Research
-
Out-of-Band SQL Injection: Exfiltrating Over DNS When There's No Output
2026-08-30
-
SQL Injection to Web Shell: Writing PHP with INTO OUTFILE
2026-08-16
-
OS Command Injection: Bypassing Length-Limited Input Filters
2026-05-10
-
Getting More Out of Burp Suite: Tips, Extensions, and Workflows
2021-08-20
-
Demons in the Database: Hiding Backdoors in RDBMS Services
2021-08-18
-
Zero-Day Research: Where to Find and Track Vulnerabilities
2021-08-12
-
The Pentesting Kit: Hardware and Tools for Physical Assessments
2021-08-05
-
OS Command Injection Tutorial - Part #1 (Basics and Filter Evasion)
2021-07-28
-
SSH Shenanigans Part #1: Tips & Tricks
2021-07-25
-
Triggering Full Path Disclosure - The Basics
2021-07-25
-
A Guide to Non-Conventional WAF/IDS Evasion Techniques
2021-07-24
-
Open Redirection Exploitation Tutorial - Part #1
2021-07-24
-
Lame 0day #1 - MyBB Hidden Content Bypass
2021-07-24
-
Winning the Race: Signals, Symlinks, and TOC/TOU
2021-06-23
-
Utilizing .htaccess for Exploitation Purposes
2021-06-23