Post per il tag: xss

My First Writeup - Emoji Letters | Romhack CTF 2022

This is the first writeup i wrote back in 2022, just after the RomHack CTF.

Pages | Imaginary CTF Round 53

ETag reuse and Firefox’s 304 caching flaw enable a CSP sandbox bypass

HTB CA 2025 - Web Writeups

At HTB Cyber Apocalypse 2025, I chained multiple exploits—from web SSRF and header injection to stored XSS and PostgreSQL RCE—to gain full remote code execution. This post details both the unintended and intended approaches.