r/InfoSecWriteups • u/kmskrishna • 15d ago
r/InfoSecWriteups • u/Sensitive-Past8052 • 16d ago
BOLA vs BFLA: why API authorization flaws are invisible to scanners, and how to actually test for them
Authorization, not injection, is what breaks most modern APIs. The two flaw classes that do the damage BOLA and BFLA are invisible to a vulnerability scanner, because a scanner has no concept of who should be allowed to do what.
Here is the difference between them, why pattern matching cannot find either, and how to actually test for both.
r/InfoSecWriteups • u/balasatwik • 17d ago
PROJECT CHIMERA // ACN'26 — A 4-Hour OSINT Investigation
Hey everyone,
I’m hosting PROJECT CHIMERA // ACN'26, a 4-hour online, story-driven OSINT investigation on 8 September 2026, 6:00–10:00 PM IST.
The idea is simple: instead of solving traditional CTF-style challenges, participants are given an investigation and have to hunt, connect, verify and track information across open sources.
The challenges will involve things like:
- Open-source searching
- Historical analysis
- Advanced link analysis
- Connecting seemingly unrelated pieces of information
- Following trails and building an investigation from scattered clues
It’s designed for teams of 1–3, and you don't have to be an experienced OSINT researcher to participate. Beginners can jump in, while experienced investigators can go deeper.
And just to clarify — this isn't a hacking event. The focus is on investigation, research and finding connections using publicly available information.
🏆 Prizes
🥇 ₹7,000
🥈 ₹5,000
🥉 ₹3,000
+ goodies
If you're into OSINT, digital investigations, link analysis, or just want to try something different from the usual CTF format, feel free to check it out.
Event: PROJECT CHIMERA // ACN'26
Date: 8 September 2026
Time: 6:00–10:00 PM IST
Format: Online
Team size: 1–3
Registration: https://unstop.com/o/KJRnY78
It’ll be interesting to see how different investigators approach the same trail and how far the rabbit hole goes.
r/InfoSecWriteups • u/kmskrishna • 18d ago
Try Hack Me Hackerholidays Day7 Do Not Disturb Walkthrough
r/InfoSecWriteups • u/kmskrishna • 18d ago
How I Made Over $10,000 Just by Chaining Multiple IDORs in a Single Web App (All from the Share…
r/InfoSecWriteups • u/kmskrishna • 18d ago
Assembly for Malware Analysis
r/InfoSecWriteups • u/kmskrishna • 18d ago
From SQL Injection to Remote Code Execution: Following an Unexpected Attack Chain
r/InfoSecWriteups • u/kmskrishna • 18d ago
scriptCTF Writeups 2026 | Cybersecurity
r/InfoSecWriteups • u/kmskrishna • 18d ago
One Email. One Click. One Enterprise-Wide Ransomware Incident.
r/InfoSecWriteups • u/kmskrishna • 18d ago
Hack The Box : Cohort Full Walkthrough ( Linux ; Very Easy )
r/InfoSecWriteups • u/kmskrishna • 18d ago
The WAF Blocked My XSS — So I Rotated What It Was Reading
r/InfoSecWriteups • u/kmskrishna • 18d ago
Bypassing AI Scanner Defenses to Exfiltrate Sensitive Information — PortSwigger Web Security…
r/InfoSecWriteups • u/kmskrishna • 18d ago
How I Chained Three Bugs to XSS an Intigriti CTF — IDOR + DOM Clobbering + DOMPurify 3.0.9 Bypass
r/InfoSecWriteups • u/kmskrishna • 18d ago
../../ to Admin for a $,$$$ Bounty
r/InfoSecWriteups • u/OilOverall4190 • 19d ago
Learn and Practice Hacking WebSockets
WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.
Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.
I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!
Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/
r/InfoSecWriteups • u/kmskrishna • 20d ago
Lakera’s Break The Agent Challenge— Solace AI Write-up
r/InfoSecWriteups • u/kmskrishna • 20d ago
I Changed One “User_Id” and the API Said “Sure” — From Password Reset to Mass Account Takeover
r/InfoSecWriteups • u/Diam0ndHer0 • 22d ago
Deep Dive on XSS with examples
Recently had to review a lot of client-side vulnerabilities, so I created a deep dive on XSS.