SweshInfoSec
| Security researcher | VAPT | Bug bounty | Penetration Testing |
You May Also Enjoy
GuardianLeaks on pentest-ground.com — Web App Pentest Walkthrough
4 minute read
Step-by-step web-app pentest of GuardianLeaks — SQLi to a full credential dump, SSRF into cloud metadata, an easy-to-miss stored XSS, and an exposed Werkzeug...
DVGA on pentest-ground.com — GraphQL Pentest Walkthrough
10 minute read
Step-by-step: unauthenticated GraphQL introspection to full RCE on DVGA — 2 criticals, one HIGH SSRF, full kill chain.
XSS — Stored Keylogger with Error Handling
1 minute read
A production-grade XSS keylogger that handles network errors gracefully and logs each keystroke with confirmation — designed for stored XSS contexts where pe...
XSS — Stealing Session Cookies
less than 1 minute read
Use an XSS injection to exfiltrate the victim’s session cookie to your server — achieving full account takeover without knowing their password.