PinnedRed Darkin·Apr 15A Real SSRF Story from HackerOne (Featuring IPv6 + Redirects)In the world of web security, even the most seemingly harmless features like webhooks can hide critical vulnerabilities. In this article…A response icon2A response icon2
PinnedRed Darkin·Apr 23How I Found a Critical Bug Using Claude Desktop (Free)TL;DR: I fed a JavaScript bundle to Claude Desktop (I use Burp MCP with Claude). It mapped hidden endpoints I’d missed after multiple…A response icon10A response icon10
PinnedRed Darkin·Oct 6, 2023Reflected Cross-Site Scripting in Hidden Input FieldsA response icon2A response icon2
Red Darkin·Jan 30, 2024How to replicate Jenkins CVE-2024–23897: Arbitrary File Read VulnerabilityIn this story, I’ll guide you through effortlessly replicating the latest Jenkins-related CVE. But before we jump into action, let’s take a…
Red Darkin·Nov 19, 2022DOM XSS via an alternative prototype pollution vector — Portswigger LabVersion en Español