Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter
Random vs SecureRandom

From 0 to pentesting hero

Random vs SecureRandom

Every service that has a login mechanism should also have the option to reset the password. But how to do it right?

26-02-2019

2 MIN READ

YAML

From 0 to pentesting hero

YAML

A popular opinion says to not use the pickle class on a data given by user because on deserialization it may lead to the object injection attack and malicious code execution.

19-02-2019

2 MIN READ

SSTI - Server-Side Template Injections

From 0 to pentesting hero

SSTI - Server-Side Template Injections

We'll talk about template engines. This time we'll use Python as an example and Flask framework, in which we will use Jinja2.

12-02-2019

2 MIN READ

Bypass PHP filters using less-than sign

From 0 to pentesting hero

Bypass PHP filters using less-than sign

Today we are going to see that the platform on which we run our programs makes a difference and we'll use PHP for this purpose.

05-02-2019

2 MIN READ

Unzip

From 0 to pentesting hero

Unzip

This time, unusually - we are not going to look at a specific programming language but a Linux function - unzip - that is for extracting files.

29-01-2019

2 MIN READ

XXE - XML External Entity

From 0 to pentesting hero

XXE - XML External Entity

Today we are going to search for some vulnerabilitis in the code responsible for XML parsing.

22-01-2019

2 MIN READ

Ruby

From 0 to pentesting hero

Ruby

Today we are going to talk about Ruby language. We'll take a look at a simple implementation of the proxy server.

16-01-2019

2 MIN READ

Why you shouldn’t use input function in Python 2?

From 0 to pentesting hero

Why you shouldn’t use input function in Python 2?

Today's example consists of 2 lines of python code, because usually it's enough to introduce a vulnerability to our application.

09-01-2019

2 MIN READ

© 2022 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter