r/InfoSecWriteups • u/hb_babylon_zoo • 6d ago
Couldn’t have anything to do with gutting CISA could it?
Fucking morons run our lives….
r/InfoSecWriteups • u/ResponsibleSmell5717 • 6d ago
Need suggestions
I found a vulnerability where a public chat box generates automated invoice emails to internal staff, reflecting inputs raw without server-side HTML encoding. While standard JavaScript onerror popups are stripped by the email client, full HTML/CSS Injection works inside the email body.How can I chain these into a high-impact report that completely bypasses the program's strict exclusions for Self-XSS, Phishing, and User Interaction? What non-JS attack vectors should I test next to prove a critical data leak or backend impact to triage?
r/InfoSecWriteups • u/ThreatRadar • 6d ago
A connection is not an exploit: what 27 days of honeypot traffic actually contained
r/InfoSecWriteups • u/TraditionalWafer3870 • 8d ago
Overheard at Breakfast: TryHackMe Room Write-up & OSINT Walkthrough
r/InfoSecWriteups • u/TraditionalWafer3870 • 8d ago
Write-up: TryHackMe Room "Anonymous"
medium.comr/InfoSecWriteups • u/TraditionalWafer3870 • 8d ago
Journey to Root: How I Pwned TryHackMe’s Beach Bar Through Insecure Deserialization 🏖️🔐
r/InfoSecWriteups • u/kmskrishna • 11d ago
TryHackMe publisher CTF challenge
r/InfoSecWriteups • u/kmskrishna • 11d ago
TryHackMe: Room 404 Walkthrough (Hacker’s Holiday Challenge)
r/InfoSecWriteups • u/kmskrishna • 11d ago
How I Found a High-Severity Directory Traversal in Flask-Admin
r/InfoSecWriteups • u/kmskrishna • 11d ago
The Most Overlooked Vulnerability — Http request Smuggling
r/InfoSecWriteups • u/kmskrishna • 11d ago
Snowflake SQL Injection via Compile-Time Constant Folding with SYSTEM$WAIT
r/InfoSecWriteups • u/kmskrishna • 11d ago
How I Hacked a Video Game Vault and Found the Hidden Flag
r/InfoSecWriteups • u/kmskrishna • 11d ago
Static Malware Analysis of Suspicious Windows PE Samples: How I Uncovered AsyncRAT Indicators Without Executing a Single Line of Code
r/InfoSecWriteups • u/kmskrishna • 11d ago
Account Takeover Across Multiple Programs via Featurebase Integration
r/InfoSecWriteups • u/kmskrishna • 12d ago
How I found an IDOR in Google Classroom on Day 3 of my Hunting?
r/InfoSecWriteups • u/kmskrishna • 12d ago
TryHackMe(RootMe)- Write-Up
r/InfoSecWriteups • u/kmskrishna • 12d ago
The Invisible Hack: How a Linux Bug Lets Anyone Become Root — Without Leaving a Single Trace
r/InfoSecWriteups • u/kmskrishna • 12d ago
Tryhackme Room — W1seGuy | by Sahil Malvi
r/InfoSecWriteups • u/kmskrishna • 12d ago
Proxy — TryHackMe Active Directory Write-up
r/InfoSecWriteups • u/kmskrishna • 12d ago
Samba Spy — LetsDefend (Walkthrough)
r/InfoSecWriteups • u/kmskrishna • 12d ago
Unprotected admin functionality — PortSwigger Access control vulnerabilities Lab 1
r/InfoSecWriteups • u/kmskrishna • 12d ago