JWT security labs
CompletedToken tampering, none-alg abuse, weak secrets, key header injection, JWKS, JKU, KID, and algorithm confusion.
open write-up ->A recruiter-friendly view of my cybersecurity progression: what I have already written up, what I am actively strengthening, and what comes next on the BSCP → OSCP track.
Token tampering, none-alg abuse, weak secrets, key header injection, JWKS, JKU, KID, and algorithm confusion.
open write-up ->Union-based SQLi, blind SQLi, conditional responses, conditional errors, time delays, Oracle and non-Oracle enumeration.
open write-up ->Challenge discovery, XSS, login bypasses, request manipulation, and Burp-driven testing against a modern vulnerable app.
open write-up ->Enumeration, SUID, sudo rights, PATH hijacking, cron jobs, capabilities, kernel exploits, and post-exploitation workflow.
open reference ->Proxy, Repeater, Intruder, Decoder, Comparer, and a practical manual testing workflow for web assessments.
open guide ->NAS experimentation, local website exposure, tunneling, SMB, device access, and practical infrastructure troubleshooting.
open build ->Access control, SSRF, OAuth, web cache deception, WebSockets, and authentication flaws. These should become future write-up clusters.
watch the archive ->Linux/Windows enumeration, privilege escalation, tunneling, Active Directory basics, exploit adaptation, and report writing.
start from Linux notes ->