Academy · Videos

Watch it done

Short walkthroughs — the technique, start to finish. Pair one with the concept and the labs in the same category.

AllAuthentication bypassBroken access control / IDORSQL / command injectionBusiness logic flawPrivilege escalationCryptographic weaknessCSRFInsecure deserializationInformation disclosureRemote code executionRace conditionAccess control & business logicWeb applicationServer-side request forgery (SSRF)Subdomain takeoverCross-site scripting (XSS)
▶
SQL / command injection

Blind injection without an error message

19:00
▶
SQL / command injection

SQL injection from quote to UNION

25:00