Shang
Blog πŸ‘¨β€πŸ’»
  • 🌸Introduction
  • πŸ’»WEB SECURITY
    • Research Vulnerability
      • πŸ“²Server-side topics
        • πŸ”API Testing
        • πŸ”Race conditions
        • πŸ”XML external entity (XXE) injection
        • πŸ”Server-side request forgery (SSRF)
        • πŸ”File upload vulnerabilities
        • πŸ”Access control vulnerabilities and privilege escalation
        • πŸ”Business logic vulnerabilities
        • πŸ”OS Command injection
        • πŸ”Directory traversal
        • πŸ”Authentication vulnerabilities
        • πŸ”SQL injection
      • πŸ“±Client-side topics
        • πŸ”DOM-based vulnerabilities
        • πŸ”Cross-origin resource sharing (CORS)
        • πŸ”WebSockets
        • πŸ”Clickjacking (UI redressing)
        • πŸ”Cross-site request forgery (CSRF)
        • πŸ”Cross-site scripting(XSS)
      • πŸŒ€Advanced topics
        • πŸ”Web cache poisoning
        • πŸ”HTTP request smuggling
        • πŸ”Prototype pollution
        • πŸ”Server-side template injection(SSTI)
        • πŸ”Insucure deserialization
    • Learn Java Vulnerability
      • Intro & Setup
      • Java Reflection Part 1
      • Java Reflection Part 2
    • Research Documents
      • 🎯DNS Rebinding
      • πŸͺRemote Code Execution - Insecure Deserialization
      • πŸͺRemote Code Execution on Jinja - SSTI Lab
      • πŸͺExploit cross-site request forgery (CSRF) - Lab
      • πŸͺExploit a misconfigured CORS - Lab
      • πŸͺSame Origin Policy (SOP) - Lab
  • πŸ“WRITE-UP CTF
    • CTF Competitions
      • πŸ”°[WolvCTF 2023] Writeup Web
      • πŸ”°[Mβ˜†CTF Training 2023] Writeup Web
      • πŸ”°[HackTM CTF 2023] Writeup Web
      • πŸ”°[Incognito 4.0 2023] Writeup Web
      • πŸ”°[LA CTF 2023] Re-writeup Web
      • πŸ”°[Dice CTF 2023] Writeup Web
      • πŸ”°[ByteBandits CTF 2023] Writeup Web
      • πŸ”°[Knight CTF 2023] Writeup Web
      • πŸ”°[Sekai CTF 2022] Writeup Web
      • πŸ”°[WRECK CTF 2022] Writeup Web
      • πŸ”°[Maple CTF 2022] Writeup Web
    • CTF WarGame
      • ✏️[Root me] Writeup Sever Side
      • ✏️Websec.fr
      • ✏️[Root me] Writeup XSS Challenge
    • [tsug0d]-MAWC
      • πŸ’‰TSULOTT
      • πŸ’‰IQTEST
      • 🧬TooManyCrypto
      • 🧬NumberMakeup
    • Pwnable.vn
Powered by GitBook
On this page
  1. WEB SECURITY

Research Vulnerability

πŸŒ‡Research on web security vulnerablities

PreviousIntroductionNextServer-side topics

Last updated 9 months ago

πŸ’»
πŸ“²Server-side topics
πŸ“±Client-side topics
πŸŒ€Advanced topics
Page cover image