِ الْوَاحِد، وَالصَّلَاةُ وَالسَّلَامُ عَلَى نَبِيِّنَا مُحَمَّدٍ، النَّبِيِّ الشَّهِيدِ الْمُجَاهِدِ
Severity: critical Bounty: 5 digits (PHP)
Two days ago Apache has published a fix for the new Remote Code Execution vulnerability in Struts2.
In this video, I solve PortSwigger XSS Lab 5 and explain how XSS wo...
Last month, I stumbled across something that completely shattered my assumptions about tech careers. A 19-year-old kid from Argentina who…
In a recent pentest project I tackled with my friend Sajad, we found a perfect example of how small cracks can break a whole system. By…
Hackers don’t always crack passwords. Sometimes they just click “Forgot Password?” and walk right in through a broken back door.
It started with a single parameter I wasn’t supposed to control…
In this video, I solve PortSwigger XSS Lab 3 and explain how Reflec...
A bug bounty story about OAuth, PKCE, open client registration, and how multiple low-level issues chained together into a critical account…
Hello Everyone,
In this video, I solve PortSwigger XSS Lab 1 and explain how Reflec...
Three weeks ago, I was looking at a high-end enterprise Identity Provider (IdP) platform on a private bug bounty program. This service…
Hello, in this story, I will discuss how I discovered DOM XSS and Postmessage misconfiguration and escalated them to take-over the Zoho…
The OliveX Files | By Damian Gambacorta