https://devcenter.heroku.com/articles/websocket-securityhttps://docs.spring.io/spring-security/reference/servlet/integrations/websocket.htmlhttps://infosecwriteups.com/ldap-injection-653d7225dd8https://infosecwriteups.com/for-newbies-simple-examples-of-ldap-injection-vulnerabilities-cbf231431923https://hackerone.com/nagli?filter=type%3Apublic&type=userhttps://gist.github.com/geoff-nixon/362a56a8c6c6de0c3087https://blog.tneitzel.eu/posts/01-attacking-java-rmi-via-ssrf/https://mogwailabs.de/en/blog/2019/03/attacking-java-rmi-services-after-jep-290/https://blog.detectify.com/industry-insights/common-nginx-misconfigurations-that-leave-your-web-server-ope-to-attack/https://zhero-web-sec.github.io/research-and-things/nextjs-and-cache-poisoning-a-quest-for-the-black-holehttps://github.com/erebe/wstunnelhttps://labs.detectify.com/security-guidance/ssrf-vulnerabilities-and-where-to-find-them/https://speakerdeck.com/fransrosen/story-of-a-rce-on-apple-through-hot-jar-swapping?slide=11https://www.nozominetworks.com/blog/dji-mavic-3-drone-research-part-2-vulnerability-analysishttps://www.nozominetworks.com/blog/dji-mavic-3-drone-research-part-1-firmware-analysishttps://github.com/shadowsocks/shadowsocks-rusthttps://security.snyk.io/vuln/SNYK-JS-PARSEURL-2936249https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html?ref=0xor0ne.xyzhttps://gist.github.com/nckroy/dd2d4dfc86f7d13045ad715377b6a48fhttps://jub0bs.com/posts/2023-05-05-smorgasbord-of-a-bug-chain/https://medmahmoudi.com/projects/how-i-found-a-p2-misrouting-issue-affecting-all-google-cloud-load-balancershttps://www.assetnote.io/resources/research/insecurity-through-censorship-vulnerabilities-caused-by-the-great-firewallhttps://orangecon.nl/assets/slides/2024/OrangeCon2024 - Confusion Attacks Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!.pdfhttps://github.com/aapooksman/certmitm?utm_source=blog.criticalthinkingpodcast.io&utm_medium=referral&utm_campaign=hackernotes-ep-89-the-untapped-bug-bounty-landscape-of-iot-w-matt-brownhttps://github.com/r0075h3ll/Oralyzerhttps://github.com/ngalongc/AuthzAI/blob/main/authz_ai.pyhttps://bxmbn.medium.com/i-received-a-bank-offer-in-my-mailbox-and-discovered-an-idor-vulnerability-5-000-bounty-bxmbn-5209cab1fba8https://blog.exodusintel.com/2024/01/19/google-chrome-v8-cve-2024-0517-out-of-bounds-write-code-execution/https://www.youtube.com/watch?v=k5HZI6CfHw4https://www.youtube.com/watch?v=9IN1Aj56hYAhttps://infosecwriteups.com/the-toddlers-introduction-to-heap-exploitation-part-1-515b3621e0e8https://drive.google.com/file/d/1PwKdma4MMSzKlEaHg1ictizwgjWHoWYo/viewhttps://blog.dorki.io/how-i-discovered-a-critical-path-traversal-vulnerability-using-dorkihttps://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkallerhttps://github.com/rapiz1/ratholehttps://pwning.tech/nftables/https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/https://github.com/narfindustries/http-gardenhttps://byte.how/posts/what-are-you-telling-me-ghidra/https://elmahdi4.wordpress.com/2024/10/25/xss-vulnerabilities-in-excalidraw-affecting-meta-cve-2024-32472/https://github.com/kevin-mizu/domloggerpp/tree/mainhttps://www.youtube.com/watch?v=13rjABQ07fw&t=1shttps://blog.projectdiscovery.io/guide-to-dns-takeovers/https://research.checkpoint.com/2023/rust-binary-analysis-feature-by-feature/https://www.shielder.com/blog/2024/01/hunting-for-~~un~~authenticated-n-days-in-asus-routers/https://blog.quarkslab.com/dji-the-art-of-obfuscation.htmlhttps://blog.thalium.re/posts/rooting-xiaomi-wifi-routers/https://hackmd.io/@pepsipu/ry-SK44pt?s=09https://vandanpathak.com/kernels-and-buffers/buffer-overflow-exploits-demystified-from-theory-to-practice/https://medium.com/@0xold/15k-rce-through-monitoring-debug-mode-4f474d8549d5https://medium.com/@moblig/how-i-accessed-microsofts-servicenow-exposing-all-microsoft-employee-emails-chat-support-5f8d535eb63bhttps://0x44.xyz/blog/cve-2023-4369/https://projectdiscovery.io/blog/ruby-saml-gitlab-auth-bypass jsmon.sh https://medium.com/@deepanshudev369/interesting-story-of-an-account-takeover-vulnerability-140a45a058a3https://blog.blackbirdsec.eu/what-are-server-side-request-forgeries-ssrf-and-how-to-exploit-them/https://github.com/hwdsl2/setup-ipsec-vpn