Cookie Theft via TLS Downgrade: Exploiting and Fixing Cryptographic Failures (OWASP A04:2025)
Use mitmproxy to steal a session cookie sent over plaintext HTTP, then fix it with HTTPS, Secure/HttpOnly/SameSite cookie flags, and…
// ethical hacking, plainly explained
Practical write-ups on AI security, web app testing, code review and DevSecOps, from someone who does the work.
Six areas, all written to be applied on real systems.
Use mitmproxy to steal a session cookie sent over plaintext HTTP, then fix it with HTTPS, Secure/HttpOnly/SameSite cookie flags, and…
Build a Node.js project with a malicious postinstall script that exfiltrates a secret, then generate an SBOM, detect the rogue…
Scan a deliberately misconfigured Docker Compose stack with curl and nikto, then apply a hardened Nginx config and prove the…
Deploy your app in seconds. Free tier included.
Walk through IDOR and forced-browsing exploits in a Flask notes app, then fix them with ownership checks and a role-required…
Break a tool-calling agent with a hidden prompt injection in a local lab, then fix it with a deny-by-default tool…
A benign pickle payload proves that loading an untrusted model file can execute arbitrary code — then a picklescan +…
Build a small local assistant, break it with direct and indirect prompt injection (including markdown-image and tool-call exfiltration), then add…
Learn PowerShell's object pipeline, Verb-Noun cmdlets, file, process and service commands, CSV/JSON export, and why execution policy is not security.
Most “learn to hack” courses stop at tool usage. The ones worth your time teach you why a technique works,…
// courses
Join the waitlist to hear when the first course opens.
// weekly roundup
A short roundup plus the newest tutorial. Unsubscribe any time.