
How an OPTIONS request with x-http-method-override can bypass blocked GET/POST methods, and how defenders can shut it down

How an OPTIONS request with x-http-method-override can bypass blocked GET/POST methods, and how defenders can shut it down

How a cookie jar overflow attack allowed me to completely bypass Imperva Incapsula's reese84 token validation

A walkthrough on my solution for Wiz's Needle in a Haystack CTF

A walkthrough on my solution for Wiz's Breaking The Barriers CTF