8:02 Insecure Deserialization #6 | Exploiting PHP deserialization with a pre-built gadget chain | 2026 CryptHawk 3 views - 7 hours ago
4:04 Multi-step Process With No Access Control On One Step | [Access Control Lab 12] [PortSwigger] [2026] CryptHawk 15 views - 1 month ago
6:04 Broken Brute-force Protection, Multiple Credentials Per Request | [Hackvertor] [Burp CE] [2026] CryptHawk 27 views - 2 months ago
3:27 User role can be modified in user profile | [PortSwigger] [Broken Access Control] [2026] CryptHawk 18 views - 1 month ago
6:22 Password Brute-force via Password Change | [Turbo Intruder] [Burp CE] [2026] CryptHawk 62 views - 2 months ago
4:23 Insecure Direct Object References | [PortSwigger] [Burp] [2026] CryptHawk 30 views - 1 month ago
2:13 Unprotected Admin Functionality | [Portswigger] [Broken Access Control] [2026] CryptHawk 21 views - 2 months ago
2:49 User role controlled by request parameter | [Portswigger] [Broken Access Control] [2026] CryptHawk 38 views - 1 month ago
3:45 User ID Controlled by request parameter with data leakage in redirect |[PortSwigger] [Burp] [2026] CryptHawk 14 views - 1 month ago
6:04 Insecure Deserialization Lab #5 | Exploiting Java deserialization with Apache Commons | PortSwigger CryptHawk 13 views - 3 days ago
3:58 User ID controlled by request parameter with password disclosure |[PortSwigger] [Burp] [2026] CryptHawk 40 views - 1 month ago
7:57 Infinite Money Logic Flaw | [PortSwigger] [Burp] [Turbo Intruder] [2026] CryptHawk 84 views - 1 month ago
3:59 Referer Based Access Control | [Access Control Lab #13] [PortSwigger] [2026] CryptHawk 21 views - 1 month ago
4:55 2FA Bypass Using a Brute-force Attack | [Turbo Intruder] [Burp CE] [2026] CryptHawk 263 views - 2 months ago
4:42 User ID Controlled By Request Parameter, With Unpredictable User IDs | [PortSwigger] [2026] CryptHawk 14 views - 1 month ago
5:18 Method Based Access Control Can Be Circumvented | [Access Control Lab #11] [PortSwigger] [2026] CryptHawk 15 views - 1 month ago
12:14 Username Enumeration via Response Timing |[BURP CE] [FFUF] [FAST] [2026] CryptHawk 51 views - 2 months ago
3:49 URL-Based Access Control Can Be Circumvented | [Access Control Lab #10] [PortSwigger] [2026] CryptHawk 33 views - 1 month ago