Exploits Explained: Vulnerabilities & Exploit Techniques

PENTESTING SECRETS

Exploits Explained

The Exploits Explained series features technical vulnerability insights from the elite security researchers on the Synack Red Team. It offers a vetted forum for this global community of hackers to share the discovery of real-world vulns, offer tips for uncovering common exploit paths and unpack their use of GenAI tools.

Recent Articles


Dissecting Stored XSS in SAP Concur Open: Event Handler Bypass and Regex Evasion Tactics - Read more


Déjà Vu with a Recurring DOM-Based XSS Vuln - Read more


Going from IDOR to account takeover for fun and profit - Read more


Discovering a Server-Side Template Injection Vuln in FreeMarker - Read more


Unmasking Harmful Content in a Healthcare Chatbot: A Red Team Perspective - Read more


Tricking AI to Enable SQL Injection Attacks - Read more


Dumping a Database with an AI Chatbot - Read more


Multi-factor Authentication Bypass Examples via Response Tampering - Read more


ZIP embedding attack on Google Chrome extensions - Read more


Defeating length filters to enable SQL injection - Read more


Attacking Open Internet Proxy Servers - Read more


Persisting Through a Client-Side Prototype Pollution - Read more


Finding Flaws in an ATM Software Tool - Read more


Escalating Privileges With SSRF - Read more


Exploits Explained: Navigating Caches & Firewalls Bypasses for XSS - Read more


Exploits Explained: Using APIs to Execute a Server-Side Request Forgery - Read more