Skip to content
No results
  • Main Blog
  • Offensive Security
  • Ops and Dev
    • SCOM
    • Web Dev
  • Other
    • SEO
  • About
scomurr.com logo banner

Play for serendipity...

  • Main Blog
  • Offensive Security
  • Ops and Dev
    • SCOM
    • Web Dev
  • Other
    • SEO
  • About
scomurr.com minimal logo

Play for serendipity...

scomurr.com logo
  • Affiliate Marketing, Canva

Creating My New Logo with Canva

Let’s Make a New Logo with Canva for Scomurr.com Scomurr.com needs a new logo! For this, I am going to use a few tools, but the goal is to come up with a killer logo that can help me drive…

  • scomurr
  • 12/13/2023
  • Security, Web Attacks

HTTP Request Smuggling – HTTP/2 Request Tunnelling

Time for another one of the advanced labs on the PortSwigger Web Security Academy. For this lab, we are dealing with an HTTP/2 downgrade attack that allows the attacker to smuggle a request to the backend. Due to how the…

  • scomurr
  • 03/19/2023
  • Security, Web Attacks

HTTP Request Smuggling – Web Cache Poisoning for Deception

This lab is a bit similar to the last, however, it has a completely different purpose. In the previous, we poisoned the cache in an attempt to trigger an XSS. In this lab, we are looking at poisoning a cache…

  • scomurr
  • 03/12/2023
  • Security, Web Attacks

HTTP Request Smuggling – Web Cache Poisoning

This lab is a lot of fun and requires chaining together techniques to fully exploit. First, we have to identify if, where, and how the application is vulnerable to a smuggling attack. Once that has been established, we need to…

  • scomurr
  • 03/05/2023
  • Security, Web Attacks

HTTP Request Smuggling – Admin Access via CL.0 Vulnerability

This next lab represents an interesting vulnerability where specific paths/routes within an application are vulnerable to desync when there is no expectation of anything other than the intended HTTP verb ever showing as part of a request. These are very…

  • scomurr
  • 02/25/2023
Prev
1 … 3 4 5 6 7 8 9 … 19
Next
  • ssti lab 7 - featured image
    SSTI – Server-side template injection with a custom exploit03/11/2025
  • ssti lab 6 - featured image
    SSTI – Server-side template injection in a sandboxed environment03/04/2025
  • ssti lab 5 featured image
    SSTI – Server-side template injection with information disclosure via user-supplied objects02/25/2025
  • monkey riding a bike - ssti lab 4 - featured image
    SSTI – Server-side template injection in an unknown language with a documented exploit02/20/2025
  • SSTI lab 3 - featured image
    SSTI – Server-side template injection using documentation02/17/2025

Scomurr.com is partially supported by readers like you. When you purchase products or services through our affiliate links, we may receive a commission. This will bring no extra costs to you and helps us to keep on creating content.

Legal

  • Terms and Conditions
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
  • DMCA
  • GDPR
  • Disclaimer

My Favorites

  • VistaSocial
  • NeuronWriter
  • Canva

Socials

Copyright © 2025 - WordPress Theme by CreativeThemes