Tag: {{ tagName }} | Tağmaç - root@Tagoletta:~#

Tag: Exploit

Windows Credential Access: LSASS, DPAPI, SAM, and Browser Secrets

Mon Jun 29 2026

Security Research

A complete attacker's guide to Windows credential access: LSASS internals and SSP architecture, DPAPI master key...

AD Certificate Services Deep Dive: ESC1 to ESC8 Attack Paths

Mon Jun 29 2026

Security Research

A deep-dive into every ADCS misconfiguration from ESC1 to ESC10: template flag analysis, certificate anatomy, NTLM relay...

Active Directory Security Testing: The Complete Attacker's Perspective

Mon Jun 29 2026

Security Research

A complete attacker's methodology for Active Directory assessments: enumeration, Kerberoasting, AS-REP Roasting,...

Web Cache Deception & Poisoning: Weaponizing the Gap Between Cache and Origin

Sat Jun 13 2026

Security Research

Two sides of cache abuse — Web Cache Deception tricks a CDN into storing a victim's private page, while Web Cache...

SSRF to Cloud Credentials: Stealing AWS IAM Tokens via Metadata API

Thu May 28 2026

Security Research

How a single Server-Side Request Forgery vulnerability can escalate to full AWS/GCP/Azure account compromise by...

HTTP Request Smuggling: Exploiting Front-End/Back-End Parsing Desync

Thu May 28 2026

Security Research

How attackers exploit disagreements between front-end and back-end servers on where HTTP requests begin and end — and...

Blind SSTI to RCE: Exploiting Template Engines Without Output

Thu May 28 2026

Security Research

How attackers detect and exploit Server-Side Template Injection when the application returns no output — using timing...

Prototype Pollution to RCE: Node.js Gadget Chains Explained

Wed May 27 2026

Security Research

How injecting properties into JavaScript's Object.prototype poisons the entire Node.js process — and how gadget chains...

Single-Packet Race Condition: Sub-Millisecond Web Exploitation

Wed May 27 2026

Security Research

How the single-packet attack technique eliminates network jitter to exploit sub-millisecond race conditions in web...

Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server

Wed May 27 2026

Security Research

How Orange Tsai's Confusion Attacks exploit URL decoding inconsistencies across Apache modules to chain ACL bypass,...

CVE-2025-69460 – Simple Image Gallery 1.0 - Remote Code Execution (Unauthenticated)

Wed Jan 21 2026

Security Research

CVE-2025-69460: Unauthenticated Remote Code Execution (RCE) vulnerability in Simple Image Gallery 1.0. Zero-day...

CVE-2025-69457 – Responsive Tourism Website 3.1 - Remote Code Execution (Unauthenticated)

Wed Jan 21 2026

Security Research

CVE-2025-69457: Unauthenticated Remote Code Execution (RCE) vulnerability in Responsive Tourism Website 3.1. Zero-day...

CVE-2025-69458 – Movie Rating System 1.0 - SQL Injection to RCE (Unauthenticated)

Wed Jan 21 2026

Security Research

CVE-2025-69458: Unauthenticated SQL Injection to Remote Code Execution (RCE) vulnerability in Movie Rating System 1.0....

CVE-2025-69459 – Movie Rating System 1.0 - Broken Access Control

Wed Jan 21 2026

Security Research

CVE-2025-69459: Broken Access Control vulnerability allowing Admin Account Creation in Movie Rating System 1.0. Zero-day...

Traffic Offense Management System 1.0 - Remote Code Execution (Unauthenticated)

Wed Aug 18 2021

Security Research

Zero-Day Discovery & Exploit Development: unauthenticated SQL Injection to RCE in Traffic Offense Management System 1.0....