DSDoogal Simpsonindoogal.dev·21h ago · 5 min readHow to Prevent SQL Injection with Parameterized QueriesQuick Answer: SQL injection attacks exploit vulnerabilities in how web applications construct database queries. By sending malicious SQL code through user input fields (like search bars), attackers ca00
Ddamienanon14ininfinitedomain.hashnode.dev·Jul 26 · 4 min readMy First SQL InjectionI've been building up to this one for a while. Out of everything I've worked through in the lab so far, SQL injection is the attack that actually made cybersecurity feel real to me, not because it's f00
AAbhinavinlog.page0.dev·Jul 15 · 2 min readLAB #04 Basic password reset poisoningLab Overview This lab is vulnerable to password reset poisoning. The user carlos will carelessly click on any links in emails that he receives. To solve the lab, log in to Carlos's account. You can lo00
JJebitokinsharonjebitok.com·Jul 14 · 24 min readBroken Authentication (TryHackMe)Link to the challenge/walkthrough on TryHackMe: Broken Authentication Introduction Authentication is the process by which a web application verifies the identity of the user making a request. It typic00
JJebitokinsharonjebitok.com·Jul 14 · 27 min readModern Web Stacks (TryHackMe)Link to the challenge on TryHackMe: Modern Web Stacks Introduction During a time-boxed engagement, the first tester to identify Apache/2.4.49 in a Server: header already knows the exact CVE before the00
DIDaniel Isaac Eindanielisaace.hashnode.dev·Jul 13 · 5 min readStop Trusting Your WAF: Modern Attackers Have Already Moved OnIntroduction For years, Web Application Firewalls (WAFs) have been marketed as one of the most important security controls for protecting web applications. Organizations invest heavily in WAF solution10
JJJeji Jamesinjeji-james.hashnode.dev·Jul 10 · 2 min readLinux Log Fortress — Access Control & Threat Pattern DetectionIn a real SOC environment, a log file is forensic evidence. Before you can analyze it, you need to protect it. This lab walks through the full workflow from locking down file permissions to hunting fo00
VMVimal Mudalagiinvimalmudalagi.hashnode.dev·Jul 7 · 9 min readLearning Web Security #1: Broken Access Control (OWASP Top 10 #1 - Beginner's Guide)Disclaimer: I'm currently learning web security through PortSwigger Web Security Academy. These are my beginner-friendly notes rewritten as a blog to help reinforce my understanding. If you're just st00
AAbhinavinlog.page0.dev·Jul 6 · 4 min readLAB #01 SSRF via OpenID dynamic client registrationLab Overview This lab allows client applications to dynamically register themselves with the OAuth service via a dedicated registration endpoint. Some client-specific data is used in an unsafe way by 10
RRelayShieldAdmininrelayshield.hashnode.dev·Jun 15 · 4 min readOnyxC2: When $250/Month Buys Everything on Your Employees' DevicesA new Malware-as-a-Service platform called OnyxC2 just raised the stakes for every SMB owner with remote workers. For $250 a month a criminal gets a fully operational credential-theft and remote-acces00