SQL Injection Without Spaces Using Brackets

In some SQL injection vulnerabilities, the environment prevents spaces in a payload. This can happen because of URL encoding (spaces become %20) or other input constraints. This article shows you how to get around this using a novel escaping technique.

Version Enumeration via Last-Modified Header

When a target does not disclose its software version directly, cache metadata can provide a useful clue. Static files are often served with a Last-Modified response header that reveals when the file was deployed.

Circumventing CSP Restrictions to Exfil Data from an XSS Foothold

Triggering an alert() from a cross-site scripting (XSS) vulnerability can be straightforward, but Content Security Policy (CSP) may block external resource loads. This article explores a scenario where cross-document messaging can still expose data from a vulnerable page.

iOS DNS Adblocking while on Cellular

On an iPhone, Wi-Fi settings let you specify a custom DNS server, but cellular connections such as LTE or 5G do not. This post shows how to use a local WireGuard interface to apply DNS-based ad blocking on cellular data.