n1h1lu5
n1h1lu5.bsky.social
n1h1lu5
@n1h1lu5.bsky.social
Pentester. Blogger. Mountain Biker.

https://n1h1lu5.com
During an external pentest, I found a web app with a login form. I sent random credentials and noticed that the redirect response had a large content length. Turns out the app was returning the whole content in the redirect. All I had to do to get access was to make my proxy change the 301 to a 200.
March 28, 2025 at 2:37 PM
^ This
March 16, 2025 at 12:18 PM
If you have 2 apples and you give one to Alice, what temperature is it outside?
March 14, 2025 at 12:17 PM
The stateless?
March 10, 2025 at 1:06 AM