AWS (2) CSRF (1) CVE (1) apollo (1) appsec (3) caching (1) cert (1) challenges (8) cloud (2) ctf (8) dns (1) effectiveness (1) graphql (1) hacking (13) infra (3) learning (1) methodology (1) misconfiguration (1) motivation (1) offsec (2) penetration tests (1) pentest (1) productivity (1) research (1) security (1)

 AWS (2)

Hijacking AWS API calls
Security Implication of Root principal in AWS

 CSRF (1)

CVE-2021-29995 CSRF to RCE on CloverDX 5.9.0

 CVE (1)

CVE-2021-29995 CSRF to RCE on CloverDX 5.9.0

 apollo (1)

Apollo Caching 1on1

 appsec (3)

CVE-2021-29995 CSRF to RCE on CloverDX 5.9.0
Apollo Caching 1on1
AWAE and OSWE review

 caching (1)

Apollo Caching 1on1

 cert (1)

PEN-300 and OSEP review

 challenges (8)

Exploiting Jinja SSTI with limited payload size.
Gynvael's web security challenge - part 6.
Gynvael's web security challenge - part 5.
Gynvael's web security challenge - part 4.
Gynvael's web security challenge - part 3.
Gynvael's web security challenge - part 2.
Gynvael's web security challenge - part 1.
Gynvael's web security challenge - part 0.

 cloud (2)

Hijacking AWS API calls
Security Implication of Root principal in AWS

 ctf (8)

Exploiting Jinja SSTI with limited payload size.
Gynvael's web security challenge - part 6.
Gynvael's web security challenge - part 5.
Gynvael's web security challenge - part 4.
Gynvael's web security challenge - part 3.
Gynvael's web security challenge - part 2.
Gynvael's web security challenge - part 1.
Gynvael's web security challenge - part 0.

 dns (1)

Hijacking AWS API calls

 effectiveness (1)

Manage Pentest in Time

 graphql (1)

Apollo Caching 1on1

 hacking (13)

PEN-300 and OSEP review
Hijacking AWS API calls
Security Implication of Root principal in AWS
CVE-2021-29995 CSRF to RCE on CloverDX 5.9.0
AWAE and OSWE review
Exploiting Jinja SSTI with limited payload size.
Gynvael's web security challenge - part 6.
Gynvael's web security challenge - part 5.
Gynvael's web security challenge - part 4.
Gynvael's web security challenge - part 3.
Gynvael's web security challenge - part 2.
Gynvael's web security challenge - part 1.
Gynvael's web security challenge - part 0.

 infra (3)

PEN-300 and OSEP review
Hijacking AWS API calls
Security Implication of Root principal in AWS

 learning (1)

Manage Pentest in Time

 methodology (1)

Pentest Methodology

 misconfiguration (1)

Apollo Caching 1on1

 motivation (1)

Manage Pentest in Time

 offsec (2)

PEN-300 and OSEP review
AWAE and OSWE review

 penetration tests (1)

Pentest Methodology

 pentest (1)

Pentest Methodology

 productivity (1)

Manage Pentest in Time

 research (1)

Apollo Caching 1on1

 security (1)

Apollo Caching 1on1