Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter
XSS Polyglot

From 0 to pentesting hero

XSS Polyglot

A polyglot is a person who speaks many languages. But the term matters also in contex of security issues.

08-08-2019

4 MIN READ

postMessage

From 0 to pentesting hero

postMessage

A functionality that allows you to exchange data between different domains.

30-07-2019

2 MIN READ

Cross-Site Websocket Hijacking

From 0 to pentesting hero

Cross-Site Websocket Hijacking

Not so long ago, to make website's content appear in real time it had to be kind of simulated. For example from the level of JavaScript - by sending a request to the server every few seconds and downloading the latest content.

24-07-2019

4 MIN READ

Don't use assert in PHP

From 0 to pentesting hero

Don't use assert in PHP

Why you shouldn't pass variables to assert function in PHP.

02-07-2019

6 MIN READ

Clickjacking

From 0 to pentesting hero

Clickjacking

How to convince the user to delete his account on the website without his consent?

17-04-2019

3 MIN READ

Open redirection

From 0 to pentesting hero

Open redirection

We are used to the fact that websites contain links to another web services. But, can automatic redirection to external domain be harmful?

09-04-2019

3 MIN READ

Reflected File Download

From 0 to pentesting hero

Reflected File Download

Can you expand the potential attack vector for a larger number of applications?

03-04-2019

3 MIN READ

CSV Injection

From 0 to pentesting hero

CSV Injection

It may be found on every website that allows for exporting data to CSV format. But how the text format can be used for the attack?

27-03-2019

2 MIN READ

© 2022 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter