Shang
Blog šŸ‘Øā€šŸ’»
  • 🌸Introduction
  • šŸ’»WEB SECURITY
    • Research Vulnerability
      • šŸ“²Server-side topics
        • šŸ”API Testing
        • šŸ”Race conditions
        • šŸ”XML external entity (XXE) injection
        • šŸ”Server-side request forgery (SSRF)
        • šŸ”File upload vulnerabilities
        • šŸ”Access control vulnerabilities and privilege escalation
        • šŸ”Business logic vulnerabilities
        • šŸ”OS Command injection
        • šŸ”Directory traversal
        • šŸ”Authentication vulnerabilities
        • šŸ”SQL injection
      • šŸ“±Client-side topics
        • šŸ”DOM-based vulnerabilities
        • šŸ”Cross-origin resource sharing (CORS)
        • šŸ”WebSockets
        • šŸ”Clickjacking (UI redressing)
        • šŸ”Cross-site request forgery (CSRF)
        • šŸ”Cross-site scripting(XSS)
      • šŸŒ€Advanced topics
        • šŸ”Web cache poisoning
        • šŸ”HTTP request smuggling
        • šŸ”Prototype pollution
        • šŸ”Server-side template injection(SSTI)
        • šŸ”Insucure deserialization
    • Learn Java Vulnerability
      • Intro & Setup
      • Java Reflection Part 1
      • Java Reflection Part 2
    • Research Documents
      • šŸŽÆDNS Rebinding
      • šŸŖRemote Code Execution - Insecure Deserialization
      • šŸŖRemote Code Execution on Jinja - SSTI Lab
      • šŸŖExploit cross-site request forgery (CSRF) - Lab
      • šŸŖExploit a misconfigured CORS - Lab
      • šŸŖSame Origin Policy (SOP) - Lab
  • šŸ“WRITE-UP CTF
    • CTF Competitions
      • šŸ”°[WolvCTF 2023] Writeup Web
      • šŸ”°[Mā˜†CTF Training 2023] Writeup Web
      • šŸ”°[HackTM CTF 2023] Writeup Web
      • šŸ”°[Incognito 4.0 2023] Writeup Web
      • šŸ”°[LA CTF 2023] Re-writeup Web
      • šŸ”°[Dice CTF 2023] Writeup Web
      • šŸ”°[ByteBandits CTF 2023] Writeup Web
      • šŸ”°[Knight CTF 2023] Writeup Web
      • šŸ”°[Sekai CTF 2022] Writeup Web
      • šŸ”°[WRECK CTF 2022] Writeup Web
      • šŸ”°[Maple CTF 2022] Writeup Web
    • CTF WarGame
      • āœļø[Root me] Writeup Sever Side
      • āœļøWebsec.fr
      • āœļø[Root me] Writeup XSS Challenge
    • [tsug0d]-MAWC
      • šŸ’‰TSULOTT
      • šŸ’‰IQTEST
      • 🧬TooManyCrypto
      • 🧬NumberMakeup
    • Pwnable.vn
Powered by GitBook
On this page

Introduction

Pentester & CTFer

NextResearch Vulnerability

Last updated 9 months ago

šŸ’ā€ā™‚ļø

  • 🌁 I’m currently studying in National Research University Moscow Power Engineering Institute (MPEI)

  • šŸ“±I’m currently a member of the CTF and team of National Research University Moscow Power Engineering Institute (MPEI)

  • 🌱 I’m currently learning: PHP(Laravel), Java, JS(Nodejs), Python, C#, Golang and Pentest Web

  • ⚔ What I like to do: I like so much music, football, chess...coding and CTF

Some infomations about me:
SeaHatVN
Unicron
🌸
Page cover image