Exploits Explained: Vulnerabilities & Exploit Techniques
PENTESTING SECRETS
Exploits Explained
The Exploits Explained series features technical vulnerability insights from the elite security researchers on the Synack Red Team. It offers a vetted forum for this global community of hackers to share the discovery of real-world vulns, offer tips for uncovering common exploit paths and unpack their use of GenAI tools.
Recent Articles
Dissecting Stored XSS in SAP Concur Open: Event Handler Bypass and Regex Evasion Tactics - Read more
Déjà Vu with a Recurring DOM-Based XSS Vuln - Read more
Going from IDOR to account takeover for fun and profit - Read more
Discovering a Server-Side Template Injection Vuln in FreeMarker - Read more
Unmasking Harmful Content in a Healthcare Chatbot: A Red Team Perspective - Read more
Tricking AI to Enable SQL Injection Attacks - Read more
Dumping a Database with an AI Chatbot - Read more
Multi-factor Authentication Bypass Examples via Response Tampering - Read more
ZIP embedding attack on Google Chrome extensions - Read more
Defeating length filters to enable SQL injection - Read more
Attacking Open Internet Proxy Servers - Read more
Persisting Through a Client-Side Prototype Pollution - Read more
Finding Flaws in an ATM Software Tool - Read more
Escalating Privileges With SSRF - Read more
Exploits Explained: Navigating Caches & Firewalls Bypasses for XSS - Read more
Exploits Explained: Using APIs to Execute a Server-Side Request Forgery - Read more