Academy · Videos

Watch it done

Short walkthroughs — the technique, start to finish. Pair one with the concept and the labs in the same category.

AllAuthentication bypassBroken access control / IDORSQL / command injectionBusiness logic flawPrivilege escalationCryptographic weaknessCSRFInsecure deserializationInformation disclosureRemote code executionRace conditionAccess control & business logicWeb applicationServer-side request forgery (SSRF)Subdomain takeoverCross-site scripting (XSS)
▶
Cross-site scripting (XSS)

XSS: reflected, stored and DOM

22:00