Pocas Notes.

Express, RCE via File Extension Confusing ≤ V4.18.2


This article is about the RCE vulnerability that occurs only in highly specific cases in web services using the Express framework. Express is a web framework based on Node.js
Read more ⟶

Express, Querystring parameter limit of req.query


This article is about the logic that can occur when a query string is passed to Express. Express is a web framework based on Node.js
Read more ⟶

CCE 2022 Write Up


This article is about write-up for the CCE 2022. there is only three web challenges, all of which contain RCE, XSS, SSRF. Actually someone ask to me paly it but i couldn't join with him.
Read more ⟶

SSTF 2022 JWT Decoder Write Up


This article is about write-up for the SSTF 2022. there is only one web challenge, which contain JWT bug
Read more ⟶

Outlook, XSS Sanitizer flaw


The article is about Security Advisory of MS. I found an interesting logic bug while working on mitigation of xss!
Read more ⟶