unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Mastery Hunt: Hidden API Endpoints — A Deep Dive into API Bug Bounty Recon & Exploitation
API security testing is the crown jewel of modern bug bounty hunting. While front-end vulnerabilitie...
2026-6-16 06:52:31 | 阅读: 35 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
swagger
outdir
injection
ffuf
payload
CAT Reloaded CTF — CATF 2025 — DFIR Challenges
2026-6-16 06:52:23 | 阅读: 35 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
windows
microsoft
download
thumbcache
catf
IEEE Victoris 4.0 — CTF 2025 — Finals DFIR Challenges
Press enter or click to view image in full sizeHi, I’m glad to share with you my writeup for solving...
2026-6-16 06:52:10 | 阅读: 23 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
watchdog
gallery
8369
malicious
resident
The Crime Blue Team Lab (CyberDefenders)
ScenarioWe’re currently in the midst of a murder investigation, and we’ve obtained the victim’s phon...
2026-6-16 06:52:3 | 阅读: 23 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
victim
sizeselect
friend
him
flight
Bug Bounty Bootcamp #45: Token?
You found a password reset that leaks the magic token in the API response. Or worse — the devs left...
2026-6-16 06:50:3 | 阅读: 17 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
forcing
resettoken
linkpress
forged
Bug Bounty Bootcamp #45: Token?
You found a password reset that leaks the magic token in the API response. Or worse — the devs left...
2026-6-16 06:50:3 | 阅读: 25 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
burp
grab
resettoken
oops
friend
TryHackMe — Checkmate | Full Walkthrough
OverviewCheckmate is a password-focused lab on TryHackMe that simulates a realistic internal network...
2026-6-16 06:49:16 | 阅读: 24 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
marco
ssh
5002
thm
linpeas
TryHackMe — Break Out The Cage | Full Write-Up
Initial AccessStep 1 — Anonymous FTP & ExfiltrationConnecting to FTP without credentials:ftp 10.48.1...
2026-6-16 06:49:10 | 阅读: 24 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
weston
cage
dads
wall
1001
I Found 3 Critical Vulnerabilities in an AI-Powered SOC Platform — Full Attack Chain
Press enter or click to view image in full sizeDisclosure Notice: This assessment was conducted with...
2026-6-16 06:48:56 | 阅读: 30 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
client
supabase
signup
security
My Instructor Said “You Can’t Get a Shell.” I Got Root. — Full Web Pentest Exam Write-Up
Press enter or click to view image in full sizeDisclosure Notice: This assessment was conducted as a...
2026-6-15 15:17:56 | 阅读: 30 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
flask
ssrf
username
invoice
payload
My Instructor Said “You Can’t Get a Shell.” I Got Root. — Full Web Pentest Exam Write-Up
Press enter or click to view image in full sizeDisclosure Notice: This assessment was conducted as a...
2026-6-15 15:17:56 | 阅读: 29 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
flask
ssrf
username
invoice
payload
Connectors CTF 2025 — DFIR Challenges
Press enter or click to view image in full sizewe got a malicious document file, have macros and oth...
2026-6-15 15:17:14 | 阅读: 26 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
windows
usrclass
microsoft
roaming
metamask
Silent Breach Lab Writeup (CyberDefenders)
You can read this writeup on my GitBook account LinkScenarioThe IMF is hit by a cyber attack comprom...
2026-6-15 15:16:1 | 阅读: 31 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
imf
security
malicious
hxd
IEEE Victoris 4.0 — CTF 2025 — Quals DFIR Challenges
Hi, I’m glad to share with you my writeup for getting first blood in 2/2 DFIR challenges.Press enter...
2026-6-12 07:12:45 | 阅读: 40 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
developer
qr
mhany
username
DVWA Cheat Sheet (Low & Medium)
Damn Vulnerable Web ApplicationBrute Force: Low & MediumPress enter or click to view image in full s...
2026-6-12 07:11:8 | 阅读: 37 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
dvwa
payload
incorrect
burp
DVWA Cheat Sheet (Low & Medium)
Damn Vulnerable Web ApplicationBrute Force: Low & MediumPress enter or click to view image in full s...
2026-6-12 07:11:8 | 阅读: 31 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
dvwa
payload
php
burp
How I Built a SOAR Automation in Microsoft Sentinel That Responds to Attacks Without a Single Click
A Logic App playbook, an automation rule, a real permissions error — and what it taught me about how...
2026-6-12 07:10:39 | 阅读: 37 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
playbook
microsoft
soar
ssh
attacker
Six levels, one lesson: LLMs cannot keep a secret
A hands-on breakdown of GitHub’s Secure Code Game Season 3 and why your system prompt is not a secur...
2026-6-12 07:10:12 | 阅读: 40 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
letters
security
database
llm
7485921
Recovering a Forgotten Password in a Self-Hosted n8n Docker Deployment
Learn how to recover complete access to a self-hosted n8n Docker deployment when password reset emai...
2026-6-12 07:8:44 | 阅读: 30 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
n8n
forgot
sizewhen
sizeinstead
losing
Header Manipulation: Bypasses, Probing, and the Security Audit Nobody Does
Request headers are not metadata. They are inputs, and inputs can be manipulated.Press enter or clic...
2026-6-12 07:8:24 | 阅读: 37 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
security
sw
bypass
httpbin
403
Previous
7
8
9
10
11
12
13
14
Next