SQL Injection Without Spaces Using Brackets
In some SQL injection vulnerabilities, the environment prevents spaces in a payload. This can happen because of URL encoding (spaces become %20) or other input constraints. This article shows you how to get around this using a novel escaping technique.
Version Enumeration via Last-Modified Header
When a target does not disclose its software version directly, cache metadata can provide a useful clue. Static files are often served with a Last-Modified response header that reveals when the file was deployed.
Circumventing CSP Restrictions to Exfil Data from an XSS Foothold
Triggering an alert() from a cross-site scripting (XSS) vulnerability can be straightforward, but Content Security Policy (CSP) may block external resource loads. This article explores a scenario where cross-document messaging can still expose data from a vulnerable page.
iOS DNS Adblocking while on Cellular
On an iPhone, Wi-Fi settings let you specify a custom DNS server, but cellular connections such as LTE or 5G do not. This post shows how to use a local WireGuard interface to apply DNS-based ad blocking on cellular data.