Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter

Ctf

Confidence Dragonsector CTF - Zippy Web 300 Writeup

Solution for Zippy task from Confidence Dragonsector CTF.

12-03-2020

3 MIN READ

Kallithea - exploit git clone functionality

From 0 to pentesting hero

Kallithea - exploit git clone functionality

4 little bugs in the Kallithea software that make it possible to access someone else's data.

17-02-2020

3 MIN READ

PHP PHAR - file_exists can be dangerous

From 0 to pentesting hero

PHP PHAR - file_exists can be dangerous

file_exists - a function that checks if a file with the given name exists on the hard drive. Could such a simple functionality be harmful?

10-02-2020

3 MIN READ

How to login into multiple SSH servers

From 0 to pentesting hero

How to login into multiple SSH servers

Do you work with a lot of linux servers? Do you log in to each of them using your ssh key? On the one hand, you would like to change it more often, but on the other, the overwhelming amount of work associated with changing certificates on many servers discourages you? In today's episode of 'from 0 to pentesting hero', we will take a look at how Netflix solved this problem.

04-02-2020

3 MIN READ

Spring Boot Actuator - security point of view

From 0 to pentesting hero

Spring Boot Actuator - security point of view

Spring Boot Actuator is a tool that allows us to monitor our application built with spring. We can quickly measure various metrics and monitor traffic on our server or check the status of our database. All this thanks to simple rest endpoints.

28-01-2020

2 MIN READ

BURP - Intruder

From 0 to pentesting hero

BURP - Intruder

You want to check which of them belong to the administrators and which are the accounts of ordinary users. Unfortunately, the account type is displayed on a different subpage than the one returned by the server after logging in.

21-01-2020

3 MIN READ

How to handle session expiration in BURP with macros?

Burp_en

How to handle session expiration in BURP with macros?

To send requests, you use the Repeater tool built into the Burp. Unfortunately, the session lifetime on the site is set to a very low value. You are logged out way too often. You must log in again to continue your work.

12-01-2020

2 MIN READ

12 tricks for Burp Repeater

Burp_en

12 tricks for Burp Repeater

Repeater is one of the most frequently used part of Burp Suite. But there is plenty of hidden features there. Do you know all of them?

06-01-2020

3 MIN READ

© 2022 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter