Infosec Consultant & Pentester
  • Home
  • About
  • CVE's
  • Responsible Disclosure
  • 100 Days of Dev Ops

web app testing

vulnerabilities

ChargePlace Scotland IDOR

Having recently entered the world of EV cars, I needed to get
Read more
Chris Young
web app testing

File Upload to Remote Code Execution

In this post, I will walk you through a real life example
Read more
Chris Young
web app testing

Bugbounty Tips - Zseano Live Mentoring Series - XSS

Over the weekend I participated in @zseanos live stream bug bounty mentoring
Read more
Chris Young
web app testing

Reflected XSS on driver.grab.com

Thought I would do a quick write up of a small bug
Read more
Chris Young
OWASP

Web Application Vulnerabilities 101 - Directory Traversal

Directory traversal aims to access files and directories that are stored outside
Read more
Chris Young
File Inclusion

DVWA - File Inclusion

LFI & RFI are commonly found in poorly written PHP code, allows
Read more
Chris Young
OWASP

CSRF - Cross Site Request Forgery

CSRF refers to an attack against authenticated web applications using Cookies wherein
Read more
Chris Young
OWASP

XSS - Cross Site Scripting

XSS in an input validation weakness which allows an attacker to inject
Read more
Chris Young
OWASP

XXE - XML External Entity

The XML External Entity (XXE) attack is a type of attack against
Read more
Chris Young
OWASP

Unrestricted File Upload

Many web applications allow users to upload content.  The content may be
Read more
Chris Young
SSRF

SSRF - Server Side Request Forgery

Server Side Request Forgery (SSRF) is a vulnerability that describes the behaviour
Read more
Chris Young
web app testing

Basic CURL commands

List HTTP methods: curl -i -X OPTIONS http://10.10.10.57
Read more
Chris Young
Infosec Consultant & Pentester © 2026
Powered by Ghost