writeups.xyz writeups.xyz / Plenum (@Plenumlab)

Title Vulnerabilities Programs Authors
Identifying and Exploiting Unsafe Deserialization in Ruby
What do Netcat, SMTP and self XSS have in common? Stored XSS
Account takeover using IDOR and the misleading case of error 403.
Token Brute-Force to Account Take-over to Privilege Escalation to Organization Take-Over
Duplicate but still cool
IDOR in JWT and the shortest token you will ever see {}.{“uid”: “1234567890”}