Watch it done
Short walkthroughs — the technique, start to finish. Pair one with the concept and the labs in the same category.
AllAuthentication bypassBroken access control / IDORSQL / command injectionBusiness logic flawPrivilege escalationCryptographic weaknessCSRFInsecure deserializationInformation disclosureRemote code executionRace conditionAccess control & business logicWeb applicationServer-side request forgery (SSRF)Subdomain takeoverCross-site scripting (XSS)
▶
Authentication bypass
A tour of authentication bypasses
18:00▶
Broken access control / IDOR
Access control, from IDOR to admin
14:00▶
SQL / command injection
Blind injection without an error message
19:00▶
Business logic flaw
Business logic: valid requests, invalid outcomes
17:00▶
Privilege escalation
Climbing from user to admin
16:00▶
Cryptographic weakness
Cryptography you can break by hand
24:00▶
CSRF
CSRF and the cookie the browser sends anyway
12:00▶
Insecure deserialization
Deserialization: trusting the wrong bytes
20:00▶
Information disclosure
Finding what an app leaks
15:00▶
Remote code execution
From foothold to remote code execution
28:00▶
Race condition
Racing the check against the update
13:00▶
Access control & business logic
Reading a scope like an attacker
20:00▶
Broken access control / IDOR
Recon that actually finds things
18:00▶
Web application
Setting up a testing proxy
14:00▶
SQL / command injection
SQL injection from quote to UNION
25:00▶
Server-side request forgery (SSRF)
SSRF and the cloud metadata endpoint
16:00▶
Subdomain takeover
Subdomain takeover, start to finish
11:00▶
Cryptographic weakness
Where crypto goes wrong in practice
21:00▶
Web application
Writing a report that gets triaged fast
12:00▶
Cross-site scripting (XSS)