GuardianLeaks on pentest-ground.com — Web App Pentest Walkthrough
Step-by-step web-app pentest of GuardianLeaks — SQLi to a full credential dump, SSRF into cloud metadata, an easy-to-miss stored XSS, and an exposed Werkzeug...
Step-by-step web-app pentest of GuardianLeaks — SQLi to a full credential dump, SSRF into cloud metadata, an easy-to-miss stored XSS, and an exposed Werkzeug...
Step-by-step: unauthenticated GraphQL introspection to full RCE on DVGA — 2 criticals, one HIGH SSRF, full kill chain.
Step-by-step: SQLi, Werkzeug RCE and Broken Access Control on a Flask app — 3 criticals, full kill chain.
Full BlackOps web assessment of DVWA running on pentest-ground.com:4280. 20 confirmed findings across RCE, LFI/RFI, SQLi, XSS, CSRF, and broken access contro...
Test Sub
Security research walkthroughs, VAPT findings, and bug bounty reports — documented with BlackOps.