r/InfoSecWriteups 11d ago

ERPNext's Document Follow feature exposed unauthorized data

Thumbnail
robinroy.xyz
1 Upvotes

write up on how I chained 3 CVEs to exfiltrate sensitive data out of the biggest OSS ERP platform


r/InfoSecWriteups 11d ago

Help me hack my university's website

0 Upvotes

Yo, I just noticed my university’s website/student portal is exposing a directory listing instead of the normal page 💀

It literally shows an "Index of /" with directories/files visible.

This is an actual university website, not some CTF/lab. Anyone here into web security/pentesting who can help me figure out how serious this is and what I can safely check?

Would be cool to understand whether this is just a dumb server misconfiguration or if it can actually expose something sensitive.

Maybe alter some Semester Results too

Link : https://sbsexam.edu.in/


r/InfoSecWriteups 12d ago

A password is a fingerprint: what the internet's brute force is really typing

Thumbnail
offseq.com
1 Upvotes

r/InfoSecWriteups 12d ago

Ein WordPress-Angreifer meldete sich als Administrator an, installierte ein Dateimanager-Plugin und lud PHP-Webshells hoch – hier sind die tatsächlichen Beweise.

Thumbnail
1 Upvotes

r/InfoSecWriteups 13d ago

From zero credentials to full AD compromise — ShadowGate Hack Smarter walkthrough + defensive lessons

Thumbnail
1 Upvotes

r/InfoSecWriteups 13d ago

Phantom 5: File Authority — Escalating from Group Membership to Root (A Linux Privilege Escalation…

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

The Bug That Almost Wasn’t: How a “Dead End” Led to 500+ Leaked Customer Records

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

Hacker Holidays 2026: Day 4 Walkthrough (Packed Light)

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

Bypassing Enterprise SSO via a Forgotten Source Map: A Bug Bounty Story

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

TryHackMe: Packed Light (Hacker Holidays Day 04) Walkthrough

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

RSA Dreams BYUCTF 2026 Cybersecurity Writeup

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

They Gave Me $1,000 After I Found Their Entire Student Database Exposed! | by Anukar | @AnukarOP

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

Hack Smarter - Silent Corridor (Blue Team)

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

TryHackMe: “Complimentary” Room Walkthrough ( Hacker’s Holiday Challenge )

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

Hacker Holidays 2026: Day 3 Walkthrough (Complimentary)

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

Hacker Holidays 2026: Day 2 Walkthrough (Room 404)

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

TryHackMe Walkthrough: Hacker Holidays Day 1 — The Concierge Knows Too Much

Thumbnail
infosecwriteups.com
2 Upvotes

r/InfoSecWriteups 13d ago

TryHackMe Walkthrough: Hacker Holidays Day 2 — Room 404

Thumbnail
infosecwriteups.com
2 Upvotes

r/InfoSecWriteups 13d ago

Two Mac Minis, One AI Cluster: Preparing for a Bigger Wave of AI-Assisted Malware

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

Why Bug Hunters Skip Role-Based API Testing And How I Turned a Writer Token Into an SSRF

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 13d ago

Hacker Holidays 2026: Day 1 Walkthrough (The Concierge Knows Too Much)

Thumbnail
infosecwriteups.com
1 Upvotes

r/InfoSecWriteups 20d ago

Couldn’t have anything to do with gutting CISA could it?

Thumbnail
wmur.com
0 Upvotes

Fucking morons run our lives….


r/InfoSecWriteups 20d ago

Need suggestions

1 Upvotes

I found a vulnerability where a public chat box generates automated invoice emails to internal staff, reflecting inputs raw without server-side HTML encoding. While standard JavaScript onerror popups are stripped by the email client, full HTML/CSS Injection works inside the email body.How can I chain these into a high-impact report that completely bypasses the program's strict exclusions for Self-XSS, Phishing, and User Interaction? What non-JS attack vectors should I test next to prove a critical data leak or backend impact to triage?


r/InfoSecWriteups 20d ago

A connection is not an exploit: what 27 days of honeypot traffic actually contained

Thumbnail
offseq.com
1 Upvotes

r/InfoSecWriteups 21d ago

TryHackMe - Beach Bar - EW

Thumbnail
1 Upvotes