Open in app

Sign in

Medium Logo
Write

Sign in

efran
efran

63 followers

Home

Lists

About

Monolithic, Microservice Architectures and Security of JWT Tokens

Before testing a system, we need to understand what it is and why it exists. So, let’s start by explaining what a JWT (JSON Web Token) is…

Nov 11, 2023
Monolithic, Microservice Architectures and Security of JWT Tokens
Monolithic, Microservice Architectures and Security of JWT Tokens
Nov 11, 2023

Hack The Box Academy Privilege Escalation

TASK1: SSH into the server above with the provided credentials, and use the ‘-p xxxxxx’ to specify the port shown above. Once you login…

Oct 6, 2023
1
Hack The Box Academy Privilege Escalation
Hack The Box Academy Privilege Escalation
Oct 6, 2023
1

XSS — DOM XSS in jQuery selector sink using a hashchange event

I started to solving XSS Labs on the PortSwigger. The previous XSS labs were straightforward, but in this example, I needed one more step…

Aug 7, 2023
XSS — DOM XSS in jQuery selector sink using a hashchange event
XSS — DOM XSS in jQuery selector sink using a hashchange event
Aug 7, 2023

XSS — Reflected XSS into a JavaScript string with angle brackets HTML encoded

The solution of the lab was hidden in the source code, and since solving it resembled a bit of puzzle solving, I think it was a very…

Aug 4, 2023
Aug 4, 2023

XXE — Exploiting XXE to retrieve data by repurposing a local DTD

After learning the techniques for exploiting XXE vulnerability, it is time to explore exploiting XXE with a local DTD. This technique…

Jul 28, 2023
XXE — Exploiting XXE to retrieve data by repurposing a local DTD
XXE — Exploiting XXE to retrieve data by repurposing a local DTD
Jul 28, 2023

Host Header Manipulations — Password reset poisoning via dangling markup

I tried several methods but I will cover the solution and the logic of the beyond. The things is happening on the raw part of the mail…

Jul 9, 2023
Host Header Manipulations — Password reset poisoning via dangling markup
Host Header Manipulations — Password reset poisoning via dangling markup
Jul 9, 2023

Host Header Attacks — Web Cache Poisoning via Ambigious Requests

In this example of the portswigger, the lab’s name provices a hint: We will be using caching mechanism and host header attacks.

Jul 8, 2023
Host Header Attacks — Web Cache Poisoning via Ambigious Requests
Host Header Attacks — Web Cache Poisoning via Ambigious Requests
Jul 8, 2023

Bluetooth-Low-Energy(BLE) CTF

Hello! Lately, I’ve become interested in hardware security, and Bluetooth has always fascinated me. In this blog, I won’t explain what BLE…

May 17, 2021
Bluetooth-Low-Energy(BLE) CTF
Bluetooth-Low-Energy(BLE) CTF
May 17, 2021

ServiceNow admin credentials exposed.

After I read the blog post on PostSwigger which is about ServiceNow admin credentials exposed, I began to think about whether all the…

Mar 15, 2021
ServiceNow admin credentials exposed.
ServiceNow admin credentials exposed.
Mar 15, 2021

SSRF with filter bypass via open redirection vulnerability

Explanation of the lab : This lab has a stock check feature which fetches data from an internal system. To solve the lab, change the stock…

Jan 11, 2021
1
SSRF with filter bypass via open redirection vulnerability
SSRF with filter bypass via open redirection vulnerability
Jan 11, 2021
1
efran

efran

63 followers
Following
  • Sam Rothlisberger

    Sam Rothlisberger

  • Erdemstar

    Erdemstar

  • Trendyol Tech

    Trendyol Tech

  • Curious ADHD

    Curious ADHD

  • Ibrahim Akdağ| Ph.D.

    Ibrahim Akdağ| Ph.D.

See all (15)

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech