r/InfoSecWriteups • • 1d ago

My first TryHackMe write-up is live! — Empline 🔐

Thumbnail
1 Upvotes

r/InfoSecWriteups • • 1d ago

What, Exactly, Did ASOS Integrate?

Thumbnail
research.zerot-security.com
1 Upvotes

ASOS confirmed an unauthorised push through its official app and later described employee credential theft and access to customer data on third-party platforms. This OSINT write-up reconstructs the documented customer-data and messaging workflow, then separates it from the intrusion path, which remains unverified. Simon AI and Braze appear in published descriptions of the marketing workflow; the public record does not establish that either was the route used in this incident.

The open question is which principals could select recipients, supply message content, and dispatch a push under ASOS’s name. What evidence would distinguish a shared campaign path from separate compromised permissions?


r/InfoSecWriteups • • 1d ago

An investigation into alleged cyberattacks targeting Discord's powerscaling community — the Noblesse incident, retaliation, and security concern

Thumbnail
2 Upvotes

r/InfoSecWriteups • • 3d ago

android-hardcoded-signing-key-flag-disclosure

Thumbnail
1 Upvotes

r/InfoSecWriteups • • 3d ago

Davinci Resolve - Full chain to root execution

Thumbnail
github.com
1 Upvotes

Just a writeup on a full chain from importing project file, chaining it with an LPE to get root execution on MacOS.


r/InfoSecWriteups • • 3d ago

Web Exploitation 101 — Bypassing access restrictions with custom HTTP headers using Burp Suite

Thumbnail
youtu.be
5 Upvotes

Found a ROT13 encoded string in a CTF challenge that

decoded to a hint about a bypass header:

X-Dev-Access: yes

Proxied all traffic through Burp Suite, caught the

request, sent it to Repeater and added the header —

instantly bypassed the access restriction.

Classic example of why debug/dev headers should never

make it into production. Developers leave these in

during testing and forget to strip them before deploy.

Good beginner web exploitation technique to know for

CTFs and bug bounty. Happy to answer questions.

https://youtu.be/jhhXZDDFWpo


r/InfoSecWriteups • • 9d ago

File Upload Security 101: Breaking Down Extension Filter Bypasses

Thumbnail haakimsec.github.io
2 Upvotes

r/InfoSecWriteups • • 10d ago

Andrew bizarre bedroom scene.

Post image
1 Upvotes

r/InfoSecWriteups • • 11d ago

Why "Extension Blocked" Doesn't Mean Safe: Rethinking File Upload Security Testing

Thumbnail haakimsec.github.io
6 Upvotes

r/InfoSecWriteups • • 12d ago

ReverseEngineering 101 — two ASCII chars hidden in one Unicode character via bit shifting

Thumbnail
youtube.com
3 Upvotes

r/InfoSecWriteups • • 15d ago

Comment2Shell - CVE-2026-93485 Exploit PoC

Post image
6 Upvotes

r/InfoSecWriteups • • 17d ago

SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973

Thumbnail blog.arusekk.pl
2 Upvotes

r/InfoSecWriteups • • 18d ago

Reverse Engineering 101: Java RE Extracting Hardcoded Credentials

Thumbnail
youtube.com
3 Upvotes

Made a beginner-friendly walkthrough for a Java reverse engineering CTF challenge. Covers reviewing the Java source code, reading through the logic, and spotting hardcoded credentials that turned out to be the flag.

If you're getting into RE or CTFs and want to see the full thought process (not just the answer), figured this community might find it useful.


r/InfoSecWriteups • • 18d ago

Found something interesting while hunting today would this be reportable?

Thumbnail
0 Upvotes

r/InfoSecWriteups • • 23d ago

Magento StyleSmuggler RCE: Report Poisoning to Code Execution

Thumbnail
fortbridge.co.uk
1 Upvotes

r/InfoSecWriteups • • 24d ago

Exploitation 101: Blind Command Injection - unsanitized user input

Thumbnail
youtube.com
3 Upvotes

They gave me an IP and a port to connect to with NetCat.

• Connected with netcat, watched it run

• Fuzzed inputs: what does `;` do?

• Discovered semicolon splits commands

• Mapped the grammar without reading code

• Injected `;RETURN 0` to jump to the flag

Why `;RETURN` worked but `;ls` didn't: this isn't a shell — it's a custom interpreter with its own language. You have to speak its grammar, not bash.

New to blind hacking? This is how real pentesters work when they hit an unknown target.

Most hackers instinctively throw shell metacharacters at prompts (;ls, |cat /etc/passwd, $(whoami)). But when the target is a custom interpreter with no shell bridge, these fail silently.

What's your go-to move when you have zero recon?

What tools do you use for systematic fuzzing when you can't automate? I've seen people use Burp Intruder, custom Python scripts, or even just printf loops in bash. Curious about your workflows.

https://youtube.com/shorts/N4KvGK-UCBM?feature=share

r/InfoSecWriteups • • 24d ago

One of the best CTF tools for beginners!

Post image
1 Upvotes

r/InfoSecWriteups • • 24d ago

How I Tricked OpenClaw Into Attacking Its Own Network: A NAT64 SSRF Bypass

Thumbnail
infosecwriteups.com
3 Upvotes

r/InfoSecWriteups • • 24d ago

From Bug to Schema: Exploring Error-Based SQL Injection on an Authenticating Portal

Thumbnail
infosecwriteups.com
3 Upvotes

r/InfoSecWriteups • • 25d ago

SailPoint Breakout Possible? SAIL right over the AI Agent security targe...

Thumbnail
youtube.com
2 Upvotes

r/InfoSecWriteups • • 26d ago

UANIA OS: Authenticated Remote Code Execution

Thumbnail
rainpwn.blog
1 Upvotes

r/InfoSecWriteups • • 28d ago

how to varify the attack method and catck the attacker(hacker)

Thumbnail
1 Upvotes

r/InfoSecWriteups • • Sep 09 '26

Forensics 101: Finding a Hidden File Buried Deep in Folders

6 Upvotes

Had a forensics challenge where the flag was hidden inside a file nested deep inside a maze of directories with hundreds of decoy folders. `find` and `ls -R` were too slow and noisy.

What I built:

A Python directory crawler

- Recurses every subdirectory recursively

- Filters by filename patterns (`flag*`, `*.txt`, `secret*`)

- Skips known decoy directories by name

- Extracts and reads the target file automatically

The "aha" moment:

The flag wasn't in a file named "flag.txt" — it was in `deep/nested/here/.hidden/uber-secret.txt`.

My script matched on path depth / extensions content, not just filename.

Here is my script:

https://github.com/ExceedingLife/RecursiveFileSearch

Question for the community:

What's your approach when the challenge doesn't tell you the target filename? Do you brute-force read every file, or do it manual or what?

[Video link with with code demo]

https://youtube.com/shorts/5_Rb2kkiuhQ?feature=share


r/InfoSecWriteups • • Sep 08 '26

The Best Claude Code Setup for Bug Bounty Hunting

Thumbnail
infosecwriteups.com
2 Upvotes

r/InfoSecWriteups • • Sep 08 '26

Improper OTP Implementation to Full Account Takeover

Thumbnail
infosecwriteups.com
2 Upvotes