BigMac
27 posts


I completed the Web Security Academy lab:
Information disclosure in version control history
@WebSecAcademy
portswigger.net/web-security/i…
English

I completed the Web Security Academy lab:
Information disclosure on debug page
@WebSecAcademy
portswigger.net/web-security/i…
English

I completed the Web Security Academy lab:
File path traversal, traversal sequences stripped non-recursively
@WebSecAcademy
portswigger.net/web-security/f…
English

I completed the Web Security Academy lab:
Username enumeration via account lock
@WebSecAcademy
portswigger.net/web-security/a…
English

I completed the Web Security Academy lab:
Broken brute-force protection, multiple credentials per request
@WebSecAcademy
portswigger.net/web-security/a…
English

I completed the Web Security Academy lab:
Broken brute-force protection, IP block
@WebSecAcademy
portswigger.net/web-security/a…
English

I completed the Web Security Academy lab:
Username enumeration via subtly different responses
@WebSecAcademy
portswigger.net/web-security/a…
English

I completed the Web Security Academy lab:
Blind SQL injection with conditional responses
@WebSecAcademy
portswigger.net/web-security/s…
English

I completed the Web Security Academy lab:
SQL injection UNION attack, retrieving data from other tables
@WebSecAcademy
portswigger.net/web-security/s…
English

I completed the Web Security Academy lab:
Blind SQL injection with time delays and information retrieval
@WebSecAcademy
portswigger.net/web-security/s…

English

I completed the Web Security Academy lab:
SQL injection attack, listing the database contents on Oracle
@WebSecAcademy
portswigger.net/web-security/s…
English

I completed the Web Security Academy lab:
SQL injection attack, querying the database type and version on MySQL and Microsoft
@WebSecAcademy
portswigger.net/web-security/s…
English

I completed the Web Security Academy lab:
SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
@WebSecAcademy
portswigger.net/web-security/s…
English

I completed the Web Security Academy lab:
Reflected XSS with AngularJS sandbox escape without strings
@WebSecAcademy
portswigger.net/web-security/c…
English

I completed the Web Security Academy lab:
Exploiting cross-site scripting to steal cookies
@WebSecAcademy
portswigger.net/web-security/c…
English

@bigmac_0x @WebSecAcademy عاش يا ريس
العربية

I completed the Web Security Academy lab:
Stored XSS into onclick event with angle brackets and double quotes HTML-encoded and single quotes and backslash escaped
@WebSecAcademy
portswigger.net/web-security/c…
English

I completed the Web Security Academy lab:
Reflected DOM XSS
@WebSecAcademy
portswigger.net/web-security/c…
English

I completed the Web Security Academy lab:
DOM XSS in document.write sink using source location.search inside a select element
@WebSecAcademy
portswigger.net/web-security/c…
English
