Open in app

Sign In

Write

Sign In

Frank Leitner
Frank Leitner

225 Followers

Home

Lists

About

Pinned

CISSP: Exam thoughts and learning materials

I often read that the exam is tough and full of trick questions that try to guide you to the wrong answer. In my case, none of the questions I encountered I would consider trick questions. But I understand why this perception exists and why many technical people find the…

Cissp

4 min read

CISSP: Exam thoughts and learning materials
CISSP: Exam thoughts and learning materials
Cissp

4 min read


Pinned

Yet another OSCP story

Finally, after a long COVID-19 induced delay, I recently received my printed certificate. This is yet another story about the journey towards OSCP. I’ll give my impressions of the course and the steps I used to prepare for the exam. …

Oscp

14 min read

Yet another OSCP story
Yet another OSCP story
Oscp

14 min read


Published in InfoSec Write-ups

·Feb 6

Write-up: Information disclosure in version control history @ PortSwigger Academy

This write-up for the lab Information disclosure in version control history is part of my walkthrough series for PortSwigger’s Web Security Academy. Learning path: Server-side topics → Information disclosure Lab: Information disclosure in version control history | Web Security Academy Practise exploiting vulnerabilities on realistic targets. Record your progression from Apprentice to Expert. See where…portswigger.net

Cybersecurity

3 min read

Write-up: Information disclosure in version control history @ PortSwigger Academy
Write-up: Information disclosure in version control history @ PortSwigger Academy
Cybersecurity

3 min read


Published in InfoSec Write-ups

·Dec 20, 2022

Write-up: Authentication bypass via encryption oracle @ PortSwigger Academy

This write-up for the lab Authentication bypass via encryption oracle is part of my walk-through series for PortSwigger’s Web Security Academy. Learning path: Server-side topics → Business logic vulnerabilities Lab: Authentication bypass via encryption oracle | Web Security Academy This lab contains a logic flaw that exposes an encryption oracle to users. To solve the lab, exploit this flaw to gain…portswigger.net

Cybersecurity

6 min read

Write-up: Authentication bypass via encryption oracle @ PortSwigger Academy
Write-up: Authentication bypass via encryption oracle @ PortSwigger Academy
Cybersecurity

6 min read


Published in InfoSec Write-ups

·Dec 13, 2022

Write-up: DOM XSS in innerHTML sink using source location.search @ PortSwigger Academy

This write-up for the lab DOM XSS in innerHTML sink using source location.search is part of my walkthrough series for PortSwigger’s Web Security Academy. Learning path: Client-side topics → Cross-site scripting Lab: DOM XSS in innerHTML sink using source location.search | Web Security Academy Practise exploiting vulnerabilities on realistic targets. Record your progression from Apprentice to Expert. See where…portswigger.net

Cybersecurity

2 min read

Write-up: DOM XSS in innerHTML sink using source location.search @ PortSwigger Academy
Write-up: DOM XSS in innerHTML sink using source location.search @ PortSwigger Academy
Cybersecurity

2 min read


Published in InfoSec Write-ups

·Dec 12, 2022

Write-up: SQL injection with filter bypass via XML encoding @ PortSwigger Academy

This write-up for the lab SQL injection with filter bypass via XML encoding is part of my walk-through series for PortSwigger’s Web Security Academy. Learning path: Server-side topics → SQL injection Lab: SQL injection with filter bypass via XML encoding | Web Security Academy Identify the vulnerability Observe that the stock check feature sends the productId and storeId to the application in…portswigger.net

Cybersecurity

5 min read

Write-up: SQL injection with filter bypass via XML encoding @ PortSwigger Academy
Write-up: SQL injection with filter bypass via XML encoding @ PortSwigger Academy
Cybersecurity

5 min read


Published in InfoSec Write-ups

·Dec 10, 2022

Write-up: DOM XSS in document.write sink using source location.search @ PortSwigger Academy

This write-up for the lab DOM XSS in document.write sink using source location.search is part of my walkthrough series for PortSwigger’s Web Security Academy. Learning path: Client-side topics → Cross-site scripting Lab: DOM XSS in document.write sink using source location.search | Web Security Academy Practise exploiting vulnerabilities on realistic targets. Record your progression from Apprentice to Expert. See where…portswigger.net

Cybersecurity

3 min read

Write-up: DOM XSS in document.write sink using source location.search @ PortSwigger Academy
Write-up: DOM XSS in document.write sink using source location.search @ PortSwigger Academy
Cybersecurity

3 min read


Published in InfoSec Write-ups

·Nov 30, 2022

Write-up: Source code disclosure via backup files @ PortSwigger Academy

This write-up for the lab Source code disclosure via backup files is part of my walkthrough series for PortSwigger’s Web Security Academy. Learning path: Server-side topics → Information disclosure Lab: Source code disclosure via backup files | Web Security Academy This lab leaks its source code via backup files in a hidden directory. To solve the lab, identify and submit the…portswigger.net Python script: script.py

Cybersecurity

3 min read

Write-up: Source code disclosure via backup files @ PortSwigger Academy
Write-up: Source code disclosure via backup files @ PortSwigger Academy
Cybersecurity

3 min read


Published in InfoSec Write-ups

·Nov 28, 2022

Write-up: Basic server-side template injection (code context) @ PortSwigger Academy

This write-up for the lab Basic server-side template injection (code context) is part of my walk-through series for PortSwigger’s Web Security Academy. Learning path: Advanced topics → Server-side template injection Lab: Basic server-side template injection (code context) | Web Security Academy Practise exploiting vulnerabilities on realistic targets. Record your progression from Apprentice to Expert. See where…portswigger.net

Cybersecurity

4 min read

Write-up: Basic server-side template injection (code context) @ PortSwigger Academy
Write-up: Basic server-side template injection (code context) @ PortSwigger Academy
Cybersecurity

4 min read


Published in System Weakness

·Nov 26, 2022

Write-up: Stored XSS into HTML context with nothing encoded @ PortSwigger Academy

This write-up for the lab Stored XSS into HTML context with nothing encoded is part of my walkthrough series for PortSwigger’s Web Security Academy. Learning path: Client-side topics → Cross-site scripting Lab: Stored XSS into HTML context with nothing encoded | Web Security Academy Practise exploiting vulnerabilities on realistic targets. Record your progression from Apprentice to Expert. See where…portswigger.net

Cybersecurity

3 min read

Write-up: Stored XSS into HTML context with nothing encoded @ PortSwigger Academy
Write-up: Stored XSS into HTML context with nothing encoded @ PortSwigger Academy
Cybersecurity

3 min read

Frank Leitner

Frank Leitner

225 Followers

Tech nerd, doing security stuff for fun and some as a job | CISSP, OSCP. Read all stories on medium and support me: https://medium.com/@frank.leitner/membership

Following
  • Prof Bill Buchanan OBE

    Prof Bill Buchanan OBE

  • Taimur Ijlal

    Taimur Ijlal

  • Rosie Kay aka ThisKindaGirl

    Rosie Kay aka ThisKindaGirl

  • Karol Mazurek

    Karol Mazurek

  • Hacktivities

    Hacktivities

See all (14)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech