Avatar ☕

xanhacks' infosec blog

xanhacks infosec blog, enjoy reading 📖 !

  1. Created with Fabric.js 3.5.0
  1. Home
  2. About
  3. Search
    1. Dark Mode

Archives

2025 1
2023 6
2022 5
2021 2

Categories

Web Malware Box Others

Tags

Web Ctf Code Analysis Flask Malware Php Privesc Race Condition Reverse Xs-Leaks
Featured image of post NextJS research, Actions discovery, SSRF, VHOST spoofing & Freemarker SSTI with filter bypass - FCSC 2025 Wirteups
Web

NextJS research, Actions discovery, SSRF, VHOST spoofing & Freemarker SSTI with filter bypass - FCSC 2025 Wirteups

Writeup of two Web challenges from FCSC 2025, featuring a NextJS application and a Spring Boot application.

Apr 25, 2025
12 minute read
Featured image of post Race Condition, OAuth without state and redirection into XSS & RCE via HTML2PDF - PhantomFeed HTB University 2023
Web

Race Condition, OAuth without state and redirection into XSS & RCE via HTML2PDF - PhantomFeed HTB University 2023

Exploiting a Race Condition, OAuth without state and redirection into XSS & RCE via HTML2PDF to solve the last web challenge PhantomFeed from HTB University 2023

Dec 10, 2023
10 minute read
Featured image of post XSS, Race Condition, XS-Leaks and CSP & iframe's sandbox bypass - LakeCTF 2023 GeoGuessy
Web

XSS, Race Condition, XS-Leaks and CSP & iframe's sandbox bypass - LakeCTF 2023 GeoGuessy

Exploiting XSS, XS-Leaks or Race condition to steal bot's GPS coordinates.

Nov 17, 2023
13 minute read
Featured image of post Nginx configuration bypass & Forging HTTP request - FCSC2023 Follow The Rabbit
Web

Nginx configuration bypass & Forging HTTP request - FCSC2023 Follow The Rabbit

Forging custom a HTTP request to bypass a restrictive Nginx configuration. Writeup of the challenge Follow The Rabbit of FCSC2023.

Apr 30, 2023
5 minute read
Featured image of post Abusing FindFirstFile to do PHP Session Hijacking - THCon23 Demo App
Web

Abusing FindFirstFile to do PHP Session Hijacking - THCon23 Demo App

Abusing the FindFirstFile Windows API function to do PHP Session Hijacking via Path Traversal. Writeup of the Demo App challenge of the THCon23 CTF.

Apr 23, 2023
3 minute read
1 2 3
© 2020 - 2025 xanhacks' infosec blog
Built with Hugo
Theme Stack designed by Jimmy