PortSwigger 37
- PortSwigger Academy Labs Walkthrough
- PortSwigger Walkthrough - Indirect prompt injection
- PortSwigger Walkthrough - Exploiting vulnerabilities in LLM APIs
- PortSwigger Walkthrough - Bypassing AI scanner defenses to exfiltrate sensitive information
- PortSwigger Walkthrough - Exploiting LLM APIs with excessive agency
- PortSwigger Walkthrough - Exploiting AI agents to trigger secondary vulnerabilities
- PortSwigger Walkthrough - Exploiting AI agents to exfiltrate sensitive information
- PortSwigger Walkthrough - Exploiting AI agents to perform destructive actions
- PortSwigger Walkthrough - Manipulating WebSocket messages to exploit vulnerabilities
- PortSwigger Walkthrough - Manipulating the WebSocket handshake to exploit vulnerabilities
- PortSwigger Walkthrough - Cross-site WebSocket hijacking
- PortSwigger Walkthrough - SSRF with filter bypass via open redirection vulnerability
- PortSwigger Walkthrough - Blind SSRF with out-of-band detection
- PortSwigger Walkthrough - SSRF with blacklist-based input filter
- PortSwigger Walkthrough - Basic SSRF against the local server
- PortSwigger Walkthrough - Basic SSRF against another back-end system
- PortSwigger Walkthrough - CORS vulnerability with trusted null origin
- PortSwigger Walkthrough - CORS vulnerability with trusted insecure protocols
- PortSwigger Walkthrough - CORS vulnerability with basic origin reflection
- PortSwigger Walkthrough - File path traversal, validation of start of path
- PortSwigger Walkthrough - File path traversal, validation of file extension with null byte bypass
- PortSwigger Walkthrough - File path traversal, simple case
- PortSwigger Walkthrough - File path traversal, traversal sequences stripped with superfluous URL-decode
- PortSwigger Walkthrough - File path traversal, traversal sequences stripped non-recursively
- PortSwigger Walkthrough - File path traversal, traversal sequences blocked with absolute path bypass
- PortSwigger Walkthrough - Username enumeration via subtly different responses
- PortSwigger Walkthrough - Username enumeration via response timing
- PortSwigger Walkthrough - Username enumeration via different responses
- PortSwigger Walkthrough - Username enumeration via account lock
- PortSwigger Walkthrough - Password reset poisoning via middleware
- PortSwigger Walkthrough - Password reset broken logic
- PortSwigger Walkthrough - Password brute-force via password change
- PortSwigger Walkthrough - Offline password cracking
- PortSwigger Walkthrough - Brute-forcing a stay-logged-in cookie
- PortSwigger Walkthrough - Broken brute-force protection, IP block
- PortSwigger Walkthrough - 2FA Simple Bypass
- PortSwigger Walkthrough - 2FA Broken Logic