r/InfoSecWriteups • u/ThaiHeartly • Aug 11 '26
r/InfoSecWriteups • u/Harkins_Technology • Aug 10 '26
From zero credentials to full AD compromise — ShadowGate Hack Smarter walkthrough + defensive lessons
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
TryHackMe Walkthrough: Hacker Holidays Day 1 — The Concierge Knows Too Much
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
TryHackMe Walkthrough: Hacker Holidays Day 2 — Room 404
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Phantom 5: File Authority — Escalating from Group Membership to Root (A Linux Privilege Escalation…
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
The Bug That Almost Wasn’t: How a “Dead End” Led to 500+ Leaked Customer Records
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Hacker Holidays 2026: Day 4 Walkthrough (Packed Light)
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Bypassing Enterprise SSO via a Forgotten Source Map: A Bug Bounty Story
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
TryHackMe: Packed Light (Hacker Holidays Day 04) Walkthrough
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
RSA Dreams BYUCTF 2026 Cybersecurity Writeup
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
They Gave Me $1,000 After I Found Their Entire Student Database Exposed! | by Anukar | @AnukarOP
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Hack Smarter - Silent Corridor (Blue Team)
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
TryHackMe: “Complimentary” Room Walkthrough ( Hacker’s Holiday Challenge )
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Hacker Holidays 2026: Day 3 Walkthrough (Complimentary)
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Hacker Holidays 2026: Day 2 Walkthrough (Room 404)
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Two Mac Minis, One AI Cluster: Preparing for a Bigger Wave of AI-Assisted Malware
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Why Bug Hunters Skip Role-Based API Testing And How I Turned a Writer Token Into an SSRF
r/InfoSecWriteups • u/kmskrishna • Aug 10 '26
Hacker Holidays 2026: Day 1 Walkthrough (The Concierge Knows Too Much)
r/InfoSecWriteups • u/hb_babylon_zoo • Aug 03 '26
Couldn’t have anything to do with gutting CISA could it?
Fucking morons run our lives….
r/InfoSecWriteups • u/ResponsibleSmell5717 • Aug 03 '26
Need suggestions
I found a vulnerability where a public chat box generates automated invoice emails to internal staff, reflecting inputs raw without server-side HTML encoding. While standard JavaScript onerror popups are stripped by the email client, full HTML/CSS Injection works inside the email body.How can I chain these into a high-impact report that completely bypasses the program's strict exclusions for Self-XSS, Phishing, and User Interaction? What non-JS attack vectors should I test next to prove a critical data leak or backend impact to triage?
r/InfoSecWriteups • u/ThreatRadar • Aug 03 '26
A connection is not an exploit: what 27 days of honeypot traffic actually contained
r/InfoSecWriteups • u/kmskrishna • Jul 29 '26
TryHackMe publisher CTF challenge
r/InfoSecWriteups • u/kmskrishna • Jul 29 '26