

Recent
OSWP: Tips and Tricks to Pwn all Networks!
·5 mins
I recently went through the OSWP certification, and in this post I’ll share how I prepared, what went wrong, and what I learned from the whole experience.
WayWitch
·3 mins
Very Easy Web Challenge. Based on abusing some bad practices when using JSON Web Tokens.
Armaxis
·2 mins
A simple web challenge where we abuse and IDOR to access a privileged account, to take advantage of a LFI via Mardown Injection