pwneglyph logo
Web banner

Web

Web application attack techniques — injection, authentication bypass, and more.

15 categories 1 note
15 total
P

Server-side Python web bugs — SSRF parser confusion, pickle and cache abuse, Jinja2 SSTI, XML and pycurl sinks, import-time code hooks, and request smuggling.

15 notes
P

PHP and Apache attack surface — .htaccess injection, object injection and POP chains, session-file primitives, native-code pivots, and libmagic / mt_rand confusion.

18 notes
J

Client- and server-side JS bugs — mXSS, prototype pollution and path-copy gadgets, CSP bypass chains, DOM clobbering, Angular sinks, and Node module / inspector pivots.

28 notes
H

Protocol-level and SQL injection techniques — HTTP/3 services, operator-precedence SQLi, boolean-blind extraction, UNION-based session forging, and replay-driven SSRF.

5 notes
P

Multi-hop and edge attacks — Traefik host-header routing, request-parsing desync, and topology enumeration through docs, headers, and operational endpoints.

3 notes
L

Application logic flaws — undocumented modes and hidden API behavior, and weak binding of proof tokens such as captchas and coupons.

2 notes
M

Per-stack triage checklists — what to think about first when the stack is Python, PHP, JS / browser, or a multi-hop proxy chain.

4 notes
M

Web challenge writeups from the Midnight Flag 2026 finals — a server-side DOMPurify/JSDOM mXSS (inkpress) and a Flask FileSystemCache pickle RCE raced through /proc/self/fd (yanta).

2 notes
F

Web challenge writeups from the FCSC 2026 qualifiers — client-side XSS, Apache/PHP server-side chains, HTTP request smuggling, Angular CSPT, prototype pollution, and Node sandbox escapes.

9 notes
B

Web challenge writeups from BreizhCTF 2026 — client+server chains mixing JSON type-confusion path traversal, SVG/CSP XSS, and Python import-shadowing RCE via gunicorn worker recycling.

1 note
M

Web challenge writeups from m0leCon CTF 2025 - ImageMagick argument injection, arbitrary write with -write, MIFF metadata survival past exiftool, and PHP webshell RCE.

1 note
P

Web challenge writeups from Plfanzen 2026 — JavaScript-flavoured server-side logic bugs: node-sqlite3 array-binding parameter pollution, missing-await bcrypt, case-insensitive LIKE, and a LiquidJS sort_natural prototype-leak side-channel.

1 note
N

Web challenge writeups from N1CTF 2025 — a Node/Express chain: sha.js hash-rewind JWT forgery (CVE-2025-9288), path.extname filter bypass, path traversal, and EJS SSTI to RCE.

1 note
O

Web challenge writeups from OpenECSC 2025 - Python object/reference confusion, shared class attributes, hidden-field mass assignment, and admin config leakage.

1 note
H

Web challenge writeups from HackTheBox — a broad mix of server- and client-side bugs: nginx cache poisoning, Next.js SSRF + Jinja2 SSTI, Go zip-slip session forgery, PHP POP chains and php-cgi argument injection, H2 SQL→RCE, Mongoose prototype pollution, Tornado object-walk gadget, and a TensorFlow Lambda-layer RCE.

16 notes
1 total