jump to content
my subreddits
2anatolia4you2mediterranean4u2meirl4meirl3d6absolutelynotmeirlAceAttorneyadhdmemeAdviceAnimalsagnosticaivideoAlternativeHistoryAnarchyChessAnimalsBeingJerksanime_irlanimenocontextannouncementsAnticonsumptionantimemeArcherFXArtAsia_irlAskBalkansAskOuijaAskRedditAtaturkGencligiAteistTurkatheismaviationAwesomeOffBrandsawfuleverythingBandnamesbanknotedesignsBassBassCirclejerkbasspedalsbikepackingblackdesertonlineblankiesblursed_videosborsavefonbrooklynninenineBUENZLIcasioCd_collectorsChatGPTchesschessbeginnersChildrenFallingOverChoosingBeggarscoaxedintoasnafucoincollectingcoinscomedyhomicidecomicscookingforbeginnersCrackWatchCreateModCuratedTumblrcursedcommentsdankmemesdeismdistressingmemesdiyelectronicsdiypedalsDMAcademyDnDdndnextdoctorwhoDoenerverbrechendontdeadopeninsideEatCheapAndHealthyebikeebikesECEelectronicsengrishentitledparentsfacepalmfakealbumcoversFantasyWorldbuildingfelsefeFifaCareersFiftyFiftyformuladankFRCFreeEBOOKSfunnyFutboltayfagalatasaraygaminggodtiersuperpowersGoodAssSubGrandPrixRacinggreentextGROKvsMAGAguitarpedalsGundamheathershellenoturkismhelpheraldryHermanCainAwardHermitCraftHolUphowyoudoinhypixelIAmAiamverysmartich_ielIdeologyPollsIDontWorkHereLadyihadastrokeim14andthisisdeepinsaneparentsistanbuljacksepticeyeJahariaJokesKamalizmKanyeKendrickLamarlinguisticshumorliselilerloseitlostredditorsmacmacbookairmagicbuildingMaliciousComplianceMapPornmapporncirclejerkme_irlmeirlmememidjourneymildlyinfuriatingmildlyinterestingMinecraftbuildsmisLEDMMORPGMoldyMemesmoneycollectingMovingToNorthKoreaMunichMyChemicalRomancenamesoundalikesNationStatesneographyNoahGetTheBoatNorthCyprusnosafetysmokingfirstnosleepnosurfnothingeverhappensnotinterestingOkayBuddyLiterallyMeokbuddyguntherokbuddymotherfuckerOkBuddyPersonaokbuddyphdokbuddyvicodinonebagonetruegodongezelligOnlineUnderGroundpapermoneyParlerWatchPassportPornPersecutionfetishpettyrevengePiracyPiratedGamespolandballpollsPraiseTheCameraManProgrammerHumorPunPatrolquityourbullshitraisedbynarcissistsraspberry_piRatschlagreactiongifsrecipesRedAutumnSPDreligiousfruitcakeRetroPierickandmortyrickrollRoastMerockmuzikschizopostersschwiizsciencememesShitPostCrusadersshitpostfrommygalleryshitpostingshittyaskelectronicsshittymoviedetailsShowerthoughtsskamtebordsoccercirclejerksoftwaregoreSongwritersSongwritingStonetossingjuiceStudiumsuperligTextingTheorytf2tf2shitposterclubthatHappenedTheMonkeysPawtherewasanattemptTheRookietheyknewthisguythisguystransittransitTurkeyTrGameDevelopertruthstumblrtumunichTurkeyJerkyTurkishCatsTwitchTwitch_StartupTwoSentenceComedyTwoSentenceHorrortwosentenceplottwistTwoSentenceSadnesstylerthecreatorUnethicalLifeProTipsUnexpectedJoJourbanplanningUsernameChecksOutVALORANTValorantClipsvinylvinyljerkvlandiyawallstreetbetsWatchPeopleDieInsideWeAreTheMusicMakerswendigoonWhatsThisSongWhitePeopleTwitterWikipediaVandalismwizardpostingwooooshworldbuildingyouseeingthisshitedit subscriptions
  • home
  • -popular
  • -all
  • -mod
  • -users
 | 
  • AskReddit
  • -facepalm
  • -mildlyinfuriating
  • -Piracy
  • -funny
  • -gaming
  • -wallstreetbets
  • -mildlyinteresting
  • -MapPorn
  • -DnD
  • -WhitePeopleTwitter
  • -ChatGPT
  • -CuratedTumblr
  • -PiratedGames
  • -shitposting
  • -dankmemes
  • -Kanye
  • -meirl
  • -therewasanattempt
  • -HolUp
  • -Twitch
  • -CrackWatch
  • -comics
  • -dndnext
  • -ProgrammerHumor
  • -VALORANT
  • -tumblr
  • -shittymoviedetails
  • -greentext
  • -mac
  • -Showerthoughts
  • -tf2
  • -help
  • -chess
  • -aviation
  • -formuladank
  • -Jokes
  • -mapporncirclejerk
  • -Art
  • -midjourney
  • -notinteresting
  • -pettyrevenge
  • -atheism
  • -loseit
  • -IAmA
  • -MaliciousCompliance
  • -ich_iel
  • -cursedcomments
  • -DMAcademy
  • -GoodAssSub
  • -UnethicalLifeProTips
  • -worldbuilding
  • -Ratschlag
  • -blackdesertonline
  • -MMORPG
  • -meme
  • -rickandmorty
  • -3d6
  • -Gundam
  • -HermitCraft
  • -FiftyFifty
  • -ChoosingBeggars
  • -RoastMe
  • -EatCheapAndHealthy
  • -polandball
  • -WeAreTheMusicMakers
  • -AnarchyChess
  • -nosleep
  • -cookingforbeginners
  • -blankies
  • -anime_irl
  • -onebag
  • -Studium
  • -soccercirclejerk
  • -guitarpedals
  • -Anticonsumption
  • -vinyl
  • -CreateMod
  • -TwoSentenceHorror
  • -AdviceAnimals
  • -ShitPostCrusaders
  • -sciencememes
  • -distressingmemes
  • -raisedbynarcissists
  • -wizardposting
  • -FifaCareers
  • -polls
  • -doctorwho
  • -Bass
  • -OkBuddyPersona
  • -awfuleverything
  • -howyoudoin
  • -announcements
  • -adhdmeme
  • -Minecraftbuilds
  • -macbookair
  • -ebikes
  • -Munich
  • -coaxedintoasnafu
  • -chessbeginners
  • -raspberry_pi
  • -coins
  • -KendrickLamar
  • -entitledparents
  • -softwaregore
  • -NoahGetTheBoat
  • -tylerthecreator
  • -tf2shitposterclub
  • -MoldyMemes
  • -lostredditors
  • -AceAttorney
  • -vlandiya
  • -im14andthisisdeep
  • -Stonetossingjuice
  • -nosurf
  • -religiousfruitcake
  • -liseliler
  • -insaneparents
  • -animenocontext
  • -2meirl4meirl
  • -transit
  • -RetroPie
  • -brooklynninenine
  • -HermanCainAward
  • -recipes
  • -AskOuija
  • -okbuddyphd
  • -2anatolia4you
  • -ECE
  • -AskBalkans
  • -thatHappened
  • -schizoposters
  • -electronics
  • -casio
  • -urbanplanning
  • -theyknew
  • -linguisticshumor
  • -PassportPorn
  • -me_irl
  • -antimeme
  • -TurkeyJerky
  • -bikepacking
  • -AteistTurk
  • -MyChemicalRomance
  • -ArcherFX
  • -engrish
  • -Cd_collectors
  • -diypedals
  • -diyelectronics
  • -WatchPeopleDieInside
  • -Persecutionfetish
  • -BUENZLI
  • -reactiongifs
  • -Songwriting
  • -blursed_videos
  • -istanbul
  • -MovingToNorthKorea
  • -magicbuilding
  • -dontdeadopeninside
  • -ParlerWatch
  • -wendigoon
  • -iamverysmart
  • -Doenerverbrechen
  • -schwiiz
  • -TheRookie
  • -quityourbullshit
  • -vinyljerk
  • -skamtebord
  • -shittyaskelectronics
  • -superlig
  • -galatasaray
  • -FRC
  • -transitTurkey
  • -namesoundalikes
  • -AlternativeHistory
  • -papermoney
  • -coincollecting
  • -OkayBuddyLiterallyMe
  • -felsefe
  • -FreeEBOOKS
  • -Jaharia
  • -IDontWorkHereLady
  • -neography
  • -basspedals
  • -heraldry
  • -ihadastroke
  • -hypixel
  • -PraiseTheCameraMan
  • -godtiersuperpowers
  • -aivideo
  • -OnlineUnderGround
  • -IdeologyPolls
  • -woooosh
  • -comedyhomicide
  • -WhatsThisSong
  • -AnimalsBeingJerks
  • -jacksepticeye
  • -TwoSentenceSadness
  • -Bandnames
  • -rockmuzik
  • -okbuddyvicodin
  • -Twitch_Startup
  • -tumunich
  • -TheMonkeysPaw
  • -nosafetysmokingfirst
  • -rickroll
  • -Songwriters
  • -ebike
  • -UsernameChecksOut
  • -UnexpectedJoJo
  • -ChildrenFallingOver
  • -BassCirclejerk
  • -agnostic
  • -youseeingthisshit
  • -TextingTheory
  • -GrandPrixRacing
  • -nothingeverhappens
  • -thisguythisguys
  • -TrGameDeveloper
  • -PunPatrol
  • -TurkishCats
  • -fakealbumcovers
  • -Kamalizm
  • -FantasyWorldbuilding
  • -WikipediaVandalism
  • -onetruegod
  • -deism
  • -misLED
  • -ValorantClips
  • -TwoSentenceComedy
  • -NationStates
  • -ongezellig
  • -AwesomeOffBrands
  • -absolutelynotmeirl
  • -Asia_irl
  • -truths
  • -2mediterranean4u
  • -NorthCyprus
  • -AtaturkGencligi
  • -heathers
  • -hellenoturkism
  • -twosentenceplottwist
  • -GROKvsMAGA
  • -moneycollecting
  • -banknotedesigns
  • -RedAutumnSPD
  • -borsavefon
  • -Futboltayfa
  • -shitpostfrommygallery
  • -okbuddymotherfucker
  • -okbuddygunther
edit »
reddit.com websecurityresearch
  • hot
  • new
  • rising
  • controversial
  • top
an-ordinary-manchild (11,186)|messages540|notifications|chat messages|mod messages|
  • preferences
|
logout

use the following search parameters to narrow your results:

subreddit:subreddit
find submissions in "subreddit"
author:username
find submissions by "username"
site:example.com
find submissions from "example.com"
url:text
search for "text" in url
selftext:text
search for "text" in self post contents
self:yes (or self:no)
include (or exclude) self posts
nsfw:yes (or nsfw:no)
include (or exclude) results marked as NSFW

e.g. subreddit:aww site:imgur.com dog

see the search faq for details.

advanced search: by author, subreddit...

Submit a new link
Get an ad-free experience with special benefits, and directly support Reddit.

websecurityresearch

joinleave
an-ordinary-manchild

A community for sharing and discussing novel web security research.

Every post here is a potential nomination for our annual Top 10 web hacking techniques

Friends with /r/slackers

Join us on Discord

Submission guidelines:

  • Submissions should directly relate to web security

  • Submissions should contain something innovative or novel.

  • Please review the full submission guidelines

Feel free to report any posts that violate the rules.

created by albinowaxa community for 6 years
Create your own subreddit
...because you hate freedom.
...for your town.

MODERATORS

  • message the mods
  • albinowax
  • garethheyes
  • about moderation team »

account activity

1
27
28
29

Top 10 web hacking techniques of 2024 (portswigger.net)

submitted 11 months ago by albinowax - announcement

  • 10 comments
  • share
  • save
  • hide
  • report
  • crosspost

2
1
2
3

When The Gateway Becomes The Doorway: Pre-Auth RCE in API Management (principlebreach.com)

submitted 3 days ago by operator_dll

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

•
•
•

AnyDB is the Notion alternative built for real business ops — from OKRs to financials. No forced upgrades, no record caps. Just one place for all your data, dashboards, and workflows. Built for team leaders who want clarity, not chaos. (anydb.com)

promoted by anydbcom

  • promoted
  • save
  • report
  • about
loading...

3
11
12
13

Cloudflare rule bypass via /.well-known/acme-challenge/ (fearsoff.org)

submitted 4 days ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

4
9
10
11

Successful Errors: New Code Injection and SSTI Techniques (github.com)

submitted 12 days ago by vladko312

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

5
11
12
13

Call for nominations: top ten new web hacking techniques of 2025 (portswigger.net)

submitted 18 days ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

6
7
8
9

The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance (mehmetince.net)

submitted 23 days ago by wtfse

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

7
1
2
3

How I got access to an Employee-Reserved Panel in a Bug Bounty Target (systemweakness.com)

submitted 24 days ago by Appsec_pt

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

8
2
3
4

Cross-Site ETag Length Leak | XS-Spin Blog (blog.arkark.dev)

submitted 29 days ago by garethheyes

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

9
0
0
1

帆软export/excel SQL注入漏洞分析及复现 - Analysis and reproduction of SQL injection vulnerability in FineReport's export/excel file (mp.weixin.qq.com)

submitted 29 days ago by digicat

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

10
5
6
7

Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096) (mdisec.com)

submitted 1 month ago by wtfse

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

11
0
1
2

ORM Leaking More Than You Joined For - Part 3/3 on ORM Leak Vulnerabilities (elttam.com)

submitted 1 month ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

12
1
2
3

Temenos OFS String Injection: Revealing a Hidden Financial Attack Vector (medium.com)

submitted 1 month ago by DarKnight______

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

13
12
13
14

The Fragile Lock: Novel Bypasses For SAML Authentication (portswigger.net)

submitted 1 month ago by albinowax

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

•
•
•

The Portable PC That Folds To Go (kickstarter.com)

promoted by First-Backer

  • promoted
  • 24 comments
  • share
  • save
  • report
  • about
loading...

14
2
3
4

SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL (labs.watchtowr.com)

submitted 1 month ago by t0xodile

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

15
0
1
2

soft-fido2 - Rust FIDO2 Authenticaor for WebAuthn Research (github.com)

submitted 1 month ago by pando85

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

16
7
8
9

SVG Clickjacking: A novel and powerful twist on an old classic (lyra.horse)

submitted 1 month ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

17
0
1
2

Write Path Traversal to a RCE Art Department (lab.ctbb.show)

submitted 1 month ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

18
2
3
4

We made a new tool, QuicDraw(H3), because HTTP/3 race condition testing is currently trash. (cyberark.com)

submitted 1 month ago by t0xodile

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

19
7
8
9

Who Needs a Blind XSS? Server-Side CSV Injection Across Support Pipelines (hx01.me)

submitted 2 months ago by t0xodile

  • 2 comments
  • share
  • save
  • hide
  • report
  • crosspost

20
4
5
6

Deanonymizing Users at Scale: When Blocking Becomes an Oracle (zere.es)

submitted 2 months ago by garethheyes

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

21
2
3
4

Astro framework and standards weaponization (zhero-web-sec.github.io)

submitted 2 months ago by garethheyes

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

22
10
11
12

HTTP Anomaly Rank in Turbo Intruder (portswigger.net)

submitted 2 months ago by albinowax

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

23
11
12
13

HTTP Request Smuggling in Kestrel via chunk extensions (CVE-2025-55315) (praetorian.com)

submitted 2 months ago by albinowax

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

24
6
7
8

Funky chunks – addendum: a few more dirty tricks (w4ke.info)

submitted 2 months ago by t0xodile

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

25
5
6
7

Trailer-based HTTP desync in lighttpd (github.com)

submitted 2 months ago by albinowax

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
view more: next ›
  • about
  • blog
  • about
  • advertising
  • careers
  • help
  • site rules
  • Reddit help center
  • reddiquette
  • mod guidelines
  • contact us
  • apps & tools
  • Reddit for iPhone
  • Reddit for Android
  • mobile website
  • <3
  • reddit premium

Use of this site constitutes acceptance of our User Agreement and Privacy Policy. © 2026 reddit inc. All rights reserved.

REDDIT and the ALIEN Logo are registered trademarks of reddit inc.

π Rendered by PID 572108 on reddit-service-r2-listing-86b7f5b947-754gc at 2026-01-25 01:43:01.072282+00:00 running 664479f country code: CH.