YPYogeshwar Peelainexploitnotes.hashnode.dev·3d ago · 15 min readTryHackMe - SeaSurfer writeupExecutive Summary The engagement began with a single disclosed virtual host name leaking out of an HTTP response header on the target web server. That one leak unraveled the entire box: it led to a Wo00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 14 · 9 min readHackTheBox : JinjaCareSummary JinjaCare is a Flask-based COVID-19 vaccination verification web app. The intended path chains wkhtmltopdf HTML/local-file injection (via the certificate-generation feature) to disclose the Fl00
WBWiktoria Blomgren Strandberginpentesting-dvwa.hashnode.dev·May 5 · 22 min readFile Inclusion in DVWA1 Introduction In this post, the File Inclusion vulnerability in the Damn Vulnerable Web Application (DVWA) is described. The objective for local file inclusion (LFI) attacks on all levels is to read 00