HackCert

// field_notes

The Hackcert Blog

389 field-grade guides on offensive ops, blue-team detection, cloud security, AI red-teaming and more — written for engineers who ship.

Showing posts for tag: Web Security Clear
API Security: Is Data Leaking Through Your Modern Web App APIs?
Intermediate 8 min read

API Security: Is Data Leaking Through Your Modern Web App APIs?

Explore the hidden vulnerabilities in modern web application APIs and understand how attackers exploit them to exfiltrate sensitive data.

Mohammad Saiful IslamAPI SecurityWeb SecurityIntermediate
Blind SQLi: Advanced Techniques to Extract Sensitive Data from Databases
Intermediate 12 min read

Blind SQLi: Advanced Techniques to Extract Sensitive Data from Databases

Master the intricacies of Blind SQL Injection, learning how attackers extract data by asking true/false questions and measuring database response times.

Mahmuda AkterBlind SQLiWeb SecurityCybersecurity
Cache Poisoning: Manipulating Web Servers to Serve Malicious Payloads
Intermediate 8 min read

Cache Poisoning: Manipulating Web Servers to Serve Malicious Payloads

Delve into the complexities of Web Cache Poisoning. Discover how attackers manipulate caching mechanisms to distribute malicious content and compromise countless users simultaneously.

Rokibul IslamCache PoisoningCybersecurityIntermediate
Clickjacking: The Invisible Threat Hijacking Your Clicks
Intermediate 8 min read

Clickjacking: The Invisible Threat Hijacking Your Clicks

Unmask the deception of Clickjacking (UI Redressing). Learn how attackers use invisible layers to trick users into performing unintended actions, and how to defend your web applications.

Rokibul IslamClickjackingCybersecurityIntermediate
CORS Misconfiguration: Risk of Data Leaks Due to Web Application Configuration Errors
Intermediate 10 min read

CORS Misconfiguration: Risk of Data Leaks Due to Web Application Configuration Errors

Explore the critical impact of CORS misconfigurations on web applications, how attackers exploit them, and best practices to prevent severe data leaks.

Rokibul IslamWeb SecurityCybersecurityIntermediate
CSRF Exploitation: Forcing Unauthorized Actions Without the User's Knowledge
Advanced 10 min read

CSRF Exploitation: Forcing Unauthorized Actions Without the User's Knowledge

Discover the mechanics of Cross-Site Request Forgery (CSRF), how attackers exploit browser behavior to force unauthorized actions, and strategies to secure your applications.

Rokibul IslamWeb SecurityCybersecurityAdvanced
DNS Attacks Explained: How Hackers Reroute Users to Malicious Sites
Advanced 14 min read

DNS Attacks Explained: How Hackers Reroute Users to Malicious Sites

Dive into the advanced mechanics of DNS Attacks, exploring how cybercriminals hijack the Domain Name System to manipulate traffic and deceive users.

Mohammad Saiful IslamNetwork SecurityAdvancedCybersecurity
IDOR Exploitation: Stealing Data Using Insecure Direct Object References
Advanced 8 min read

IDOR Exploitation: Stealing Data Using Insecure Direct Object References

A deep dive into Insecure Direct Object References (IDOR), exploring advanced exploitation techniques, impact analysis, and robust mitigation strategies for web applications.

Mohammad Saiful IslamWeb SecurityCybersecurityAdvanced
JWT Bruteforcing: How Attackers Manipulate JSON Web Tokens for Server Access
Intermediate 10 min read

JWT Bruteforcing: How Attackers Manipulate JSON Web Tokens for Server Access

Understand the mechanics of JSON Web Token (JWT) bruteforcing, how weak signing keys lead to total system compromise, and robust defense strategies.

Abdullah Al MamunWeb SecurityAuthenticationCybersecurity
Mass Assignment: Exploiting Web API Vulnerabilities for Privilege Escalation
Intermediate 10 min read

Mass Assignment: Exploiting Web API Vulnerabilities for Privilege Escalation

Understand the mechanics of Mass Assignment vulnerabilities in modern web APIs. Learn how attackers manipulate object parameters to elevate their privileges.

Rokibul IslamWeb SecurityAPI SecurityVulnerability
$ show_operator_page --current=1 --total=3
01 / 03
Showing 1-10 of 24 entries