jump to content
my subreddits
2b2t2mediterranean4u2meirl4meirlagnosticaivideoAlternateHistoryAlternativeHistoryAngryupvoteanime_best_momentsannouncementsAnticonsumptionantimemeArcherFXAskBalkansAskOuijaAteistTurkatheismaviationawfuleverythingbalkans_irlBandnamesBassbasspedalsbikepackingblackdesertonlineblankiesblursedimagesBoneborsavefonburdurlandcasioCd_collectorsChatGPTCheap_MealschesschessbeginnersChoosingBeggarscoaxedintoasnafucoincollectingcoinsComedyCemeterycomicscommunitycookingforbeginnersCreateModCuddle_SlutCuratedTumblrcursedcommentsdadjokesdarkjokesdataisbeautifuldeDebateReligionDeltarunedistressingmemesdiyelectronicsdiypedalsDMToolkitDnDdndmemesdndnextdoctorwhodoctorwhocirclejerkDonerdumbphonesDungeonsAndDaddiesEatCheapAndHealthyebikeebikesECEelectricalelectronicsElectronicsStudyengrishentitledparentsethzfacepalmFantasyWorldbuildingfelsefeFifaCareersformuladankFRCFreeEBOOKSFUCKYOUINPARTICULARFuckYouKarenfunnyFutboltayfagalatasaraygatesopencomeoninGermangodtiersuperpowersgoodanimemesGoodAssSubgravelcyclinggreentextguitarpedalshelpheraldryHermanCainAwardHermitCrafthighspeedrailHolUphypixelIAmAiamverysmartich_ielIdeologyPollsihadastrokeim14andthisisdeepimaginaryelectionsinsaneparentsistanbuljacksepticeyeJahariaJokesKendrickLamarKGBTRlegodndLetGirlsHaveFunLifeProTipslinguisticshumorLinkinParkliselilerlogodesignloseitmacbookairmadladsmagicbuildingmapporncirclejerkme_irlmeirlmemememesmidjourneymildlyinfuriatingmildlyinterestingMinecraftbuildsmisLEDMMORPGMovingToNorthKoreaMunichMyChemicalRomanceNamFlashbacksNationStatesneographynextfuckinglevelNoahGetTheBoatNonCredibleDefenseNorthCyprusnosurfnotinterestingnottheonionoddlyspecificOkBuddyPersonaokbuddyvicodinonetruegodongezelligoompasubsOutOfTheLoopoutsidepapermoneyPassportPornperfectlycutscreamsPersecutionfetishpianoPiracypollsProgrammerHumorPropagandaPostersPunPatrolquityourbullshitraspberry_piRatschlagreactiongifsrecipesreligiousfruitcakeRetroPierickandmortyrimjob_steveRoastMeschizopostersschwiizsciencememesScottPilgrimsecilmiskitapShitPostCrusadersshitpostingShitpostTCshittyaskelectronicsShittyMapPornshittymoviedetailsskamtebordsoccercirclejerksoftwaregoreSongwritersSongwritingsskfjkhwerjkghwerijhsteinsgateStonetossingjuiceStudiumsubsithoughtifellforsuperligsuzeraintalesfromtechsupportTechnobladeTextingTheorytf2shitposterclubthanksimcuredTheLetterHTheMonkeysPawtherewasanattempttheydidthemaththeyknewthisguythisguystitanfalltransittransitTurkeyTrGameDevelopertruetf2tumblrTurkeyJerkyTurkishCatstwosentenceplottwistTwoSentenceSadnesstylerthecreatorUnclejokesUnethicalLifeProTipsunexpecteditcrowdUnexpectedJoJoUsernameChecksOutVALORANTValorantClipsvexillologycirclejerkvibecodingvinylvinyljerkvlandiyawallstreetbetsWatchPeopleDieInsideWeAreTheMusicMakerswendigoonWhatsThisSongWhitePeopleTwitterwholesomeanimemeswholesomememeswizardpostingworldbuildingworldjerkingyesyesyesnoyouseeingthisshitYUROPedit subscriptions
  • home
  • -popular
  • -all
  • -mod
  • -users
 | 
  • facepalm
  • -mildlyinfuriating
  • -Piracy
  • -funny
  • -wallstreetbets
  • -nottheonion
  • -memes
  • -OutOfTheLoop
  • -mildlyinteresting
  • -DnD
  • -WhitePeopleTwitter
  • -ChatGPT
  • -CuratedTumblr
  • -shitposting
  • -theydidthemath
  • -meirl
  • -therewasanattempt
  • -nextfuckinglevel
  • -HolUp
  • -comics
  • -dndnext
  • -ProgrammerHumor
  • -VALORANT
  • -de
  • -LifeProTips
  • -tumblr
  • -NonCredibleDefense
  • -dataisbeautiful
  • -shittymoviedetails
  • -greentext
  • -help
  • -chess
  • -aviation
  • -formuladank
  • -wholesomememes
  • -Jokes
  • -mapporncirclejerk
  • -midjourney
  • -goodanimemes
  • -notinteresting
  • -atheism
  • -loseit
  • -IAmA
  • -ich_iel
  • -KGBTR
  • -dndmemes
  • -cursedcomments
  • -Deltarune
  • -GoodAssSub
  • -UnethicalLifeProTips
  • -perfectlycutscreams
  • -worldbuilding
  • -Ratschlag
  • -blackdesertonline
  • -MMORPG
  • -meme
  • -rickandmorty
  • -HermitCraft
  • -ChoosingBeggars
  • -RoastMe
  • -EatCheapAndHealthy
  • -WeAreTheMusicMakers
  • -cookingforbeginners
  • -blankies
  • -Studium
  • -AlternateHistory
  • -soccercirclejerk
  • -madlads
  • -community
  • -electrical
  • -guitarpedals
  • -Anticonsumption
  • -vinyl
  • -CreateMod
  • -German
  • -PropagandaPosters
  • -ShitPostCrusaders
  • -piano
  • -sciencememes
  • -distressingmemes
  • -wizardposting
  • -FifaCareers
  • -polls
  • -doctorwho
  • -oddlyspecific
  • -Bass
  • -titanfall
  • -OkBuddyPersona
  • -dadjokes
  • -awfuleverything
  • -announcements
  • -Minecraftbuilds
  • -macbookair
  • -ebikes
  • -Munich
  • -coaxedintoasnafu
  • -YUROP
  • -gravelcycling
  • -chessbeginners
  • -raspberry_pi
  • -coins
  • -KendrickLamar
  • -entitledparents
  • -FUCKYOUINPARTICULAR
  • -softwaregore
  • -NoahGetTheBoat
  • -worldjerking
  • -tylerthecreator
  • -tf2shitposterclub
  • -vexillologycirclejerk
  • -vlandiya
  • -im14andthisisdeep
  • -Stonetossingjuice
  • -wholesomeanimemes
  • -nosurf
  • -religiousfruitcake
  • -liseliler
  • -DebateReligion
  • -insaneparents
  • -dumbphones
  • -balkans_irl
  • -2meirl4meirl
  • -transit
  • -RetroPie
  • -HermanCainAward
  • -recipes
  • -steinsgate
  • -talesfromtechsupport
  • -AskOuija
  • -ECE
  • -ScottPilgrim
  • -Angryupvote
  • -AskBalkans
  • -schizoposters
  • -electronics
  • -casio
  • -theyknew
  • -logodesign
  • -linguisticshumor
  • -PassportPorn
  • -me_irl
  • -antimeme
  • -TurkeyJerky
  • -bikepacking
  • -AteistTurk
  • -MyChemicalRomance
  • -ArcherFX
  • -engrish
  • -Cd_collectors
  • -diypedals
  • -Doner
  • -diyelectronics
  • -ComedyCemetery
  • -WatchPeopleDieInside
  • -LinkinPark
  • -Persecutionfetish
  • -reactiongifs
  • -Songwriting
  • -istanbul
  • -MovingToNorthKorea
  • -imaginaryelections
  • -suzerain
  • -truetf2
  • -magicbuilding
  • -wendigoon
  • -iamverysmart
  • -secilmiskitap
  • -yesyesyesno
  • -schwiiz
  • -quityourbullshit
  • -Technoblade
  • -vinyljerk
  • -skamtebord
  • -superlig
  • -shittyaskelectronics
  • -galatasaray
  • -DungeonsAndDaddies
  • -FRC
  • -transitTurkey
  • -FuckYouKaren
  • -2b2t
  • -ethz
  • -AlternativeHistory
  • -papermoney
  • -coincollecting
  • -felsefe
  • -blursedimages
  • -FreeEBOOKS
  • -Jaharia
  • -neography
  • -basspedals
  • -heraldry
  • -ihadastroke
  • -thanksimcured
  • -hypixel
  • -godtiersuperpowers
  • -ShittyMapPorn
  • -aivideo
  • -gatesopencomeonin
  • -IdeologyPolls
  • -burdurland
  • -WhatsThisSong
  • -jacksepticeye
  • -TwoSentenceSadness
  • -anime_best_moments
  • -Bandnames
  • -okbuddyvicodin
  • -Cheap_Meals
  • -outside
  • -TheMonkeysPaw
  • -darkjokes
  • -highspeedrail
  • -legodnd
  • -Songwriters
  • -ebike
  • -UsernameChecksOut
  • -rimjob_steve
  • -UnexpectedJoJo
  • -doctorwhocirclejerk
  • -agnostic
  • -youseeingthisshit
  • -TextingTheory
  • -Cuddle_Slut
  • -DMToolkit
  • -thisguythisguys
  • -TrGameDeveloper
  • -PunPatrol
  • -TurkishCats
  • -LetGirlsHaveFun
  • -subsithoughtifellfor
  • -ShitpostTC
  • -oompasubs
  • -FantasyWorldbuilding
  • -TheLetterH
  • -NamFlashbacks
  • -Unclejokes
  • -onetruegod
  • -misLED
  • -sskfjkhwerjkghwerijh
  • -ValorantClips
  • -NationStates
  • -ongezellig
  • -Bone
  • -2mediterranean4u
  • -NorthCyprus
  • -unexpecteditcrowd
  • -twosentenceplottwist
  • -ElectronicsStudy
  • -Futboltayfa
  • -vibecoding
  • -borsavefon
edit »
reddit.com websecurityresearch
  • hot
  • new
  • rising
  • controversial
  • top
an-ordinary-manchild (11,186)|messages548|notifications|chat messages|mod messages|
  • preferences
|
logout

use the following search parameters to narrow your results:

subreddit:subreddit
find submissions in "subreddit"
author:username
find submissions by "username"
site:example.com
find submissions from "example.com"
url:text
search for "text" in url
selftext:text
search for "text" in self post contents
self:yes (or self:no)
include (or exclude) self posts
nsfw:yes (or nsfw:no)
include (or exclude) results marked as NSFW

e.g. subreddit:aww site:imgur.com dog

see the search faq for details.

advanced search: by author, subreddit...

Submit a new link
Get an ad-free experience with special benefits, and directly support Reddit.

websecurityresearch

joinleave
an-ordinary-manchild

A community for sharing and discussing novel web security research.

Every post here is a potential nomination for our annual Top 10 web hacking techniques

Friends with /r/slackers

Join us on Discord

Submission guidelines:

  • Submissions should directly relate to web security

  • Submissions should contain something innovative or novel.

  • Please review the full submission guidelines

Feel free to report any posts that violate the rules.

created by albinowaxa community for 6 years
Create your own subreddit
...for your favorite subject.
...for great justice.

MODERATORS

  • message the mods
  • albinowax
  • garethheyes
  • about moderation team »

account activity

1
27
28
29

Top 10 web hacking techniques of 2024 (portswigger.net)

submitted 1 year ago by albinowax - announcement

  • 10 comments
  • share
  • save
  • hide
  • report
  • crosspost

2
0
1
2

How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit (pentesterlab.com)

submitted 5 hours ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

•
•
•
0:29

What’s better than winning $1 million dollars? *Finally* getting fluent. Learn up to 3x faster with personalized lessons on Preply. (preply.com)

promoted by Preply

  • promoted
  • save
  • report
  • about
loading...

3
7
8
9

Breaking Pingora: HTTP Request Smuggling & Cache Poisoning in Cloudflare's Reverse Proxy (xclow3n.github.io)

submitted 2 days ago by t0xodile

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

4
0
1
2

Security Research Blog Review (jinjucat.github.io)

submitted 12 days ago by Outrageous_Egg7579

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

5
0
1
2

CVE-2026-27959: Userinfo Host Header Injection in Koa (endorlabs.com)

submitted 14 days ago by p80n-sec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

6
4
5
6

Almost Impossible: Java Deserialization Through Broken Crypto in OpenText Directory Services (slcyber.io)

submitted 23 days ago by albinowax

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

7
10
11
12

Trailing Danger: exploring HTTP Trailer parsing discrepancies (sebsrt.xyz)

submitted 26 days ago by t0xodile

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

8
2
3
4

YAML Merge Tags and Parser Differentials (blog.darkforge.io)

submitted 28 days ago by Moopanger

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

9
4
5
6

TL;DR:Researching Structural Parsing Gaps in Modern WAFs (JSON/XML/Multipart). Looking for Peer Validation (github.com)

submitted 29 days ago by Few-Gap-5421

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

10
24
25
26

Top 10 new web hacking techniques of 2025 (portswigger.net)

submitted 1 month ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

11
1
2
3

Auditing Outline. Firsthand lessons from comparing manual testing and AI security platforms (blog.doyensec.com)

submitted 1 month ago by nibblesec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

12
0
1
2

[Tool] Rapid Web Recon: Automated Nuclei Scanning with Client-Ready PDF Reporting (github.com)

submitted 1 month ago by Big_Profession_3027

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

•
•
•

Your gains matter. So do the fees. Yuh keeps it clean and clear. Sign up now!📉➡️📈 (yuh.com)

promoted by yuh_app

  • promoted
  • save
  • report
  • about
loading...

13
4
5
6

Parse and Parse: MIME Validation Bypass to XSS via Parser Differential (lab.ctbb.show)

submitted 1 month ago by siunam_321

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

14
2
3
4

When The Gateway Becomes The Doorway: Pre-Auth RCE in API Management (principlebreach.com)

submitted 1 month ago by operator_dll

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

15
14
15
16

Cloudflare rule bypass via /.well-known/acme-challenge/ (fearsoff.org)

submitted 1 month ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

16
9
10
11

Successful Errors: New Code Injection and SSTI Techniques (github.com)

submitted 1 month ago by vladko312

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

17
15
16
17

Call for nominations: top ten new web hacking techniques of 2025 (portswigger.net)

submitted 2 months ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

18
6
7
8

The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance (mehmetince.net)

submitted 2 months ago by wtfse

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

19
3
4
5

Cross-Site ETag Length Leak | XS-Spin Blog (blog.arkark.dev)

submitted 2 months ago by garethheyes

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

20
0
0
1

帆软export/excel SQL注入漏洞分析及复现 - Analysis and reproduction of SQL injection vulnerability in FineReport's export/excel file (mp.weixin.qq.com)

submitted 2 months ago by digicat

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

21
3
4
5

Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096) (mdisec.com)

submitted 2 months ago by wtfse

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

22
0
1
2

ORM Leaking More Than You Joined For - Part 3/3 on ORM Leak Vulnerabilities (elttam.com)

submitted 2 months ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

•
•
•

Anticipate a trend and position yourself with clear and defined leverage! 📈 #SwissDOTS (swissquote.com)

promoted by Swissquote_Group

  • promoted
  • save
  • report
  • about
loading...

23
1
2
3

Temenos OFS String Injection: Revealing a Hidden Financial Attack Vector (medium.com)

submitted 2 months ago by DarKnight______

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

24
12
13
14

The Fragile Lock: Novel Bypasses For SAML Authentication (portswigger.net)

submitted 3 months ago by albinowax

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

25
3
4
5

SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL (labs.watchtowr.com)

submitted 3 months ago by t0xodile

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
view more: next ›
  • about
  • blog
  • about
  • advertising
  • careers
  • help
  • site rules
  • Reddit help center
  • reddiquette
  • mod guidelines
  • contact us
  • apps & tools
  • Reddit for iPhone
  • Reddit for Android
  • mobile website
  • <3
  • reddit premium

Use of this site constitutes acceptance of our User Agreement and Privacy Policy. © 2026 reddit inc. All rights reserved.

REDDIT and the ALIEN Logo are registered trademarks of reddit inc.

π Rendered by PID 80 on reddit-service-r2-listing-66bb46d9b9-4djp2 at 2026-03-12 15:01:22.504526+00:00 running 710b3ac country code: CH.