unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
My eJPTv2 Journey — 82%
Ever since I was in 11th standard, I’ve been deeply curious about computers — how they work, how sys...
2026-7-27 09:39:44 | 阅读: 5 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
ejptv2
preparation
handwritten
exams
Unauthenticated Disclosure of A/B Test Data in Convert Pro — How Two Forgotten AJAX Endpoints…
Press enter or click to view image in full sizeThis is a write-up of a vulnerability I independently...
2026-7-27 09:38:59 | 阅读: 4 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
convertpro
wpdb
wp
variation
Unauthenticated Disclosure of A/B Test Data in Convert Pro — How Two Forgotten AJAX Endpoints…
Press enter or click to view image in full sizeThis is a write-up of a vulnerability I independently...
2026-7-27 09:38:59 | 阅读: 4 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
convertpro
wpdb
wp
variation
One Header Away from 10+ GB of Customer Documents (PII) — $6K Bounty
Press enter or click to view image in full sizeSample Document LeakedAn anonymous attacker could ful...
2026-7-27 09:38:35 | 阅读: 6 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
tos
anonymous
prod
volces
volcengine
One Header Away from 10+ GB of Customer Documents (PII) — $6K Bounty
Press enter or click to view image in full sizeSample Document LeakedAn anonymous attacker could ful...
2026-7-27 09:38:35 | 阅读: 14 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
tos
anonymous
prod
volcengine
cloud
How I Found a Bug Worth $3,500 — In a Feature Nobody Was Watching.
A storage-exhaustion flaw. A stored XSS that waited for an admin. Both hiding in the same “boring” f...
2026-7-27 09:37:44 | 阅读: 5 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
boring
payload
fires
vishw
security
How I Found a Bug Worth $3,500 — In a Feature Nobody Was Watching.
A storage-exhaustion flaw. A stored XSS that waited for an admin. Both hiding in the same “boring” f...
2026-7-27 09:37:44 | 阅读: 3 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
boring
payload
fires
vishw
waited
Unprotected admin functionality with unpredictable URL — PortSwigger Access Control Lab 2
Finding ID: BAC-Portswigger-002Title: Unprotected admin functionality with unpredictable URLRisk (Se...
2026-7-27 09:36:25 | 阅读: 4 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
security
client
a01
LetsDefend: SOC169 — Possible IDOR Attack Detected (Walkthrough)
Investigating an IDOR Vullneron a WebServerAlert Overview|--------------------|---------------------...
2026-7-27 09:36:11 | 阅读: 3 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
idor
attacker
sizes
malicious
LetsDefend Challenge: Memory Analysis (Walkthrough)
Analysing Memory Dump extracted from a compromised Windows HostPress enter or click to view image in...
2026-7-27 09:36:5 | 阅读: 4 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
windows
memory
vol
dumped
malicious
VulnNet: Roasted Tryhackme ctf walkthrough
VulnNet Entertainment just deployed a new instance on their network with the newly-hired system admi...
2026-7-27 09:31:45 | 阅读: 3 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
microsoft
windows
msrpc
cpe
privileges
Pickle Rick Tryhackme CTF
This Rick and Morty-themed challenge requires you to exploit a web server and find three ingredients...
2026-7-27 09:31:38 | 阅读: 3 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
reverse
robots
ingredient
python3
rick
Tryhackme New Room — FLIP
Here’s a link to the room: https://tryhackme.com/room/flipTASK [1] Source CodeFirst, go ahead and re...
2026-7-27 09:30:14 | 阅读: 3 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
username
ciphertext
sup3rpass1
f3
How I Found an Auth Flaw in a Government Site: From GraphQL Introspection to Unauthorized Access
Press enter or click to view image in full sizeDisclaimer:This write-up describes a vulnerability th...
2026-7-27 09:24:22 | 阅读: 4 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
security
1host
How a Simple Profile Update Led to Cross-Tenant Data Exposure
Free Article Link: Click for free!Press enter or click to view image in full sizeFor responsible dis...
2026-7-27 09:23:41 | 阅读: 10 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
security
suggested
panels
lesson
How to deploy File Integrity Monitoring with Wazuh SIEM!
File Integrity MonitoringPress enter or click to view image in full sizeFile integrity monitoring (F...
2026-7-22 19:3:32 | 阅读: 17 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
wazuh
monitoring
security
cyberattack
Two Ways To Mess Up Your JWT Safety Net In Your Own Lab.
Press enter or click to view image in full sizeIn the lab we’re going to build today, we’ll talk abo...
2026-7-22 18:50:13 | 阅读: 19 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
payload
username
security
getcookie
AllSignsPoint2Pwnage — TryHackMe Windows Write-up
AllSignsPoint2Pwnage is a Windows-based room on TryHackMe that requires the user to enumerate open S...
2026-7-22 10:48:4 | 阅读: 13 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
windows
php
vnc
microsoft
sizei
PortSwigger Lab Writeup — Bypassing AI scanner defenses to exfiltrate sensitive information
Author: Raghav VivekanandanIntroductionThe PortSwigger Web Security Academy lab “Bypassing AI Scanne...
2026-7-22 10:47:9 | 阅读: 18 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
defenses
injection
raghav
payload
security
Device Code Phishing: How Attackers Abuse Microsoft’s Legitimate Authentication Page Without…
Press enter or click to view image in full sizeThe most convincing Microsoft phishing attack yet. Le...
2026-7-18 09:24:57 | 阅读: 23 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
microsoft
phishing
victim
stage
Previous
-140
-139
-138
-137
-136
-135
-134
-133
Next