AArshadinblog.arshadakl.in·6d ago · 6 min readHow a Profile Update Feature Could Drain a Company's Bank AccountI was looking at one of the most normal features you can find in almost any application: Update Profile. Nothing exciting. A user changes their name, profile picture, maybe email, and the backend upda00
SSunnyincybersecurity-learning.hashnode.dev·Aug 26 · 10 min readTryHackMe Broken Access Control Room: Comprehensive Learning Guide & Deep DiveIntroduction I recently completed the Broken Access Control room on TryHackMe as part of my ongoing cybersecurity learning journey. Consistently ranked as the #1 vulnerability in the OWASP Top 10, Bro00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 25 · 11 min readHackSmarter - Casino WriteupSummary Casino is a Flask-based "Guest WiFi & Portal" resort captive portal. A leaked JS source-map exposes an unauthenticated internal API endpoint (/api/v1/rooms/status) that dumps the entire guest 00
SSunnyincybersecurity-learning.hashnode.dev·Aug 11 · 11 min readTryHackMe Corridor Beginner-Friendly Learning GuideIntroduction I recently completed the Corridor room on TryHackMe as part of my ongoing cybersecurity learning journey. This was a short room, but it introduced an important web application security co00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 13 · 8 min readHackTheBox: NeoVault Challenge WriteupSummary NeoVault is a small banking app (Next.js frontend + REST API) that lets users register, transfer funds, and download PDF statements. The API ships in two parallel versions, v1 and v2. v2 patch00
JJebitokinsharonjebitok.com·Jun 26 · 61 min readToken City - AI Odyssey CTF (TryHackMe)Link to the section of the AI Odyssey CTF on TryHackMe: Token City. It covers challenges like: ML Sec: The Loan Arranger | AI Sec + DFIR: Rogue Commit | AI Sec + Web App Sec: Sealed Substation | Agent01S
AAAmanda Alleninamandaallen.hashnode.dev·Jun 8 · 4 min readWhy Broken Access Control Continues to Dominate Web Application Security in 2026Web application security has evolved significantly over the last decade. Organizations invest heavily in security testing, secure development practices, cloud security, and automated scanning. Yet one10
MBMouhamed Ben Abdallahinerinmin-writeups.hashnode.dev·May 12 · 8 min readUnprotected Admin FunctionalityPlatform: PortSwigger Web Security Academy Category: Access Control / Vertical Privilege Escalation Difficulty: Apprentice Tool(s): Browser only Date: 12/05/2026 Overview This lab demonstrates a ver00
WBWiktoria Blomgren Strandberginpentesting-dvwa.hashnode.dev·Mar 8 · 14 min readAuthorisation Bypass in DVWA1 Introduction In this post, the Authorisation Bypass vulnerability in the Damn Vulnerable Web Application (DVWA) is described. The objective for attacks on all levels is to identify any areas where a00
CSCyenetic Solutions Ltdincyenetic.hashnode.dev·Feb 24 · 4 min readThe no. 1 OWASP Web Security Risk in 2025-2026: How Broken Access Control Can Destroy Your Business & Revenue (And How to Stop It)As a Business Owner, you probably don't spend your days thinking about code vulnerabilities. You're focused on growth, customers, revenue, and staying ahead of competitors. ![Image](data:image/png;bas00