Web security notes by CHW covering web reconnaissance, XSS, SSTI, SSRF, IDOR, exploitation workflows, and practical offensive security labs.
Posts for: #Offsec
[OSWA, WEB-200] Instructional notes - Part 2
OSWA WEB-200 筆記 Part 2,聚焦 SSTI、command injection、SSRF、IDOR 與常見 Web 漏洞重點。
[OSWA, WEB-200] Instructional notes - Part 1
OSWA WEB-200 筆記 Part 1,涵蓋 web application recon、Burp Suite、XSS、CSRF、SQLi 與 XML 攻擊。
[OSCP, PEN-200] Cheat Sheet
OSCP PEN-200 cheat sheet covering reconnaissance, scanning, web attacks, enumeration, and commonly used exam commands.
[OSCP, PEN-200] Instructional notes - Part 8
OSCP PEN-200 筆記 Part 8,涵蓋 cloud infrastructure attacks、Gitea、Jenkins 與模擬滲透測試流程。
[OSCP, PEN-200] Instructional notes - Part 7
OSCP PEN-200 筆記 Part 7,涵蓋 lateral movement、PtH/PtT/PtK、AD persistence 與 AWS recon。