4:09 Exploiting LLM APIs with excessive agency - APPRENTICE AmirHossein Soltani 46 views - 2 years ago
4:06 Exploiting an API endpoint using documentation - APPRENTICE AmirHossein Soltani 34 views - 2 years ago
2:29 Exploiting NoSQL operator injection to bypass authentication - APPRENTICE AmirHossein Soltani 152 views - 2 years ago
4:41 Remote code execution via server-side prototype pollution - PRACTITIONER AmirHossein Soltani 31 views - 2 years ago
1:50 Bypassing flawed input filters for server-side prototype pollution - PRACTITIONER AmirHossein Soltani 7 views - 2 years ago
2:07 Detecting server-side prototype pollution without polluted property reflection - PRACTITIONER AmirHossein Soltani 12 views - 2 years ago
5:57 Privilege escalation via server-side prototype pollution - PRACTITIONER AmirHossein Soltani 29 views - 2 years ago
0:52 Client-side prototype pollution in third-party libraries - PRACTITIONER AmirHossein Soltani 17 views - 2 years ago
5:19 Client-side prototype pollution via flawed sanitization - PRACTITIONER AmirHossein Soltani 9 views - 2 years ago
4:49 DOM XSS via an alternative prototype pollution vector - Prototype pollution AmirHossein Soltani 12 views - 2 years ago
2:54 DOM XSS via client-side prototype pollution - PRACTITIONER AmirHossein Soltani 21 views - 2 years ago
3:29 Client-side prototype pollution via browser APIs - PRACTITIONER AmirHossein Soltani 43 views - 2 years ago
14:27 Scanning non-standard data structures - PRACTITIONER AmirHossein Soltani 686 views - 2 years ago
3:11 Discovering vulnerabilities quickly with targeted scanning - PRACTITIONER AmirHossein Soltani 105 views - 2 years ago
2:47 JWT authentication bypass via flawed signature verification - APPRENTICE AmirHossein Soltani 17 views - 2 years ago
3:51 JWT authentication bypass via unverified signature - APPRENTICE AmirHossein Soltani 19 views - 2 years ago
2:37 Web shell upload via Content-Type restriction bypass - APPRENTICE AmirHossein Soltani 80 views - 2 years ago
2:18 Remote code execution via web shell upload - APPRENTICE AmirHossein Soltani 31 views - 2 years ago
1:30 Authentication bypass via OAuth implicit flow - APPRENTICE AmirHossein Soltani 16 views - 2 years ago
2:52 Web cache poisoning via a fat GET request - PRACTITIONER AmirHossein Soltani 37 views - 2 years ago
1:45 Web cache poisoning via an unkeyed query parameter - PRACTITIONER AmirHossein Soltani 20 views - 2 years ago
1:25 Web cache poisoning via an unkeyed query string - PRACTITIONER AmirHossein Soltani 13 views - 2 years ago
7:16 Targeted web cache poisoning using an unknown header - PRACTITIONER AmirHossein Soltani 23 views - 2 years ago
7:32 Web cache poisoning with multiple headers - PRACTITIONER AmirHossein Soltani 26 views - 2 years ago
4:14 Web cache poisoning with an unkeyed cookie - PRACTITIONER AmirHossein Soltani 17 views - 2 years ago
5:26 Web cache poisoning with an unkeyed header - PRACTITIONER AmirHossein Soltani 39 views - 2 years ago
2:09 Authentication bypass via information disclosure - APPRENTICE AmirHossein Soltani 20 views - 2 years ago
0:58 Information disclosure in error messages - APPRENTICE AmirHossein Soltani 19 views - 2 years ago
1:25 Manipulating WebSocket messages to exploit vulnerabilities - APPRENTICE AmirHossein Soltani 158 views - 2 years ago
2:17 Username enumeration via different responses - APPRENTICE AmirHossein Soltani 205 views - 2 years ago
2:01 User ID controlled by request parameter with password disclosure - APPRENTICE AmirHossein Soltani 14 views - 2 years ago
1:44 User ID controlled by request parameter with data leakage in redirect - APPRENTICE AmirHossein Soltani 8 views - 2 years ago
1:12 User ID controlled by request parameter, with unpredictable user IDs - APPRENTICE AmirHossein Soltani 21 views - 2 years ago
1:08 User role can be modified in user profile - APPRENTICE AmirHossein Soltani 24 views - 2 years ago
0:57 User role controlled by request parameter - APPRENTICE AmirHossein Soltani 22 views - 2 years ago
0:53 Unprotected admin functionality with unpredictable URL - APPRENTICE AmirHossein Soltani 19 views - 2 years ago
3:14 Server-side template injection with information disclosure via user-supplied objects - PRACTITIONER AmirHossein Soltani 5 views - 2 years ago
1:00 Server-side template injection in an unknown language with a documented exploit - PRACTITIONER AmirHossein Soltani 10 views - 2 years ago
1:12 Server-side template injection using documentation - PRACTITIONER AmirHossein Soltani 10 views - 2 years ago
3:07 Basic server-side template injection (code context) - PRACTITIONER AmirHossein Soltani 44 views - 2 years ago