Skip to main content
Yadhu's Blog
home
projects
about
tags
Posts
Exploiting HTTP Request Smuggling in Node.js and Gunicorn
May 11, 2024
/2024/05/11/Exploiting-HTTP-Request-Smuggling-in-Node.js-and-Gunicorn/
Yadhu Krishna M
Web Exploitation
#HTTP Request Smuggling
#Bug Bounty
#CVE
PyCGI: From Nginx Path-Traversal to RCE; bi0s CTF 2022
January 19, 2023
/2023/01/19/PyCGI-From-Nginx-Path-Traversal-to-RCE-bi0s-CTF-2022/
Yadhu Krishna M
Web Exploitation
#RCE
#Nginx Misconfiguration
#Path Traversal
#React.js
#JavaScript
Unlocking the EmoLocker: bi0s CTF 2022 - Author’s Writeup
January 19, 2023
/2023/01/19/Unlocking-the-EmoLocker-bi0s-CTF-2022-Authors-Writeup/
Yadhu Krishna M
Web Exploitation
#RCE
#Nginx Misconfiguration
#Path Traversal
#React.js
#JavaScript
A Timeline of Growth: Reflections on the Past, Present and Future
November 13, 2022
/2022/11/13/A-Timeline-of-Growth-Reflections-on-the-Past-Present-and-Future/
Yadhu Krishna M
Life
#Life
A tale of HTML Injection to Account takedown at Exercism.org
November 5, 2022
/2022/11/05/A-tale-of-HTML-Injection-to-Account-takedown-at-Exercism.org/
Yadhu Krishna M
Web Exploitation
#XSS
#Bug Bounty
#React.js
#JavaScript
Good Intentions - CSAW CTF Qualifiers 2022
October 17, 2022
/2022/10/17/Good-Intentions-CSAW-CTF-Qualifiers-2022/
Yadhu Krishna M
Web
#Flask
#File Upload
#Python Log Config Injection
NarutoKeeper - Securinets CTF Quals 2022
April 14, 2022
/2022/04/14/NarutoKeeper-Securinets-CTF-Quals-2022/
ma1f0y
Web
#SecurinetsCTFQuals
#XS-Leak
#XSS
#CSP
Vulpixelize - HITCON CTF 2021
December 5, 2021
/2021/12/05/Vulpixelize-HITCON-CTF-2021/
Yadhu Krishna M
Web
#DNS Rebinding
#HITCONCTF
Shisui - Fword CTF 2021 Write-up
August 30, 2021
/2021/08/30/Shisui-Fword-CTF-2021-Write-up/
Yadhu Krishna M
Web Exploitation
#XSS
#DOM Clobbering
InCTF Internationals 2021 - MD-Notes Write-up
August 15, 2021
/2021/08/15/InCTF-Internationals-2021-MD-Notes-Write-up/
Yadhu Krishna M
Web Exploitation
#XSS
#JavaScript
Exploiting Client-side Prototype Pollution - arg.js
June 22, 2021
/2021/06/22/Exploiting-Client-side-Prototype-Pollution-arg.js/
Yadhu Krishna M
Web Exploitation
#Prototype Pollution
#XSS
Waffle Write-up - m0leCon CTF 2021 Teaser
May 16, 2021
/2021/05/16/Waffle-Write-up-m0leCon-CTF-2021-Teaser/
Yadhu Krishna M
Web Exploitation
#SQLi
#JSON Interoperability
Story of My first Bug Bounty
April 29, 2021
/2021/04/29/Story-of-My-first-Bug-Bounty/
Yadhu Krishna M
Web Exploitation
#Bug Bounty
#Life
HTBCTF Finals 2021: Waf-Waf Write-up
March 13, 2021
/2021/03/13/HTBCTF-Finals-2021-Waf-Waf-Write-up/
Yadhu Krishna M
Web Exploitation
#HTBCTF
#SQL Injection
#PHP
DiceCTF 2021: Write-up WebIDE Challenge
February 9, 2021
/2021/02/09/DiceCTF-2021-Write-up-WebIDE-Challenge/
Yadhu Krishna M
Web Exploitation
#DiceCTF
#XSS
#JavaScript Sandbox Escape
Towards Cyber Security
August 2, 2020
/2020/08/02/Towards-Cyber-Security/
Yadhu Krishna M
Life
#Life