unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Device Code Phishing: How Attackers Abuse Microsoft’s Legitimate Authentication Page Without…
Press enter or click to view image in full sizeThe most convincing Microsoft phishing attack yet. Le...
2026-7-18 09:24:57 | 阅读: 19 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
microsoft
phishing
victim
stage
From SQL Injection to Infrastructure-Level RCE: A PostgreSQL Superuser Compromise
Imagine finding a backdoor that gives you absolute superuser access to a state infrastructure networ...
2026-7-18 09:24:45 | 阅读: 18 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
superuser
vsswb
pjobnumber
silence
From User Enumeration to PII Exposure: Chaining Two APIs Into a $2,000 Bug
Free Article Link: Click for free!Press enter or click to view image in full sizeOne of the biggest...
2026-7-18 09:23:37 | 阅读: 14 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
harmless
reminded
developers
biggest
From User Enumeration to PII Exposure: Chaining Two APIs Into a $2,000 Bug
Free Article Link: Click for free!Press enter or click to view image in full sizeOne of the biggest...
2026-7-18 09:23:37 | 阅读: 16 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
harmless
sizeone
biggest
importantly
How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)
Active Directory SecurityPress enter or click to view image in full sizeGroup Policy Objects (GPOs)...
2026-7-18 09:23:3 | 阅读: 10 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
bloodhound
gpo
chithan
writedacl
writeowner
How I Escalated to Domain Admin Using AD CS (And How to Fix It)
Press enter or click to view image in full sizeWhat is AD CS?Active Directory Certificate Services (...
2026-7-18 09:22:57 | 阅读: 11 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
esc1
certipy
dc1
enrollment
How I AES-Roasted My Active Directory Lab (And How to Fix It)
Press enter or click to view image in full sizeAS-REP Roasting is one of the easiest ways to obtain...
2026-7-18 09:22:46 | 阅读: 11 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
cracked
svc
netexec
goad
eCPPTv3 Review
Almost a year ago, I took the INE’s “eCPPTv3” exam, and here is my honest reviewWhy eCPPT?A year ago...
2026-7-18 09:22:38 | 阅读: 9 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
cpts
ecppt
ecpptv3
advise
comfortable
CallMeOnTheChain — EtherRAT Lab Writeup [CyberDefenders]
You can read this writeup on my GitBook: LinkScenarioSomething is wrong at Maromalix. On February 10...
2026-7-18 09:22:34 | 阅读: 13 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
c2
sizeso
attacker
238
600$ For Stealing Podcasts/Show via RSS Feed Manipulation
2026-7-18 09:22:18 | 阅读: 12 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
itunes
podcasts
famous
inboxjoin
hunters
600$ For Stealing Podcasts/Show via RSS Feed Manipulation
2026-7-18 09:22:18 | 阅读: 7 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
podcasts
itunes
famous
sizehello
ownership
Decoding the Obfuscated Layer: A Playbook Walkthrough of Command-Line Forensics
A full and detailed insight into CLI forensics, going into depth following a TryHackMe labPress ente...
2026-7-18 09:21:20 | 阅读: 9 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
security
payload
analysis
tryhackme
playbook
Zero Credentials, Full Access: Inside a Complete Authorization Failure
Bounty Case Files #01How multiple trust-boundary failures allowed anonymous access to premium functi...
2026-7-17 07:19:36 | 阅读: 11 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
client
openapi
tier
gmv
Zero Credentials, Full Access: Inside a Complete Authorization Failure
Bounty Case Files #01How multiple trust-boundary failures allowed anonymous access to premium functi...
2026-7-17 07:19:36 | 阅读: 14 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
client
openapi
tier
gmv
How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers
Press enter or click to view image in full sizeAuthor: GitHub: alisalive LinkedIn: camalzads Type:...
2026-7-17 07:19:31 | 阅读: 15 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
quiz
answers
academy
php
enrolled
How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers
Press enter or click to view image in full sizeAuthor: GitHub: alisalive LinkedIn: camalzads Type:...
2026-7-17 07:19:31 | 阅读: 14 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
quiz
answers
academy
php
enrolled
Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
TL;DRThis one started from setting up the YouTube app on my PS5. The device authorization grant (RFC...
2026-7-17 07:19:2 | 阅读: 14 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
client
youtube
victim
cloud
2026
SAR 2,629 For Stored XSS via svg Image Leading to ATO
Press enter or click to view image in full sizeREPORT BOUNTYHacking via Pictures: Stored XSS via SVG...
2026-7-17 07:18:36 | 阅读: 11 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
webhook
8c54e2aa
48ec
SAR 2,629 For Stored XSS via svg Image Leading to ATO
Press enter or click to view image in full sizeREPORT BOUNTYHacking via Pictures: Stored XSS via SVG...
2026-7-17 07:18:36 | 阅读: 12 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
webhook
48ec
8c54e2aa
Lab 3 : Source code disclosure via backup files
Just nowLab ObjectiveThe goal of this lab is to locate leaked backup files and extract a hard-coded...
2026-7-17 07:5:38 | 阅读: 7 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
backup
database
coded
robots
naguib
Previous
-2
-1
0
1
2
3
4
5
Next