Haft
Search
Search
Dark mode
Light mode
Explorer
Tag: Write-ups
37 items with this tag.
Dec 10, 2025
DOM XSS in jQuery selector sink using a hashchange event
Write-ups
Labs
Portswigger
Nov 18, 2025
Cypher
Write-ups
HTB
Linux
Nov 18, 2025
GetSimple
Write-ups
HTB
Linux
Nov 18, 2025
Nibbles
Write-ups
HTB
Linux
Nov 18, 2025
CSRF vulnerability with no defenses
Write-ups
Labs
Portswigger
Nov 18, 2025
CSRF where Referer validation depends on header being present
Write-ups
Labs
Portswigger
Nov 18, 2025
CSRF where token is duplicated in cookie
Write-ups
Labs
Portswigger
Nov 18, 2025
CSRF where token is not tied to non-session cookie
Write-ups
Labs
Portswigger
Nov 18, 2025
CSRF where token is not tied to user session
Write-ups
Labs
Portswigger
Nov 18, 2025
CSRF where token validation depends on request method
Write-ups
Labs
Portswigger
Nov 18, 2025
CSRF where token validation depends on token being present
Write-ups
Labs
Portswigger
Nov 18, 2025
CSRF with broken Referer validation
Write-ups
Labs
Portswigger
Nov 18, 2025
SameSite Lax bypass via cookie refresh
Write-ups
Labs
Portswigger
Nov 18, 2025
SameSite Lax bypass via method override
Write-ups
Labs
Portswigger
Nov 18, 2025
SameSite Strict bypass via client-side redirect
Write-ups
Labs
Portswigger
Nov 18, 2025
SameSite Strict bypass via sibling domain
Write-ups
Labs
Portswigger
Nov 18, 2025
DOM based Open Redirection
Write-ups
Labs
Portswigger
Nov 18, 2025
Routing-based SSRF
Write-ups
Labs
Portswigger
Nov 18, 2025
SSRF via flawed request parsing
Write-ups
Labs
Portswigger
Nov 18, 2025
Authentication bypass via OAuth implicit flow
Write-ups
Labs
Portswigger
Nov 18, 2025
Basic SSRF against another back-end system
Write-ups
Labs
Portswigger
Nov 18, 2025
Basic SSRF against the local server
Write-ups
Labs
Portswigger
Nov 18, 2025
Blind SSRF with out-of-band detection
Write-ups
Labs
Portswigger
Nov 18, 2025
Blind SSRF with Shellshock exploitation
Write-ups
Labs
Portswigger
Nov 18, 2025
SSRF with blacklist-based input filter
Write-ups
Labs
Portswigger
Nov 18, 2025
SSRF with filter bypass via Open redirection vulnerability
Write-ups
Labs
Portswigger
Nov 18, 2025
SSRF with whitelist-based input filter
Write-ups
Labs
Nov 18, 2025
Cross-site WebSocket hijacking
Write-ups
Labs
Portswigger
Nov 18, 2025
Manipulating WebSocket messages to exploit vulnerabilities
Write-ups
Labs
Portswigger
Nov 18, 2025
DOM XSS in document.write sink using source location.search inside a select element
Write-ups
Labs
Portswigger
Nov 18, 2025
DOM XSS in document.write sink using source location.search
Write-ups
Labs
Portswigger
Nov 18, 2025
DOM XSS in inner.html sink using source location.search
Write-ups
Labs
Portswigger
Nov 18, 2025
DOM XSS in jQuery anchor href attribute sink using location.search source
Write-ups
Labs
Portswigger
Nov 18, 2025
Reflected XSS into HTML context with nothing encoded
Write-ups
Labs
Portswigger
Nov 18, 2025
Stored XSS into HTML context with nothing encoded
Write-ups
Labs
Portswigger
Nov 18, 2025
Exploiting XXE to perform SSRF attacks
Write-ups
Labs
Portswigger
Nov 14, 2025
Understanding Block-level encryption on Linux
LUKS
cryptography
Write-ups