unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Hacking JSON Web Tokens: How Attackers Exploit API Authentication
JWTs are trusted by millions of APIs worldwide: yet one small misconfiguration can turn a security f...
2026-5-29 09:15:40 | 阅读: 37 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
rs256
hs256
payload
burp
Cybersploit 1 Walkthrough — OffSec | Beginner Guide & Screenshots
I’m a professional penetration tester with hands-on red-team experience and OSCP-style practice. I t...
2026-5-29 09:15:21 | 阅读: 32 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
37292
ssh
itsskv
robots
flag2
Advanced Client Side Injection Secrets Leads To (SSRF , Prev Esc)
Client-Side Injection(Advanced): How Small Bugs Lead To Big Bounties(SSRF , Prev Esc , KeyLogger , 3...
2026-5-29 09:15:10 | 阅读: 41 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
injection
victim
attacker
postmessage
client
Advanced Client Side Injection Secrets Leads To (SSRF , Prev Esc)
Client-Side Injection(Advanced): How Small Bugs Lead To Big Bounties(SSRF , Prev Esc , KeyLogger , 3...
2026-5-29 09:15:10 | 阅读: 33 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
injection
victim
attacker
postmessage
bypass
How We Bypassed an Axios Security Patch (CVE-2026–42043): The 16-Million IP Loophole
When a patch for a critical vulnerability drops in a library downloaded over 500 million times a wee...
2026-5-29 09:14:46 | 阅读: 38 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
loopback
axios
proxy
attacker
bypass
How We Bypassed an Axios Security Patch (CVE-2026–42043): The 16-Million IP Loophole
When a patch for a critical vulnerability drops in a library downloaded over 500 million times a wee...
2026-5-29 09:14:46 | 阅读: 44 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
loopback
axios
proxy
bypass
attacker
Android Lock Screen Bypass via Google Gemini — The Patch That Wasn’t (Status: Not Fixed)
TL;DR: On a fully patched Pixel 6a running Android 16, an attacker with physical access can escape t...
2026-5-29 09:12:39 | 阅读: 43 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
gemini
overlay
bypass
security
“Bug Bounty Bootcamp #40: XXE — Reading Server Files and Pivoting to Internal Networks Through XML”
That innocent XML import feature could be a direct line to your /etc/passwd and internal cloud metad...
2026-5-28 12:15:44 | 阅读: 39 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
ssrf
remote
pulls
lesson
featurexml
“Bug Bounty Bootcamp #40: XXE — Reading Server Files and Pivoting to Internal Networks Through XML”
That innocent XML import feature could be a direct line to your /etc/passwd and internal cloud metad...
2026-5-28 12:15:44 | 阅读: 38 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
ssrf
remote
pulls
friend
weaponize
“Bug Bounty Bootcamp #39: PDF SSRF and Blind Exfiltration — When Headless Browsers Become Your Data…
The invoice generator doesn’t show errors. The image fetcher hangs on invalid IPs. But with a single...
2026-5-28 12:12:0 | 阅读: 45 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
ssrf
inject
headless
exfiltrate
hangs
“Bug Bounty Bootcamp #39: PDF SSRF and Blind Exfiltration — When Headless Browsers Become Your Data…
The invoice generator doesn’t show errors. The image fetcher hangs on invalid IPs. But with a single...
2026-5-28 12:12:0 | 阅读: 45 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
ssrf
headless
inject
princexml
tackle
Extending Wazuh detection capabilities with clickdetect, Opensearch PPL and Sigma Rules
Hey, souzo here. If you’ve ever wanted alerting rules that actually work in Wazuh without fighting O...
2026-5-28 12:9:11 | 阅读: 41 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
opensearch
sigma
wazuh
clickdetect
runner
Built Pentest Environment On Your Mac Using Docker
A Simple and Working Setup for Every Apple Silicon Macs (M1, M2, M3, M4, M5)Press enter or click to...
2026-5-28 12:6:17 | 阅读: 46 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
silicon
macs
chip
macbooks
chips
I Found Root Access on Critical Financial Infrastructure Using a Two-Day-Old Kernel Exploit
My name is Hamza Hashim. I’m an offensive security researcher and if you’ve followed my work before,...
2026-5-28 12:4:52 | 阅读: 46 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
jenkins
sitting
github
frag
security
Intercepting Docker Application Requests Using Burp Suite on Windows
Press enter or click to view image in full sizeIntercepting Docker Application Requests Using Burp S...
2026-5-28 12:4:28 | 阅读: 50 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
burp
proxy
windows
wsl2
containers
How a GraphQL Invitation Flow Exposed Users at Scale
Press enter or click to view image in full sizeA normal invite feature revealed registered accounts,...
2026-5-28 11:55:16 | 阅读: 42 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
invite
invitation
overly
readers
identifiers
How a GraphQL Invitation Flow Exposed Users at Scale
Press enter or click to view image in full sizeA normal invite feature revealed registered accounts,...
2026-5-28 11:55:16 | 阅读: 41 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
invite
invitation
workflows
exposure
reveals
I Sent You a JPEG. Now I Own Your Mac.
Exploiting ExifTool’s macOS Command Injection Blind Spot (CVE-2026–3102)A JPEG should never execute...
2026-5-28 11:52:19 | 阅读: 39 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
exiftool
injection
2026
3102
pipelines
Prompt Engineering: TryHackMe Walkthrough
Learn how LLMs process text and craft effective prompts for security and adversarial testing, from T...
2026-5-28 11:48:46 | 阅读: 28 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
security
prompts
tryhackme
llm
I Booked a ₹30,000 Conference Ticket for ₹1. The Site Let Me.
A business logic flaw. A Burp Suite intercept. And the first Hall of Fame of my life.Press enter or...
2026-5-28 11:47:46 | 阅读: 40 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
premium
client
burp
discount
fame
Previous
13
14
15
16
17
18
19
20
Next