HTB Nexus — Git Template Sync Path Traversal to Root
From a leaked .env in Gitea commit history to a Krayin CRM upload RCE, password reuse into jones, and a raw git object-model trick abusing an unsanitized path join in a root-run template-sync script to write an SSH key into /root/.ssh/authorized_keys.
2092 words
|
10 minutes
IDOR in Haryana Higher Education Admissions Portal: Unauthenticated Access to Student Documents
Broken Access Control / IDOR vulnerability in the Haryana admissions portal allowing unauthenticated access to student-uploaded documents (certificates, photos, signatures) via predictable URLs containing registration IDs.
592 words
|
3 minutes
Cover Image of the Post
You Are Never Browsing Alone
How cross-device tracking and data brokers connect your activity across phones, computers, and apps — even when using different accounts. Real mechanisms used by major platforms and how to raise the cost of being tracked.
1327 words
|
7 minutes
ExpressionEngine Preview Flaw: How Anyone Could Read Private Drafts and Hidden Content
How a preview feature in ExpressionEngine let unauthenticated attackers read any private draft, closed entry, or future content by tricking the system into ignoring all visibility rules.
905 words
|
5 minutes
Cover Image of the Post
That Time I Accidentally Sent My NTLM Hash to My Own Server (And What I Learned)
That Time I Accidentally Sent My NTLM Hash to My Own Server (And What I Learned) A casual dive into Windows authentication quirks So I was messing around i...
1135 words
|
6 minutes
Intigriti December 2025 Challenge: Unsafe postMessage + eval() XSS
DOM-based XSS via an insecure postMessage handler that used eval() with no origin validation. A 48-character prefix was required before arbitrary JavaScript could be executed in the challenge context.
610 words
|
3 minutes
SantaCloud Intigriti 2025: Exposed Backup File Leads to Admin Takeover and Private Notes IDOR
Chained vulnerability in SantaCloud: robots.txt disclosure → composer.json~ backup leak → hardcoded admin credentials → full account takeover → IDOR allowing access to any user's private notes and flags.
564 words
|
3 minutes
Intigriti Challenge 1125
Critical Pre-Auth RCE via JWT none Algorithm + Jinja2 SSTI in Admin Profile
600 words
|
3 minutes
1
2