Web exploits

In this tag we are gonna talk about web exploitation

Get RCE With SSTI Get RCE With SSTI

Yo yo miss me right? Guess what Im back🥳🥳So lets talk about SSTI or Server-side template injection As usually we need to works with things before jumping into SSTI. So lets try a template engine and learn what is it Lets use a Template engine A template engine is

Mar 29, 2024 4 mins

Getting RCE from web via ftp exploit Getting RCE from web via ftp exploit

Yo yo homies I’m back . yeah this post is in a different category than my other post(that’s why my banner template changed) so first we need to talk about what is FTP and why are we using it What is FTP The File Transfer Protocol is a

Mar 20, 2024 5 mins

Secrets of LFI🤫 Secrets of LFI🤫

Yo yo homies Guess what? I lunched my web .ok so you can see my crackhead blog and portfolio :- so lets start Layout handling is crucial in web dev .But sometimes silly dev use to handle layout like this http://example.com/home.php?page=profile.php And as

Mar 12, 2024 5 mins

Payload will after you Payload will after you

Yo homies I’m back with another post.so lets start Before we dive into second order sql injection we need to talk about what is sql injecion What is Sql injection So Sql injection is attack that inject a malicious sql query to Application that can be execute SELECT

Mar 10, 2024 3 mins

Real time exploitation | Isuk4 Real time exploitation | Isuk4

Yo yo homies.im back with another post.so lets start Hmmm.Did you chat with live agents on any day? If you did that, you know that it’s a real time chat. like live agent can see you’re Mg in real time so how does developer make

Mar 10, 2024 2 mins

Request can be malicious Request can be malicious

Heey after about week im back so lets start. so first this story begins with my homie sent me a web backend develop with express.js to fix a bug😒so I fixed it but you know me😂after I fixed it I read the whole code.hmm there is

Mar 10, 2024 2 mins

Cross site scripting | Isuk4 Cross site scripting | Isuk4

So lets begin What is Cross site scripting if a website that directly renders user input it can be execute a html or js code that’s what we called xss or cross site scripting. how it can be dangerous 1. Code Execution: One of the primary dangers of XSS

Mar 10, 2024 4 mins

Secrets about Gadget chains🤫 Secrets about Gadget chains🤫

Yo Yo Homies,I’m back with another post so do you remember our last post we talked about Insecure deserializion and PHP object injection(yeah i know that POI is a type of Insecure …) so lets continue this What is serialization? simply serialization is a process of convert object

Mar 10, 2024 3 mins

Copyright © Isuk4 . All Rights Reserved