New Post December 22, 2025 A $3,500-Worth HTML Injection by Abusing CSRF-like This article explains how an HTML injection vulnerability can be abused to bypass the usual limitations of CSRF, allowing attackers to execute sensitive actions. #bugbounty
November 10, 2025 Brute Forcing Web Logins Using FFuF FFuF offers a lightweight and fast alternative to heavy Burp Suite (Intruder) for cracking web logins. #tutorial
October 11, 2025 Cracking a JWT Secret Key (HS256) with Hashcat How a weak JWT Secret Key can be cracked using Hashcat, allowing attackers to forge valid sessions and abuse authentication. #technique