Author name: JPRHACK

Open Redirect
Open Redirect, OSCP, OWASP TOP 10 and web vulnerabilities

Open Redirect

Open Redirect: when a website trusts a URL too much 🔀 An Open Redirect is a vulnerability that occurs when an application redirects the user to a URL specified in a parameter (for example newurl or redirect) without validating that the destination belongs to a trusted domain. At first glance it seems harmless —after all, […]

Enumeracion y explotacion de Json Web Tokens (JWT)
JWT, OSCP, OWASP TOP 10 and web vulnerabilities

Enumeration and Exploitation of Json Web Tokens (JWT)

🔐 Enumeration and Exploitation of JSON Web Tokens (JWT) JSON Web Tokens (JWT) are the most common mechanism nowadays for handling authentication and authorization in web applications. It’s an open standard (RFC 7519) that defines a compact format for transmitting signed information between client and server. The problem is that many implementations blindly trust the

Inyecciones CSS (CSSI)
CSS Injection, OWAS TOP 10 y vulnerabilidades web

CSS Injections (CSSI)

CSS Injections (CSSI): when a simple color opens the door to XSS 🎨 CSS Injections (CSSI) are a type of web vulnerability that allows an attacker to inject malicious CSS code into a page, taking advantage of the fact that the application takes user input and dumps it directly into its stylesheet without validating or

Ataques de Deserializacion
Insecure Deserialization, OWASP TOP 10 and web vulnerabilities

Deserialization Attacks

forms #loginForms #registrationForms #privilegeEscalation Imagine an application with a form that sends a ping to some site, as the Cereal machine does. We’d intercept this request with burpsuite. We’re going to launch our localhost ip imagine it sends a payload like this obj=O%3A8%3A%22pingTest%22%3A1%3A%7Bs%3A9%3A%22ipAddress%22%3Bs%3A13%3A%22192.168.1.211%22%3B%7D&ip=192.168.1. At first this is urlencoded but if we select it and press

OSCP cheat sheet
OSCP

OSCP cheat sheet

Scanning machines Initial scan ssh-keygen -f ‘/root/.ssh/known_hosts’ -R ‘172.17.0.3’ nmap -p- –open -sS –min-rate 5000 -vvv -n -Pn 172.16.116.200 -oG allPorts ## ligolo nmap -p- -sT -Pn -n –min-rate 500 -T3 172.16.116.200 -vvv -oG allPorts ## vulnlab nmap -p- -sS –min-rate 1000 T4 10.10.121.28 -oG allPorts nmap -p- -vvv –min-rate 1000 -oG allPorts ## UDP

Scroll to Top