unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
I Found the Entire Admin UI of a Live PlatformJust By Tweaking Traffic in Burp Suite
Hey, I’m Hamza Hashim. On socials I am known as refang. I write about real bugs I find out in the wi...
2026-6-9 08:46:28 | 阅读: 29 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
intern
burp
grader
enrolled
privileged
Host & Network Penetration Testing: System-Host Based Attacks CTF 2 — eJPT (INE)
A beginner-friendly walkthrough covering Shellshock exploitation, libssh authentication bypass, and...
2026-6-9 08:45:36 | 阅读: 34 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
ine
target1
greetings
nmap
shellshock
How GraphQL Mutation Aliasing Led to a $12,500 DoS Bug in HackerOne’s Account Recovery Flow
Press enter or click to view image in full sizeA small GraphQL behavior created a very real availabi...
2026-6-9 08:45:17 | 阅读: 32 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
hackerone
hunters
reporter
mutation
How GraphQL Mutation Aliasing Led to a $12,500 DoS Bug in HackerOne’s Account Recovery Flow
Press enter or click to view image in full sizeA small GraphQL behavior created a very real availabi...
2026-6-9 08:45:17 | 阅读: 31 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
hackerone
hunters
security
idors
sizea
SQL Injection in Password Reset: Full Database, One Email
A ukey token in a forgot-password email handed me full read access to every record in their database...
2026-6-9 08:42:43 | 阅读: 33 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
database
php
ukey
sqlmap
forgot
SQL Injection in Password Reset: Full Database, One Email
A ukey token in a forgot-password email handed me full read access to every record in their database...
2026-6-9 08:42:43 | 阅读: 33 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
php
database
ukey
forgot
sqlmap
LFI Escalation Lab Writeup [CyberDefenders]
You can read this writeup on my GitBook account LinkScenarioIT staff reported unusual behavior on a...
2026-6-9 08:42:13 | 阅读: 27 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
payload
powershell
database
mft
GreyCTF 2026 — Crimewatch Forensics Challenge Writeup
We are provided with 2 weird files named "a" and "b", and a python file as shown:the below screen sh...
2026-6-9 08:42:0 | 阅读: 20 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
sizeso
coordinates
weird
ftk
sizeafter
Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide
Estimative language, evidence discipline, and analytic integrity for cyber threat intelligencePress...
2026-6-8 04:31:26 | 阅读: 84 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
attribution
analysis
cti
analytic
kent
Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana
11 validated detections from public sources, OpenCTI graph, and a one-command labTable of ContentsPr...
2026-6-8 04:31:1 | 阅读: 64 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
muddywater
mw
det
opencti
sysmon
CTI as a Code: Complete Step-by-Step Methodology
Version-controlled threat intelligence — from first call to deployed Sigma rule.Press enter or click...
2026-6-8 04:30:49 | 阅读: 52 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
pir
proj
gap
contractor
det
CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma
A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP the...
2026-6-8 04:30:34 | 阅读: 48 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
cfo
levi
c2
rd
203
ThreatMapper: I Built a Self-Hosted AI Threat Intelligence Platform — Here’s How to Use It
Map adversary behaviour to MITRE ATT&CK in seconds, compare against 160+ APT groups, and generate PD...
2026-6-8 04:30:9 | 阅读: 92 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
analysis
navigator
ttp
llm
OSCP Windows Enumeration Checklist: My Complete Privilege Escalation Workflow for Every Box
By Got Root? | https://medium.com/@got-rootPress enter or click to view image in full sizeOSCP windo...
2026-6-8 04:26:28 | 阅读: 46 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
windows
oscp
spending
motivates
scattered
JavaScript Prototype Pollution Deep Dive : — Reconnaissance, Exploitation & Bug Bounty Guideline
From Recon to RCE — A comprehensive deep-dive into one of JavaScript’s most misunderstood vulnerabil...
2026-6-8 04:26:8 | 阅读: 39 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
polluted
pollution
qs
isadmin
payload
The Most Dangerous Security Bug Is the One That Feels Like a Feature
A single click should not carry the weight of your entire developer identity.There is a particular k...
2026-6-7 14:47:28 | 阅读: 27 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
repository
feels
security
friction
developer
The 5 Skills Every Cybersecurity Engineer Needs in 2026 (That Universities Still Aren’t Teaching)
A friend of mine runs security hiring at a mid-sized fintech. Last year he told me about two finalis...
2026-6-7 14:47:23 | 阅读: 25 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
hiring
friend
security
diploma
Update: The Ending of My $500 Loss and Web Cache Poisoning Story.
The Account Was Eventually Deactivated.Over the following weeks, I started receiving multiple paymen...
2026-6-7 14:46:53 | 阅读: 36 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
deactivated
charge
sizeproof
refund
contacted
Update: The Ending of My $500 Loss and Web Cache Poisoning Story.
The Account Was Eventually Deactivated.Over the following weeks, I started receiving multiple paymen...
2026-6-7 14:46:53 | 阅读: 26 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
deactivated
charge
sizeproof
refund
contacted
SPIP RCE + Docker SUID Escape | THM Publisher
Hello Friend,Welcome to another TryHackMe challenge PublisherStep 1 — Nmap ReconnaissanceWe begin wi...
2026-6-7 14:46:43 | 阅读: 37 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
ssh
spip
remote
whatweb
nmap
Previous
9
10
11
12
13
14
15
16
Next