PinnedFHantke·Apr 18, 2022Hacking the University in a Few StepsEscalating a Wrong Date to Get Code ExecutionA response icon11A response icon11
InInfoSec Write-upsbyFHantke·Jan 28, 2024How to Get CVEs Online (Fast)Some thoughts about CVEsA response icon2A response icon2
FHantke·Jan 14, 2024ExamSys — Multiple SQL InjectionsExamSys is an open source online exam system. During a routine scan through GitHub, this repository was found vulnerable to multiple SQL…
FHantke·Aug 5, 2023Till Breach Do Us Part: The Uninvited Guest at Your WeddingPicture this: you’ve just had the perfect wedding. The vows were spoken, the dance floor was packed, but something was wrong...
InInfoSec Write-upsbyFHantke·May 5, 2022Clique Writeup — ångstromCTF 2022Mutation XSS in DOMPurify and marked
InInfoSec Write-upsbyFHantke·Mar 28, 2021Intigriti — XSS Challenge 0321XSS with CSRF BypassA response icon2A response icon2
InInfoSec Write-upsbyFHantke·Mar 14, 2021Post Office — DaVinciCTF — WriteupA conversation with a pirate
InInfoSec Write-upsbyFHantke·Mar 14, 2021DaVinciCTF — Web Challenges — WriteupThis weekend, I had the pleasure to play the DaVinci CTF and score first place with my team FAUST. It was great fun and a good quality CTF…