3:33Portswigger exploiting path delimiters for web cache deceptionThe Stupid Programmer2.8K views·1 year ago
2:51Portswigger Exploiting path mapping for web cache deceptionThe Stupid Programmer8.7K views·1 year ago
3:02Portswigger Multi-step process with no access control on one stepThe Stupid Programmer831 views·1 year ago
1:48Portswigger User ID controlled by request parameter with password disclosureThe Stupid Programmer1.0K views·2 years ago
1:37Portswigger User ID controlled by request parameter with data leakage in redirectThe Stupid Programmer825 views·2 years ago
1:51Portswigger User ID controlled by request parameter, with unpredictable user IDsThe Stupid Programmer1.3K views·2 years ago
5:24Portswigger Exploiting insecure output handling in LLMsThe Stupid Programmer1.1K views·2 years ago
3:11Portswigger Method-based access control can be circumventedThe Stupid Programmer1.0K views·2 years ago
4:08Portswigger URL-based access control can be circumventedThe Stupid Programmer895 views·2 years ago
1:15Portswigger Unprotected admin functionality with unpredictable URLThe Stupid Programmer1.0K views·2 years ago
2:56Portswigger Exploiting server-side parameter pollution in a REST URLThe Stupid Programmer1.4K views·2 years ago
3:36Portswigger Exploiting server side parameter pollution in a query stringThe Stupid Programmer2.2K views·2 years ago
4:17Portswigger Exploiting a mass assignment vulnerabilityThe Stupid Programmer1.4K views·2 years ago
4:09Portswigger Finding and exploiting an unused API endpointThe Stupid Programmer2.4K views·2 years ago
3:05Portswigger Exploiting an API endpoint using documentationThe Stupid Programmer2.4K views·2 years ago