**PENTESTING SECRETS**

# Exploits Explained

The Exploits Explained series features technical vulnerability insights from the elite security researchers on the Synack Red Team. It offers a vetted forum for this global community of hackers to share the discovery of real-world vulns, offer tips for uncovering common exploit paths and unpack their use of GenAI tools.

## Recent Articles

\
Dissecting Stored XSS in SAP Concur Open: Event Handler Bypass and Regex Evasion Tactics - [Read more](/content/exploits-explained/dissecting-stored-xss-in-sap-concur-open-event-handler-bypass-and-regex-evasion-tactics/index.html)

\
Déjà Vu with a Recurring DOM-Based XSS Vuln - [Read more](/content/exploits-explained/exploits-explained-deja-vu-with-a-recurring-dom-based-xss-vuln/index.html)

\
Going from IDOR to account takeover for fun and profit - [Read more](/content/exploits-explained/exploits-explained-going-from-idor-to-account-takeover-for-fun-and-profit/index.html)

\
Discovering a Server-Side Template Injection Vuln in FreeMarker - [Read more](/content/exploits-explained/exploits-explained-discovering-a-server-side-template-injection-vuln-in-freemarker/index.html)

\
Unmasking Harmful Content in a Healthcare Chatbot: A Red Team Perspective - [Read more](/content/exploits-explained/unmasking-harmful-content-in-a-medical-chatbot-a-red-team-perspective/index.html)

\
Tricking AI to Enable SQL Injection Attacks - [Read more](/content/exploits-explained/exploits-explained-tricking-ai-to-enable-sql-injection-attacks/index.html)

\
Dumping a Database with an AI Chatbot - [Read more](/content/exploits-explained/dumping-a-database-with-an-ai-chatbot/index.html)

\
Multi-factor Authentication Bypass Examples via Response Tampering - [Read more](/content/exploits-explained/multi-factor-authentication-bypass-examples-via-response-tampering/index.html)

\
ZIP embedding attack on Google Chrome extensions - [Read more](/content/exploits-explained/exploits-explained-zip-embedding-attack-on-google-chrome-extensions/index.html)

\
Defeating length filters to enable SQL injection - [Read more](/content/exploits-explained/exploits-explained-defeating-length-filters-to-enable-sql-injection/index.html)

\
Attacking Open Internet Proxy Servers - [Read more](/content/exploits-explained/exploits-explained-attacking-open-internet-proxy-servers/index.html)

\
Persisting Through a Client-Side Prototype Pollution - [Read more](/content/exploits-explained/persisting-through-a-client-side-prototype-pollution/index.html)

\
Finding Flaws in an ATM Software Tool - [Read more](/content/exploits-explained/exploits-explained-finding-flaws-in-an-atm-software-tool/index.html)

\
Escalating Privileges With SSRF - [Read more](/content/exploits-explained/exploits-explained-escalating-privileges-with-ssrf/index.html)

\
Exploits Explained: Navigating Caches & Firewalls Bypasses for XSS - [Read more](/content/exploits-explained/navigating-caches-firewall-bypass-xss/index.html)

\
Exploits Explained: Using APIs to Execute a Server-Side Request Forgery - [Read more](/content/exploits-explained/exploits-explained-using-apis-to-execute-a-server-side-request-forgery/index.html)
