LSCP

LSCP

Menu
  • Lyhin Security Consulting & Pentesting
  • LSCP Responsible Disclosure Lab

Category: Uncategorized

Lifehacks for hackers: The “TODAY” reporting model

August 13, 2021
 |  No Comments
 |  Uncategorized

This short article defines the TODAY model, which is a 5-step guide of how to create pen-test reports in an efficient […]

Read More →

How White-Box hacking works: Remote Code Execution and Stored XSS in PhotoShow 3.0

July 19, 2021
 |  No Comments
 |  Uncategorized

A bit outdated, nevertheless is beautiful in terms of ethical hacking – photoshow is an open source web application with 490 […]

Read More →

Lifehacks for hackers: Split XSS

June 12, 2021
 |  No Comments
 |  Uncategorized

In case of multiple Stored XSS with the strict size limitation – consider the following exploitation technique; it would work, even […]

Read More →

How White-Box hacking works: Stored XSS in ntopng

May 13, 2021
 |  No Comments
 |  Uncategorized

There is a stored XSS vulnerability in the ‘ntopng web application’ community edition version 4.1.200612. This vulnerability allows a malicious individual […]

Read More →

Lifehacks for hackers: Exploiting of Data Protection API

April 10, 2021
 |  No Comments
 |  Uncategorized

The simplest way of how to find and exploit Data Protection API misconfigurations: Install the demo version of iExplorer tool on […]

Read More →

How White-Box hacking works: XSS in OroCRM

March 13, 2021
 |  No Comments
 |  Uncategorized

Recently, Lyhin’s Lab decided to take a more challenging application. OroCRM v4.1.6: Has 785 stars and 260 forks on Github PHP […]

Read More →

Lifehacks for hackers: how to monitor mobile devices’ filesystem dynamically

February 13, 2021
 |  No Comments
 |  Uncategorized

I suppose you want to discover how the pre-defined mobile application interacts with the filesystem and precisely understand what happens on […]

Read More →

How White-Box hacking works: Scipio ERP, RCE/CSRF and Co

January 16, 2021
 |  No Comments
 |  Uncategorized

Why Scipio ERP (v2.0.0): 240 stars on Github Apache-2.0 License Java The mentioned vulnerabilities were found and exploited by Ihor Voschyk […]

Read More →

LH4H: Mobile Application Threat Analysis @ PCSD

December 20, 2020
 |  No Comments
 |  Uncategorized

Had an online talk at Practical Cyber Security Day. Presentation: https://lyhinslab.org/media/Lyhin_MATA.pptx Self-explaining screenshot: Related reference: https://lyhinslab.org/index.php/2020/10/17/lifehacks-for-hackers-how-to-audit-mobile-apps/

Read More →

How White-Box hacking works: Authorization Bypass in Alerta 8.0.3

November 14, 2020
 |  No Comments
 |  Uncategorized

We have bad news for vendors whose applications use hardcoded secrets, for example, to create and validate JSON Web Tokens within […]

Read More →

Posts pagination

Previous 1 2 3 Next

Recent Posts

  • EXP Lore Cyber
  • Rimpact
  • The Security Spirit
  • Lifehacks for Hackers: does this scope need AV?
  • Temporary suspension of the lab

Archives

  • August 2025
  • March 2023
  • October 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
LSCP Theme By SKT Free Themes