unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
The $0 IDOR That Was Worth More Than a $12,500 P1
2026-7-17 07:4:55 | 阅读: 9 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
How I Detected an Insider Threat in Splunk When Every Single Action Looked Legitimate
No broken password. No exploit. No firewall alert. Just an employee using access they were supposed...
2026-7-17 07:4:43 | 阅读: 19 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
stage
powershell
fin
windows
workstation
Lab 2 : Information Disclosure on a Debug Page
The VulnerabilityDebug pages are a common byproduct of development. Tools like phpinfo() are incredi...
2026-7-17 07:4:3 | 阅读: 8 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
burp
clicked
php
zeyad
repeater
TryHackMe — Linux Agency | Complete Write-Up & Walkthrough
2026-7-17 06:50:44 | 阅读: 7 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
mission
gtfobins
ssh
robert
python
Host & Network Penetration Testing: Exploitation CTF 3 — eJPT (INE)
A walkthrough covering ProFTPD mod_copy exploitation, local service banner grabbing, SMB brute-force...
2026-7-17 06:50:3 | 阅读: 13 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
ine
target2
target1
proftpd
nmap
Lookup: TryHackMe CTF Walkthrough
Lab link: https://tryhackme.com/room/lookupTitle: Test your enumeration skills on this boot-to-root...
2026-7-7 11:36:26 | 阅读: 31 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
username
thm
pwm
ssh
machine
JWTweak v2.1: A Guided, Offline Toolkit for Modern JWT Attacks
Paste a token, get a full attack plan — then execute it, entirely offline.JSON Web Tokens sit at the...
2026-7-7 11:35:53 | 阅读: 27 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
powers
sit
gap
scores
No Rules, No Locks: Firebase Misconfiguration and the Borrowers It Left Behind
Press enter or click to view image in full sizeFirebase security rules are opt-in. The default, for...
2026-7-7 11:35:41 | 阅读: 28 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
firebase
loan
firestore
stringvalue
googleapis
The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration.
A POST to IMDS may fail — but a redirect can quietly turn it into something else.This writeup docume...
2026-7-7 11:35:22 | 阅读: 34 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
imds
303
library
client
bigquery
Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…
There’s a browser property called window.name that’s easy to overlook because it behaves differently...
2026-7-7 11:35:7 | 阅读: 26 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
payload
akamai
403
backurl
Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…
There’s a browser property called window.name that’s easy to overlook because it behaves differently...
2026-7-7 11:35:7 | 阅读: 25 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
payload
akamai
403
backurl
BadSuccessor — Exploiting delegated Managed Service Accounts in Windows Server 2025
Understanding what is delegated Managed Service Accounts in Windows Server 2025, and how an unpatche...
2026-7-7 11:34:55 | 阅读: 30 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
dmsa
tryhackme
windows
tbyte
sizestep
Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time
OverviewIn this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file sy...
2026-7-6 06:34:23 | 阅读: 21 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
wazuh
monitoring
windows
fim
ossec
Mastering curl Commands Bug Bounty Hunter's Guide
Every bug bounty hunter has curl installed. Few use it to its full potential. While Burp Suite and c...
2026-7-6 06:30:13 | 阅读: 25 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
jq
uthis
shines
security
Mastering curl Commands Bug Bounty Hunter's Guide
Every bug bounty hunter has curl installed. Few use it to its full potential. While Burp Suite and c...
2026-7-6 06:30:13 | 阅读: 26 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
jq
stateless
subdomain
security
Mass Assignment and the Identity Drift: From Profile Edit to Insurance Takeover
Press enter or click to view image in full sizeNo customer support call. No re-verification.Yet the...
2026-7-6 06:29:11 | 阅读: 25 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
insurance
attacker
mass
assignment
birth
Mass Assignment and the Identity Drift: From Profile Edit to Insurance Takeover
Press enter or click to view image in full sizeNo customer support call. No re-verification.Yet the...
2026-7-6 06:29:11 | 阅读: 17 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
insurance
attacker
mass
assignment
birth
The File That Answered Back — XXE Hidden in Cell A2
Press enter or click to view image in full sizeMost people know XXE. Few think to look for it inside...
2026-7-6 06:28:59 | 阅读: 27 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
xlsx
workbook
sheet1
windows
The File That Answered Back — XXE Hidden in Cell A2
Press enter or click to view image in full sizeMost people know XXE. Few think to look for it inside...
2026-7-6 06:28:59 | 阅读: 25 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
xlsx
workbook
windows
sheet1
RCE via Gemini Live AI Voice Session Misconfiguration.
Press enter or click to view image in full sizeSource: https://ai.google.dev/gemini-api/docs/live-ap...
2026-7-6 06:28:53 | 阅读: 23 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
gemini
client
constraints
bidi
expire
Previous
2
3
4
5
6
7
8
9
Next