| Skip to content | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365#start-of-content |
|
| https://patch-diff.githubusercontent.com/ |
|
Sign in
| https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Fscriptkkiddie%2Flearn365 |
| GitHub CopilotWrite better code with AI | https://github.com/features/copilot |
| GitHub SparkBuild and deploy intelligent apps | https://github.com/features/spark |
| GitHub ModelsManage and compare prompts | https://github.com/features/models |
| MCP RegistryNewIntegrate external tools | https://github.com/mcp |
| ActionsAutomate any workflow | https://github.com/features/actions |
| CodespacesInstant dev environments | https://github.com/features/codespaces |
| IssuesPlan and track work | https://github.com/features/issues |
| Code ReviewManage code changes | https://github.com/features/code-review |
| GitHub Advanced SecurityFind and fix vulnerabilities | https://github.com/security/advanced-security |
| Code securitySecure your code as you build | https://github.com/security/advanced-security/code-security |
| Secret protectionStop leaks before they start | https://github.com/security/advanced-security/secret-protection |
| Why GitHub | https://github.com/why-github |
| Documentation | https://docs.github.com |
| Blog | https://github.blog |
| Changelog | https://github.blog/changelog |
| Marketplace | https://github.com/marketplace |
| View all features | https://github.com/features |
| Enterprises | https://github.com/enterprise |
| Small and medium teams | https://github.com/team |
| Startups | https://github.com/enterprise/startups |
| Nonprofits | https://github.com/solutions/industry/nonprofits |
| App Modernization | https://github.com/solutions/use-case/app-modernization |
| DevSecOps | https://github.com/solutions/use-case/devsecops |
| DevOps | https://github.com/solutions/use-case/devops |
| CI/CD | https://github.com/solutions/use-case/ci-cd |
| View all use cases | https://github.com/solutions/use-case |
| Healthcare | https://github.com/solutions/industry/healthcare |
| Financial services | https://github.com/solutions/industry/financial-services |
| Manufacturing | https://github.com/solutions/industry/manufacturing |
| Government | https://github.com/solutions/industry/government |
| View all industries | https://github.com/solutions/industry |
| View all solutions | https://github.com/solutions |
| AI | https://github.com/resources/articles?topic=ai |
| Software Development | https://github.com/resources/articles?topic=software-development |
| DevOps | https://github.com/resources/articles?topic=devops |
| Security | https://github.com/resources/articles?topic=security |
| View all topics | https://github.com/resources/articles |
| Customer stories | https://github.com/customer-stories |
| Events & webinars | https://github.com/resources/events |
| Ebooks & reports | https://github.com/resources/whitepapers |
| Business insights | https://github.com/solutions/executive-insights |
| GitHub Skills | https://skills.github.com |
| Documentation | https://docs.github.com |
| Customer support | https://support.github.com |
| Community forum | https://github.com/orgs/community/discussions |
| Trust center | https://github.com/trust-center |
| Partners | https://github.com/partners |
| GitHub SponsorsFund open source developers | https://github.com/sponsors |
| Security Lab | https://securitylab.github.com |
| Maintainer Community | https://maintainers.github.com |
| Accelerator | https://github.com/accelerator |
| Archive Program | https://archiveprogram.github.com |
| Topics | https://github.com/topics |
| Trending | https://github.com/trending |
| Collections | https://github.com/collections |
| Enterprise platformAI-powered developer platform | https://github.com/enterprise |
| GitHub Advanced SecurityEnterprise-grade security features | https://github.com/security/advanced-security |
| Copilot for BusinessEnterprise-grade AI features | https://github.com/features/copilot/copilot-business |
| Premium SupportEnterprise-grade 24/7 support | https://github.com/premium-support |
| Pricing | https://github.com/pricing |
| Search syntax tips | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
| documentation | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
|
Sign in
| https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Fscriptkkiddie%2Flearn365 |
|
Sign up
| https://patch-diff.githubusercontent.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=scriptkkiddie%2Flearn365 |
| Reload | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365 |
| Reload | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365 |
| Reload | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365 |
|
scriptkkiddie
| https://patch-diff.githubusercontent.com/scriptkkiddie |
| learn365 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365 |
| harsh-bothra/learn365 | https://patch-diff.githubusercontent.com/harsh-bothra/learn365 |
|
Notifications
| https://patch-diff.githubusercontent.com/login?return_to=%2Fscriptkkiddie%2Flearn365 |
|
Fork
1
| https://patch-diff.githubusercontent.com/login?return_to=%2Fscriptkkiddie%2Flearn365 |
|
Star
6
| https://patch-diff.githubusercontent.com/login?return_to=%2Fscriptkkiddie%2Flearn365 |
|
6
stars
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/stargazers |
|
424
forks
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/forks |
|
Branches
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/branches |
|
Tags
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/tags |
|
Activity
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/activity |
|
Star
| https://patch-diff.githubusercontent.com/login?return_to=%2Fscriptkkiddie%2Flearn365 |
|
Notifications
| https://patch-diff.githubusercontent.com/login?return_to=%2Fscriptkkiddie%2Flearn365 |
|
Code
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365 |
|
Pull requests
0
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/pulls |
|
Actions
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/actions |
|
Projects
0
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/projects |
|
Security
0
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/security |
|
Insights
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/pulse |
|
Code
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365 |
|
Pull requests
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/pulls |
|
Actions
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/actions |
|
Projects
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/projects |
|
Security
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/security |
|
Insights
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/pulse |
| Branches | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/branches |
| Tags | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/tags |
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/branches |
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/tags |
| 200 Commits | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/commits/main/ |
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/commits/main/ |
| MindMaps | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/tree/main/MindMaps |
| MindMaps | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/tree/main/MindMaps |
| days | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/tree/main/days |
| days | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/tree/main/days |
| README.md | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/README.md |
| README.md | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/README.md |
| suggestions.md | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/suggestions.md |
| suggestions.md | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/suggestions.md |
| README | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365 |
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365#learn365 |
| Harsh Bothra | https://twitter.com/harshbothra_ |
| Mehedi Hasan Remon | https://twitter.com/remonsec |
| 2FA Bypass Techniques | https://t.co/HPi5ZP2SKG?amp=1 |
| Scope Based Recon | https://www.xmind.net/m/hKKexj/ |
| Cookie Based Authentication Vulnerabilities | http://www.xmind.net/m/2FwJ7D |
| Unauthenticated JIRA CVEs | https://raw.githubusercontent.com/harsh-bothra/learn365/main/MindMaps/JIRA_CVEs.png |
| Android Application Penetration Testing Checklist | https://www.xmind.net/m/GkgaYH/ |
| 2FA Bypass Techniques | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day1.md |
| Regular Expression Denial Of Service | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day2.md |
| SAML Vulnerabilities | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day3.md |
| Unauthenticated & Exploitable JIRA Vulnerabilities | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day4.md |
| Client-Side Template Injection(CSTI) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day5.md |
| Cross-Site Leaks (XS-Leaks) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day6.md |
| Cross-Site Script Includes (XSSI) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day7.md |
| JSON Padding Attacks | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day8.md |
| JSON Attacks | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day9.md |
| Abusing Hop-by-Hop Headers | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day10.md |
| Cache Poisoned Denial of Service (CPDos) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day11.md |
| Unicode Normalization | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day12.md |
| WebSocket Vulns (Part-1) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day13.md |
| WebSocket Vulns (Part-2) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day14.md |
| WebSocket Vulns (Part-3) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day15.md |
| Web Cache Deception Attack | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day16.md |
| Session Puzzling Attack | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day17.md |
| Mass Assignment Attack | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day18.md |
| HTTP Parameter Pollution | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day19.md |
| GraphQL Series (Part-1) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day20.md |
| GraphQL Vulnerabilities (Part-2) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day21.md |
| GraphQL WrapUp (Part-3) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day22.md |
| Password Reset Token Issues | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day23.md |
| My previous works | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day24.md |
| Salesforce Security Misconfiguration (Part-1) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day25.md |
| Salesforce Security Misconfiguration (Part-2)) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day26.md |
| Salesforce Configuration Review (Wrap) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day27.md |
| Common Business Logic Issues: Part-1 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day28.md |
| Common Business Logic Issues (Part-2) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day29.md |
| Common Business Logic Issues (Wrap) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day30.md |
| Captcha Bypass Techniques | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day31.md |
| Pentesting Kibana Service | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day32.md |
| Pentesting Docker Registry | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day33.md |
| HTML Scriptless Attacks / Dangling Markup Attacks (Part - 1) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day34.md |
| HTML Scriptless Attacks / Dangling Markup Attacks (Wrap) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day35.md |
| Pentesting Rsync Service | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day36.md |
| CRLF Injection | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day37.md |
| Pentesting FTP Service | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day38.md |
| OpenID Connect Implementation Issues | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day39.md |
| Cookie Based Authentication Vulnerabilities | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day40.md |
| Cobalt Vulnerability Wiki - Resource | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day41.md |
| Race Conditions | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day42.md |
| SMTP Open Relay Attack | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day43.md |
| Pentesting BACNet | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day44.md |
| API Security Tips | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day45.md |
| Pentesting SSH - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day46.md |
| CORS Misconfiguration | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day47.md |
| Incomplete Trailing Escape Pattern Issue | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day48.md |
| Pivoting & Exploitation in Docker Environments - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day49.md |
| Detect Complex Code Patterns using Semantic grep - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day50.md |
| Student Roadmap to Become a Pentester - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day51.md |
| Hacking How-To Series - Playlist | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day52.md |
| JS Prototype Pollution | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day53.md |
| JSON Deserialization Attacks | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day54.md |
| Android App Dynamic Analysis using House | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day55.md |
| Testing IIS Servers | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day56.md |
| Secure Code Review - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day57.md |
| JSON Interoperability Vulnerabilities - Research Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day58.md |
| HTTP Desync Attacks - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day59.md |
| XSLT Injection | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day60.md |
| Bypassing AWS Policies - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day61.md |
| Source Code Review Guidelines - Resource | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day62.md |
| All of the Threats: Intelligence, Modelling and Hunting - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day63.md |
| Hidden Property Abuse (HPA) attack in Node.js - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day64.md |
| HTTP Request Smuggling in 2020 - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day65.md |
| Dependecy Confusion Attack - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day66.md |
| Format String Vulnerabilities - Webinar | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day67.md |
| Mobile Application Dynamic Analysis - Webinar | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day68.md |
| Insecure Deserialization - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day69.md |
| Web Cache Entanglement - Talk + Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day70.md |
| OWASP AMASS - Bootcamp | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day71.md |
| Offensive Javascript Techniques for Red Teamers | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day72.md |
| Basic CMD for Pentesters - Cheatsheet | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day73.md |
| Investigating and Defending Office 365 - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day74.md |
| WinjaCTF 2021 Solutions - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day75.md |
| Kubernetes Security: Attacking and Defending K8s Clusters - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day76.md |
| AWS Cloud Security - Resources | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day77.md |
| WAF Evasion Techniques - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day78.md |
| File Inclusion - All-in-One | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day79.md |
| DockerENT Insights - Tool Demo Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day80.md |
| ImageMagick - Shell injection via PDF password : Research Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day81.md |
| Offensive GraphQL API Pentesting - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day82.md |
| Bug Bounties with Bash - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day83.md |
| Chrome Extensions Code Review - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day84.md |
| Server-Side Template Injection - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day85.md |
| Exploiting GraphQL - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day86.md |
| Exploiting Email Systems - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day87.md |
| Hacking with DevTools - Tutorial | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day88.md |
| Common Android Application Vulnerabilities - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day89.md |
| SAML XML Injection - Research Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day90.md |
| Finding Access Control & Authorization Issues with Burp - Blogs | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day91.md |
| OAuth 2.0 Misimplementation, Vulnerabilities, and Best Practices - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day92.md |
| JWT Attacks - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day93.md |
| Random Readings | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day94_102.md |
| Attacking Ruby on Rails Applications - Whitepaper | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day103.md |
| Pentesting a Chrome Extension: Real Life Case Study - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day104.md |
| XXE Simplified - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day105.md |
| Web Hacking Pro Tips #9 with @zseano - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day106.md |
| JS Prototype Pollution - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day107.md |
| XSS via GraphQL Endpoint - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day108.md |
| WS-2016-7107: CSRF tokens in Spring and the BREACH attack - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day109.md |
| AWS SSRF Metadata Leakage - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day110.md |
| Burp Suite Extension Development - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day111.md |
| Random Readings | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day112_115.md |
| Hacking OAuth Apps Pt-1 - Tutorial | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day116.md |
| Portable Data exFiltration: XSS for PDFs - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day117.md |
| PoC code and a case study on Task Hijacking in Android explaining how and why it works. (aka StrandHogg) - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day118.md |
| OAuth - Flawed CSRF Protection - Tutorial | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day119.md |
| Hacking Electron Apps with Electronegativity - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day120.md |
| Awesome ElectronJS Hacking Resources | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day121.md |
| Pentesting Blockchain Solutions - Tutorial | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day122.md |
| Random Readings | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day123_124.md |
| Oversized XML Attack - Wiki | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day125.md |
| XML Complexity Attack in Soap Header - Wiki | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day126.md |
| Web Service Attacks [Remaining] - Wiki | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day127.md |
| Domain Hijacking Via Logic Error - Gandi And Route 53 Vulnerability - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day128.md |
| Automating Recon with Axiom - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day129.md |
| Testing Extensions in Chromium Browsers - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day130.md |
| iOS Pentesting Series Pt. - 1 - Tutorial | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day131.md |
| DNS Based Out of Band Blind SQL injection in Oracle — Dumping data - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day132.md |
| GitDorker Talk - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day133.md |
| Mobisec 2020 Slides - Slides & Videos | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day134.md |
| Web App Pentesting in Angular Context - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day135.md |
| RCE in Homebrew - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day136.md |
| WordPress Plugin Security Testing Cheat Sheet - Wiki | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day137.md |
| JavaScript prototype pollution: practice of finding and exploitation - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day138.md |
| HowTo: intercept mutually-authenticated TLS communications of a Java thick client - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day139.md |
| UBERNETES NAMESPACES ISOLATION - WHAT IT IS, WHAT IT ISN'T, LIFE, UNIVERSE AND EVERYTHING - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day140.md |
| Frag Attacks - Wiki | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day141.md |
| Free Automated Recon Using GH Actions - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day142.md |
| DAY[0] Episode 66 - BlackHat USA, Pre-Auth RCEs, and JSON Smuggling - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day143.md |
| Bug hunter adventures - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day144.md |
| Static Analysis of Client-Side JS Code - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day145.md |
| Method Confusion In Go SSTIs Lead To File Read And RCE - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day146.md |
| Finding and Exploiting Unintended Functionality in Main Web App APIs - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day147.md |
| SecuriTEA & Crumpets - Episode 6 - Gareth Heyes - Hackvertor - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day148.md |
| GraphQL CSRF - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day149.md |
| Deep dive into ART(Android Runtime) for dynamic binary analysis - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day150.md |
| 13 Nagios Vulnerabilities - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day151.md |
| Frida Scripting Guide - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day152.md |
| Android Exported Activities and how to exploit them - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day153.md |
| XXE-scape through the front door: circumventing the firewall with HTTP request smuggling - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day154.md |
| Turning Blind RCE into Good RCE via DNS Exfiltration using Collabfiltrator - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day155.md |
| XSS in AWS Console - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day156.md |
| Adventures into HTTP2 and HTTP3 - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day157.md |
| AppCache's forgotten tales - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day158.md |
| CVE-2021-33564 Argument Injection in Ruby Dragonfly - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day159.md |
| DevSecOps 100 - Introductory Couse [Free] - Course | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day160.md |
| Unexpected Execution: Wild Ways Code Execution can Occur in Python - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day161.md |
| Retrieving AWS security credentials from the AWS console - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day162.md |
| Object Injection to SQL Injection & NoSql Injection Cheatsheet - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day163.md |
| HTTP Parameter Pollution - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day164.md |
| XXE Workshop - Labs | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day165.md |
| How to Analyze Code for Vulnerabilities - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day166.md |
| Testing 2FA - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day167.md |
| Your E-Mail Validation Logic is Wrong - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day168.md |
| Active Scanning Techniques - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day169.md |
| Bypassing 2FA using OpenId Misconfiguration - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day170.md |
| Security Shorts - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day171.md |
| The JavaScript Bridge in Modern Desktop Applications - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day172.md |
| Advanced Web Application Penetration Testing JWT Security Issues - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day173.md |
| Quick Analysis for the SSID Format String Bug - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day174.md |
| Live GitLab Ask a Hacker with Bug Bounty Hunter (vakzz) William Bowling (Public) - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day175.md |
| iOS App Testing Through Burp on Corellium - blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day176.md |
| Blind XSS: setup your self-hosted XSS Hunter with the PwnMachine - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day177.md |
| Attacking GraphQL's Autocorrect - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day178.md |
| Apex Security Whitepaper - Paper + Labs | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day179.md |
| Django SSTI - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day180.md |
| Pen-Testing Salesforce SAAS Application - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day181.md |
| How to solve an XSS challenge from Intigriti in under 60 minutes - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day182.md |
| How to get the max out of an IDOR? - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day183.md |
| Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464) - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day184.md |
| Some ways to find more IDOR - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day185.md |
| A supply-chain breach: Taking over an Atlassian account - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day186.md |
| alert() is dead, long live print() - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day187.md |
| Hacker Heroes #3 - @TomNomNom (Interview) - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day188.md |
| SSRF in ColdFusion/CFML Tags and Functions - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day189.md |
| $25,000 Facebook postMessage account takeover vulnerability - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day190.md |
| Pentester Diaries Ep6: The Importance of Report Writing - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day191.md |
| Introduction to Web Cache Poisoning - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day192.md |
| Intercepting Flutter iOS Application - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day193.md |
| Credential stuffing in Bug bounty hunting - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day194.md |
| What is a Browser Security Sandbox?! (Learn to Hack Firefox) - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day195.md |
| WILSON Cloud Respwnder - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day196.md |
| $20,000 RCE in GitLab via 0day in exiftool metadata processing library CVE-2021-22204 - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day197.md |
| Padding Oracle Attacks - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day198.md |
| Demystifying the state of kubernetes cluster security - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day199.md |
| Two One-liners for Quick ColdFusion Static Analysis Security Testing - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day200.md |
| So many different techniques to learn here! [CTF walkthrough] - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day201.md |
| UDP Technology IP Camera vulnerabilities - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day202.md |
| Exploiting the Sudo Baron Samedit vulnerability (CVE-2021-3156) on VMWare vCenter Server 7.0 - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day203.md |
| Reflected XSS Through Insecure Dynamic Loading - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day204.md |
| Stored XSS via Mermaid Prototype Pollution vulnerability - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day205.md |
| Getting Partial AWS Account IDs for any Cloudfront Website - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day206.md |
| Remote code execution in cdnjs of Cloudflare - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day207.md |
| Docker Security Series - Series | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day208.md |
| REvil Vanishes! - Chrome Zero-Day Vulnerability, iOS WiFi SSID Bug, Patch Tuesday Review - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day209.md |
| How to Build a Phishing Engagement – Coding TTP’s - Webcast | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day210.md |
| Deep Link Exploitation: Introduction & Open/unvalidated Redirection - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day211.md |
| Exploiting Android WebView Vulnerabilities - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day212.md |
| WooCommerce Unauthenticated SQL Injection Vulnerability - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day213.md |
| Traversing My Way in the Internal Network - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day214.md |
| How I Found Multiple Bugs On FaceBook In 1 Month And a Part For My Methodology & Tools - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day215.md |
| Pre-Auth RCE in ManageEngine OPManager - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day216.md |
| Guest Blog Post - Attacking the DevTools - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day217.md |
| Kubernetes Hardening Guide - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day218.md |
| Introducing hallucinate: One-stop TLS traffic inspection and manipulation using dynamic instrumentation - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day219.md |
| Do Not use alert(1) in XSS - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day220.md |
| A Look Into zseano's Thoughts When Testing a Target - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day221.md |
| Zimbra 8.8.15 - Webmail Compromise via Email - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day222.md |
| Security XML Implementation across the Web - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day223.md |
| Potential remote code execution in PyPi - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day224.md |
| XXE Case Studies - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day225.md |
| HackerTools - NoSQLMap - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day226.md |
| Learn with @sec_r0: Attacks and Defenses to Docker & Kubernetes - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day227.md |
| Source Zero Con Talks - Talks | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day228.md |
| DevOps for Hackers with Hands-On Labs w/ Ralph May - Talks | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day229.md |
| Advanced Recon Guide - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day230.md |
| Just Gopher It: Escalating a Blind SSRF to RCE for $15k - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day231.md |
| Stealing Bitcoin with Cross-Site Request Forgery (Ride the Lightning + Umbrel) - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day232.md |
| Modify in-flight data to payment provider Smart2Pay - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day233.md |
| Hacker Heroes #9 - RobinZekerNiet (Interview) - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day234.md |
| Learn with @HolyBugx: Demystifying Cookies and Tokens - Talk | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day235.md |
| Hacker Tools: ReNgine – Automatic recon - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day236.md |
| FROM PWN2OWN 2021: A NEW ATTACK SURFACE ON MICROSOFT EXCHANGE - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day237.md |
| How to Hack Apple ID - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day238.md |
| Insecure Features in PDFs - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day239.md |
| Burp Upload Scanner - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day240.md |
| Adobe Reader - PDF callback via XSLT stylesheet in XFA - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day241.md |
| A Curious Exploration of Malicious PDF Documents - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day242.md |
| Common mistakes when using permissions in Android - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day243.md |
| iOS Pentesting 101 - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day244.md |
| API Tokens: A Tedious Survey - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day245.md |
| Cross-Site Request Forgery (CSRF) Complete Guide - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day246.md |
| HTTP Desync Attack Explained With Paper - Video | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day247.md |
| AWS ReadOnlyAccess: Not Even Once - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day248.md |
| Understanding Salesforce Flows and Common Security Risks - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day249.md |
| Python context free payloads in Mako templates - Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day250.md |
| CVE-2021-26084 Remote Code Execution on Confluence Servers | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day251.md |
| Introduction to smart contract security and hacking in Ethereum | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day252.md |
| Automating Authorization Testing: AuthMatrix – Part 1 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day253.md |
| Go Fuzz Yourself – How to Find More Vulnerabilities in APIs Through Fuzzing | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day254.md |
| More secure Facebook Canvas : Tale of $126k worth of bugs that lead to Facebook Account Takeovers | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day255.md |
| Smart Contract Security Verification Standard | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day256.md |
| Remote File Inclusion Zines by @sec_r0 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day257.md |
| GitHub Actions check-spelling community workflow - GITHUB_TOKEN leakage via advice.txt symlink | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day258.md |
| Write-Up on Facebook Bug | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day259.md |
| Mass assignment and learning new things | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day260.md |
| A different way to attack certain reverse proxies | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day261.md |
| Introducing Process Hiving & RunPE | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day262.md |
| IAM Vulnerable - An AWS IAM Privilege Escalation Playground | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day263.md |
| Complete Jailbreak Chart | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day264.md |
| OWASP Top 10 2021 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day265.md |
| Powershell for Pentesters | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day266.md |
| How to search for XSS (with blacklisted HTML tags) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day267.md |
| How to learn anything in Computer Science or Cybersecurity - Security Simplified | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day268.md |
| Reused VMWare exploits & Escaping Azure Container Instances [Bug Bounty Podcast] | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day269.md |
| Docker Hacking | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day270.md |
| Getting Started in Blockchain Security and Smart Contract Auditing - Beau Bullock | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day271.md |
| HacktivityCon | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day272.md |
| CrikeyCon 2021 - Shubham Shah - Hacking on Bug Bounties for Five Years | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day273.md |
| Beginners Guide to 0day/CVE AppSec Research | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day274.md |
| VULNERABILITY DIGGING WITH CODEQL | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day275.md |
| OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day276.md |
| Post Exploitation - Transferring Files To Windows Targets | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day277.md |
| SecuriTEA & Crumpets - Episode 12 - Ksenia Peguero | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day278.md |
| Talk: Absolute AppSec Ep. #147 - James Kettle (@albinowax), Security Research | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day279.md |
| A Flickr CSRF, GitLab, & OMIGOD, Azure again? [Bug Bounty Podcast] | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day280.md |
| NETGEAR smart switches, SpookJS, & Parallels Desktop [Binary Exploitation Podcast] | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day281.md |
| Unusual Applications of OpenAI in Cybersecurity + How to get into CTFs | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day282.md |
| SiegeCast "COBALT STRIKE BASICS" with Tim Medin and Joe Vest | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day283.md |
| An Attacker's Approach to Pentesting IBM Cloud - fwd:cloudsec 2021 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day284.md |
| echo "Shell Injection" | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day285.md |
| Exploiting Jinja SSTI with limited payload size. | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day286.md |
| Fuzzing WebSocket messages on Burpsuite | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day287.md |
| Thinking About Simple SQL Injections | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day288.md |
| Training XSS Muscles | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day289.md |
| "A tale of making internet pollution free" - Exploiting Client-Side Prototype Pollution in the wild | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day290.md |
| Chasing a Dream:: Pre-authenticated Remote Code Execution in Dedecms | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day291.md |
| Multiple bugs allowed malicious Android Applications to takeover Facebook/Workplace accounts | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day292.md |
| Ping'ing XMLSec | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day293.md |
| 10 Types of Web Vulnerabilities that are Often Missed | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day294.md |
| CVE-2021–35215, SolarWinds Orion Deserialization to RCE. | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day295.md |
| Bachelor's thesis on HTTP Request Smuggling | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day296.md |
| Stored XSS in markdown via the DesignReferenceFilter | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day297.md |
| Building a POC for CVE-2021-40438 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day298.md |
| Turbo Intruder: Embracing the billion-request attack | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day299.md |
| How to conduct a basic security code review - Security Simplified | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day300.md |
| How to Analyze Code for Vulnerabilities using Joern | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day301.md |
| Azure Privilege Escalation via Service Principal Abuse | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day302.md |
| CREATING A MALICIOUS AZURE AD OAUTH2 APPLICATION | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day303.md |
| 0-Day Hunting (Chaining Bugs/Methodology) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day304.md |
| Discourse SNS webhook RCE | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day305.md |
| Android Exploits 101 Workshop | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day306.md |
| SHELLS AND SOAP: WEBSPHERE DESERIALIZATION TO RCE | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day307.md |
| PHP-FPM LOCAL ROOT VULNERABILITY | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day308.md |
| Support Board 3.3.4 Arbitrary File Deletion to Remote Code Execution | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day309.md |
| SuDump: Exploiting suid binaries through the kernel | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day310.md |
| Attacking and Securing CI/CD Pipeline | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day311.md |
| Exploiting Protobuf Webapps | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day312.md |
| CookieMonster | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day313.md |
| Get shells with JET, the Jolokia Exploitation Toolkit | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day314.md |
| Android security checklist: WebView | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day315.md |
| 5 Ways to Exploit a Domain Takeover Vulnerability | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day316.md |
| Create a proxy DLL with artifact kit | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day317.md |
| How to search for XXE! | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day318.md |
| Defeating Android Certificate Pinning with Frida | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day319.md |
| What can I do with Open Redirect with OAuth? | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day320.md |
| Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day321.md |
| T-Reqs: HTTP Request Smuggling with Differential Fuzzing | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day322.md |
| ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day323.md |
| MULTIPLE CONCRETE CMS VULNERABILITIES ( PART1 – RCE ) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day324.md |
| Android App Hacking Workshop | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day325.md |
| Secondary Contexts Slides | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day326.md |
| HTTP/2 request smuggling (explained using beer) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day327.md |
| Scanning for hardcoded secrets in source code - Security Simplified | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day328.md |
| Staying sane in bug bounties | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day329.md |
| How Your E-book Might Be Reading You: Exploiting EPUB Reading Systems | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day330.md |
| Attacking SAML implementations | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day331.md |
| Uniscan: An RFI, LFI, and RCE Vulnerability Scanner | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day332.md |
| JavaScript type confusion: Bypassed input validation (and how to remediate) | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day333.md |
| Multiple Vulnerabilities in ResourceSpace | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day334.md |
| Unboxing BusyBox – 14 new vulnerabilities uncovered by Claroty and JFrog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day335.md |
| Zero-Day Disclosure: Palo Alto Networks GlobalProtect VPN CVE-2021-3064 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day336.md |
| Simple SSRF Allows Access To Internal Assets | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day337.md |
| Multiple Resource by XVNPW Blog | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day338.md |
| WordPress Plugin Confusion: How an update can get you pwned | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day339.md |
| RCE with SSRF and File Write as an exploit chain on Apache Guacamole | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day340.md |
| Grafana CVE-2021-43798 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day341.md |
| Data Exfiltration via CSS + SVG Font | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day342.md |
| The Pen Testing Tools We’re Thankful for in 2021 | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day343.md |
| HitCon CTF Challenges by Orange | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day344.md |
| Random Readings | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day345-363.md |
| Metasploit Basics for Hackers | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day364.md |
| NCC Group’s Cryptopals Guided Tour! | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/blob/main/days/day365.md |
|
Readme
| https://patch-diff.githubusercontent.com/scriptkkiddie/learn365#readme-ov-file |
| Please reload this page | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365 |
|
Activity | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/activity |
|
6
stars | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/stargazers |
|
2
watching | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/watchers |
|
1
fork | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/forks |
|
Report repository
| https://patch-diff.githubusercontent.com/contact/report-content?content_url=https%3A%2F%2Fgithub.com%2Fscriptkkiddie%2Flearn365&report=scriptkkiddie+%28user%29 |
| Releases | https://patch-diff.githubusercontent.com/scriptkkiddie/learn365/releases |
| Packages
0 | https://patch-diff.githubusercontent.com/users/scriptkkiddie/packages?repo_name=learn365 |
|
| https://github.com |
| Terms | https://docs.github.com/site-policy/github-terms/github-terms-of-service |
| Privacy | https://docs.github.com/site-policy/privacy-policies/github-privacy-statement |
| Security | https://github.com/security |
| Status | https://www.githubstatus.com/ |
| Community | https://github.community/ |
| Docs | https://docs.github.com/ |
| Contact | https://support.github.com?tags=dotcom-footer |