JJebitokinsharonjebitok.com·6d ago · 20 min readChallenges: Grep (TryHackMe)Challenge on TryHackMe: Grep Introduction TryHackMe's Grep room bills itself as an OSINT challenge under the Red Teaming path, and that framing turned out to be the whole point. Coming into this box e00
PGPred Grayinipqs.hashnode.dev·Aug 30 · 22 min readIPQS False Positive: How a Legitimate New Domain Got a 95 Risk Score A little over two months ago, I registered a domain for personal use. The plan was simple. I wanted a permanent email address based on my last name, something like first@lastname.me. I registered the 00
SGShriganesh Guptain0xshriganeshgupta.hashnode.dev·Aug 30 · 5 min readThe Compliance Trap: Why Developers Need to Stop Hoarding User PIIWhen you're building a project for a weekend hackathon, speed is everything. You spin up a quick database, wire up an authentication or KYC provider, and save every single field they throw back at you00
AYAayush Yadavinaayushyadav.hashnode.dev·Aug 22 · 26 min readWhere the LLM Stops: Deterministic Scoring in an AI-Assisted VAPT PipelineEvery VAPT report ends the same way: a handful of numbers. A CVSS score. A severity label. A priority rank. Sometimes an aggregate risk score. Those are the numbers a remediation team actually acts on20
SSpecsinspecswrites.hashnode.dev·Aug 20 · 32 min readThe Tunnel Is Safe, Not The Destination: HTTPS Demystified The Illusion of Safety Connection is secure. A padlock. The "S" in HTTPS. For decades, these have been signals we trust when browsing the web. I trusted them too, but I never stopped to ask what was a10
MM1Hinm1h.hashnode.dev·Aug 16 · 5 min readBreached Credentials Lead to Admin Account Compromise via stored XSSObjective: Health Smarter is releasing a new portal for patients and employees to manage appointments and healthcare data. You have been hired to perform a full web application penetration test agains10
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·Aug 15 · 6 min readEncoding in Web ApplicationsWeb applications move data constantly—through URLs, form fields, cookies, headers, and API payloads. The catch: many transport mechanisms (especially URLs and HTML) are text-oriented, while real input11Z
VCVictor Chukwuemeka Onwuegbuchuleminvictor-chukwuemeka.hashnode.dev·Aug 14 · 18 min readTLS and Certificates: How Two Strangers Agree on a Secret, and Why Your Browser Trusts AnyoneLast post ended with a promise. We had explained that HTTPS is ordinary HTTP running inside an encrypted tunnel called TLS, Transport Layer Security, and that this tunnel provides confidentiality, int00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 13 min readTryHackMe : Dreaming WriteupSummary Dreaming is a Linux box built around a Pluck CMS install. Brute-forcing the CMS admin login gives access to the admin panel, which is then abused via a known authenticated file-upload RCE (CVE11N
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 15 min readTryHackMe : WhyHackMe writeupSummary WhyHackMe is an medium Linux box that chains a handful of low-friction bugs into root. Anonymous FTP leaks a hint pointing at a pass.txt file that's only reachable from localhost. The blog app10