Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter
Don't use assert in PHP

From 0 to pentesting hero

Don't use assert in PHP

Why you shouldn't pass variables to assert function in PHP.

02-07-2019

6 MIN READ

Clickjacking

From 0 to pentesting hero

Clickjacking

How to convince the user to delete his account on the website without his consent?

17-04-2019

3 MIN READ

Open redirection

From 0 to pentesting hero

Open redirection

We are used to the fact that websites contain links to another web services. But, can automatic redirection to external domain be harmful?

09-04-2019

3 MIN READ

Reflected File Download

From 0 to pentesting hero

Reflected File Download

Can you expand the potential attack vector for a larger number of applications?

03-04-2019

3 MIN READ

CSV Injection

From 0 to pentesting hero

CSV Injection

It may be found on every website that allows for exporting data to CSV format. But how the text format can be used for the attack?

27-03-2019

2 MIN READ

Client Side Template Injection

From 0 to pentesting hero

Client Side Template Injection

Retrieving parameters from the user and later displaying them on the website always carries risk of XSS attack. But can you perform such attack without using the HTML tag?

21-03-2019

3 MIN READ

XSS using SVG file

From 0 to pentesting hero

XSS using SVG file

The functionality of file upload is a key place where we should pay special attention to. If the attacker successfully sends and executes a malicious file, the whole server may be taken over.

12-03-2019

3 MIN READ

escapeshellcmd vs escapeshellarg

From 0 to pentesting hero

escapeshellcmd vs escapeshellarg

Executing system commands on the programming language level sounds like asking for trouble. But how to do it right and safe?

05-03-2019

2 MIN READ

© 2022 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter