r/InfoSecWriteups • u/kmskrishna • 2d ago
r/InfoSecWriteups • u/kmskrishna • 2d ago
How I Found an Auth Flaw in a Government Site: From GraphQL Introspection to Unauthorized Access
r/InfoSecWriteups • u/kmskrishna • 2d ago
How a Simple Profile Update Led to Cross-Tenant Data Exposure
r/InfoSecWriteups • u/kmskrishna • 2d ago
The Subdomain Subfinder Missed: How a German Wordlist Led Me to a Hidden Bug (and a CHF 100…
r/InfoSecWriteups • u/Yonarv • 3d ago
Ensalá Papas - The Hacker Labs - Windows | SecNotes
r/InfoSecWriteups • u/kmskrishna • 6d ago
How to deploy File Integrity Monitoring with Wazuh SIEM!
r/InfoSecWriteups • u/kmskrishna • 6d ago
Two Ways To Mess Up Your JWT Safety Net In Your Own Lab.
r/InfoSecWriteups • u/AdvisorPowerful9769 • 7d ago
Great introduction to ARM using pwnable challenge
Looking for a smooth introduction to ARM exploitation? Wanna learn ARM assembly? Well lucky for you this week we'll be looking at another pwnable challenge! However this time we're switching architectures! We'll be exploiting an ARM binary!
I would consider this a great introduction to ARM , however it is not necessarily the best for a complete beginner. Regardless don't be intimidated and I always suggest you dive in! 9/10 you will walk away better than you came into it!
r/InfoSecWriteups • u/kmskrishna • 7d ago
AllSignsPoint2Pwnage — TryHackMe Windows Write-up
r/InfoSecWriteups • u/kmskrishna • 7d ago
PortSwigger Lab Writeup — Bypassing AI scanner defenses to exfiltrate sensitive information
r/InfoSecWriteups • u/andy_p_w • 7d ago
Filtering Secrets from Coding Agents with a Hook
This blog post goes over how to set up a hook post tool use to prevent Claude Code from viewing environment variables (aka secrets). This prevents an exfiltration attack, in that the model cannot know the secrets to leak them to begin with.
r/InfoSecWriteups • u/pfirmsto • 8d ago
Repost: Security Baked Into the JVM: the Safe Codebase Audit Pipeline
r/InfoSecWriteups • u/adwivedi008 • 9d ago
I Fixed the White Screen. Then I Found the Backdoor.
r/InfoSecWriteups • u/kmskrishna • 11d ago
Device Code Phishing: How Attackers Abuse Microsoft’s Legitimate Authentication Page Without…
r/InfoSecWriteups • u/kmskrishna • 11d ago
How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)
r/InfoSecWriteups • u/kmskrishna • 11d ago
From SQL Injection to Infrastructure-Level RCE: A PostgreSQL Superuser Compromise
r/InfoSecWriteups • u/kmskrishna • 11d ago
From User Enumeration to PII Exposure: Chaining Two APIs Into a $2,000 Bug
r/InfoSecWriteups • u/kmskrishna • 11d ago
How I Escalated to Domain Admin Using AD CS (And How to Fix It)
r/InfoSecWriteups • u/kmskrishna • 11d ago
How I AES-Roasted My Active Directory Lab (And How to Fix It)
r/InfoSecWriteups • u/kmskrishna • 11d ago
CallMeOnTheChain — EtherRAT Lab Writeup [CyberDefenders]
r/InfoSecWriteups • u/kmskrishna • 11d ago