Pocas Notes.
Express, RCE via File Extension Confusing ≤ V4.18.2
This article is about the RCE vulnerability that occurs only in highly specific cases in web services using the Express framework. Express is a web framework based on Node.js
Read more ⟶
Express, Querystring parameter limit of req.query
This article is about the logic that can occur when a query string is passed to Express. Express is a web framework based on Node.js
Read more ⟶
CCE 2022 Write Up
This article is about write-up for the CCE 2022. there is only three web challenges, all of which contain RCE, XSS, SSRF. Actually someone ask to me paly it but i couldn't join with him.
Read more ⟶
SSTF 2022 JWT Decoder Write Up
This article is about write-up for the SSTF 2022. there is only one web challenge, which contain JWT bug
Read more ⟶
Outlook, XSS Sanitizer flaw
The article is about Security Advisory of MS. I found an interesting logic bug while working on mitigation of xss!
Read more ⟶