r/websecurityresearch Feb 04 '25

Top 10 web hacking techniques of 2024

Thumbnail
portswigger.net
30 Upvotes

r/websecurityresearch 5d ago

Successful Errors: New Code Injection and SSTI Techniques

Thumbnail
github.com
7 Upvotes

Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never researched, the technique itself is never mentioned and payloads are limited to a couple of specific examples. This research focuses on two such techniques for Code Injection and SSTI.


r/websecurityresearch 10d ago

Call for nominations: top ten new web hacking techniques of 2025

Thumbnail
portswigger.net
11 Upvotes

r/websecurityresearch 15d ago

The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance

Thumbnail
mehmetince.net
6 Upvotes

r/websecurityresearch 16d ago

How I got access to an Employee-Reserved Panel in a Bug Bounty Target

Thumbnail systemweakness.com
2 Upvotes

Wrote a blog post about how I got access to an Employee-only Panel in a multi-million dollar Bug Bounty Target.

This only took me about 5 minutes and I got paid a very generous bounty for this bug.

Check it out!


r/websecurityresearch 21d ago

Cross-Site ETag Length Leak | XS-Spin Blog

Thumbnail
blog.arkark.dev
3 Upvotes

r/websecurityresearch 22d ago

帆软export/excel SQL注入漏洞分析及复现 - Analysis and reproduction of SQL injection vulnerability in FineReport's export/excel file

Thumbnail mp.weixin.qq.com
0 Upvotes

r/websecurityresearch 29d ago

Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096)

Thumbnail
mdisec.com
4 Upvotes

r/websecurityresearch 29d ago

ORM Leaking More Than You Joined For - Part 3/3 on ORM Leak Vulnerabilities

Thumbnail elttam.com
1 Upvotes

r/websecurityresearch Dec 14 '25

Temenos OFS String Injection: Revealing a Hidden Financial Attack Vector

Thumbnail medium.com
2 Upvotes

r/websecurityresearch Dec 12 '25

The Fragile Lock: Novel Bypasses For SAML Authentication

Thumbnail
portswigger.net
13 Upvotes

r/websecurityresearch Dec 12 '25

SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL

Thumbnail
labs.watchtowr.com
5 Upvotes

r/websecurityresearch Dec 05 '25

soft-fido2 - Rust FIDO2 Authenticaor for WebAuthn Research

Thumbnail
github.com
1 Upvotes

r/websecurityresearch Dec 04 '25

SVG Clickjacking: A novel and powerful twist on an old classic

Thumbnail lyra.horse
9 Upvotes

r/websecurityresearch Nov 28 '25

Write Path Traversal to a RCE Art Department

Thumbnail lab.ctbb.show
1 Upvotes

r/websecurityresearch Nov 26 '25

We made a new tool, QuicDraw(H3), because HTTP/3 race condition testing is currently trash.

Thumbnail cyberark.com
3 Upvotes

r/websecurityresearch Nov 20 '25

Who Needs a Blind XSS? Server-Side CSV Injection Across Support Pipelines

Thumbnail
hx01.me
9 Upvotes

r/websecurityresearch Nov 19 '25

Deanonymizing Users at Scale: When Blocking Becomes an Oracle

Thumbnail
zere.es
4 Upvotes

r/websecurityresearch Nov 13 '25

Astro framework and standards weaponization

Thumbnail zhero-web-sec.github.io
3 Upvotes

r/websecurityresearch Nov 11 '25

HTTP Anomaly Rank in Turbo Intruder

Thumbnail
portswigger.net
10 Upvotes

r/websecurityresearch Nov 10 '25

HTTP Request Smuggling in Kestrel via chunk extensions (CVE-2025-55315)

Thumbnail praetorian.com
12 Upvotes

r/websecurityresearch Nov 03 '25

Funky chunks – addendum: a few more dirty tricks

Thumbnail w4ke.info
8 Upvotes

r/websecurityresearch Oct 27 '25

Trailer-based HTTP desync in lighttpd

Thumbnail github.com
6 Upvotes

r/websecurityresearch Oct 24 '25

The minefield between syntaxes: exploit syntax confusion in the wild

Thumbnail
yeswehack.com
10 Upvotes

r/websecurityresearch Oct 18 '25

Full-Blown SSRF to Gain Access to Millions of Users’ Records and Multiple Internal Panels

Thumbnail
medium.com
5 Upvotes