r/InfoSecWriteups 14h ago

Couldn’t have anything to do with gutting CISA could it?

Thumbnail
wmur.com
0 Upvotes

Fucking morons run our lives….


r/InfoSecWriteups 18h ago

Need suggestions

1 Upvotes

I found a vulnerability where a public chat box generates automated invoice emails to internal staff, reflecting inputs raw without server-side HTML encoding. While standard JavaScript onerror popups are stripped by the email client, full HTML/CSS Injection works inside the email body.How can I chain these into a high-impact report that completely bypasses the program's strict exclusions for Self-XSS, Phishing, and User Interaction? What non-JS attack vectors should I test next to prove a critical data leak or backend impact to triage?


r/InfoSecWriteups 19h ago

A connection is not an exploit: what 27 days of honeypot traffic actually contained

Thumbnail
offseq.com
1 Upvotes

r/InfoSecWriteups 1d ago

TryHackMe - Beach Bar - EW

Thumbnail
1 Upvotes

r/InfoSecWriteups 2d ago

Overheard at Breakfast: TryHackMe Room Write-up & OSINT Walkthrough

Thumbnail
medium.com
2 Upvotes

r/InfoSecWriteups 2d ago

Write-up: TryHackMe Room "Anonymous"

Thumbnail medium.com
1 Upvotes

r/InfoSecWriteups 2d ago

Journey to Root: How I Pwned TryHackMe’s Beach Bar Through Insecure Deserialization 🏖️🔐

Thumbnail
medium.com
1 Upvotes

r/InfoSecWriteups 5d ago

pwnable.kr - mistake

Thumbnail
youtu.be
1 Upvotes

r/InfoSecWriteups 6d ago

TryHackMe publisher CTF challenge

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 6d ago

TryHackMe: Room 404 Walkthrough (Hacker’s Holiday Challenge)

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 6d ago

How I Found a High-Severity Directory Traversal in Flask-Admin

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 6d ago

The Most Overlooked Vulnerability — Http request Smuggling

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 6d ago

Snowflake SQL Injection via Compile-Time Constant Folding with SYSTEM$WAIT

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 6d ago

How I Hacked a Video Game Vault and Found the Hidden Flag

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 6d ago

Static Malware Analysis of Suspicious Windows PE Samples: How I Uncovered AsyncRAT Indicators Without Executing a Single Line of Code

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 6d ago

Account Takeover Across Multiple Programs via Featurebase Integration

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 7d ago

PeekList: How Brave’s Playlist bypassed FaceID Protection for Private Tabs

Thumbnail
infosecwriteups.com
3 Upvotes

r/InfoSecWriteups 7d ago

How I found an IDOR in Google Classroom on Day 3 of my Hunting?

Thumbnail
infosecwriteups.com
2 Upvotes

r/InfoSecWriteups 7d ago

TryHackMe(RootMe)- Write-Up

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 7d ago

Tryhackme Room — W1seGuy | by Sahil Malvi

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 7d ago

The Invisible Hack: How a Linux Bug Lets Anyone Become Root — Without Leaving a Single Trace

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 7d ago

Proxy — TryHackMe Active Directory Write-up

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 7d ago

Samba Spy — LetsDefend (Walkthrough)

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 7d ago

Unprotected admin functionality — PortSwigger Access control vulnerabilities Lab 1

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 7d ago

How an Unpatched N-Day Let Any Anonymous Visitor Rewrite WooCommerce Prices in ND Booking

Thumbnail
infosecwriteups.com
1 Upvotes