<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Yusuf AlMahmeed</title><link>https://www.yusufalmahmeed.com/</link><description>Recent content on Yusuf AlMahmeed</description><generator>Hugo</generator><language>en-us</language><copyright>© 2026 Yusuf AlMahmeed · &lt;a href="https://www.yusufalmahmeed.com/privacy/"&gt;privacy&lt;/a&gt;</copyright><lastBuildDate>Fri, 09 Oct 2026 18:09:00 +0300</lastBuildDate><atom:link href="https://www.yusufalmahmeed.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Exploiting XXE to Perform SSRF</title><link>https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-xxe-to-ssrf/</link><pubDate>Fri, 09 Oct 2026 18:09:00 +0300</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-xxe-to-ssrf/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;XML external entity (XXE) injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Exploiting XXE to perform SSRF attacks&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Apprentice&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Read the server&amp;rsquo;s IAM credentials from cloud metadata&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="the-idea"&gt;The idea&lt;/h2&gt;&#10;&lt;p&gt;In the &lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-retrieve-files/"&gt;file-retrieval lab&lt;/a&gt;&#10; the&#10;external entity pointed at a local file with &lt;code&gt;file://&lt;/code&gt;. Point it at an &lt;code&gt;http://&lt;/code&gt;&#10;URL instead and the XML parser becomes an HTTP client that fetches whatever URL we&#10;give it. That is &lt;strong&gt;SSRF&lt;/strong&gt; (server-side request forgery): making the server send&#10;requests to targets we choose, from its own trusted position on the network.&lt;/p&gt;</description></item><item><title>Exploiting XXE to Retrieve Files</title><link>https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-retrieve-files/</link><pubDate>Fri, 09 Oct 2026 17:43:00 +0300</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-retrieve-files/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;XML external entity (XXE) injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Exploiting XXE using external entities to retrieve files&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Apprentice&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Read &lt;code&gt;/etc/passwd&lt;/code&gt; from the server&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="what-is-xxe"&gt;What is XXE?&lt;/h2&gt;&#10;&lt;p&gt;&lt;strong&gt;XML external entity (XXE) injection&lt;/strong&gt; happens when an application parses XML we&#10;control, and the &lt;strong&gt;parser&lt;/strong&gt; (the library that reads the XML and turns it into data&#10;the app can use) is allowed to process &lt;strong&gt;external entities&lt;/strong&gt;. An &lt;em&gt;entity&lt;/em&gt;&#10;in XML is a named placeholder, declared in a &lt;strong&gt;DTD&lt;/strong&gt; (Document Type Definition)&#10;and referenced in the document; an &lt;em&gt;external&lt;/em&gt; entity takes its value from a URI&#10;the parser fetches. If we can declare our own entity that points at a local file,&#10;the parser reads that file and we can often get the contents reflected back.&lt;/p&gt;</description></item><item><title>Shakabrah</title><link>https://www.yusufalmahmeed.com/posts/shakabrah/</link><pubDate>Tue, 06 Oct 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/shakabrah/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Machine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Shakabrah&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;OffSec Proving Grounds&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Easy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;OS&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Linux (Ubuntu)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Learning Path&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Web fundamentals / OSWA &amp;amp; OSCP prep&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Key Techniques&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;OS command injection, reverse shell, SUID binary privesc&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Est. Time to Complete&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;~20–30 min&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;&#10;&lt;p&gt;Shakabrah is a Linux box that comes down to two clean steps. The web server&#10;hosts a &amp;ldquo;Connection Tester&amp;rdquo; that pings whatever host you give it, and it builds&#10;that &lt;code&gt;ping&lt;/code&gt; command by pasting your input straight onto a shell, so a shell&#10;metacharacter (a character the shell treats specially, like &lt;code&gt;&amp;amp;&amp;amp;&lt;/code&gt; or &lt;code&gt;;&lt;/code&gt;) turns&#10;the box into a command runner. That gets a reverse shell as &lt;code&gt;www-data&lt;/code&gt;. From&#10;there, a single misconfigured SUID binary, &lt;code&gt;vim.basic&lt;/code&gt;, is all&#10;it takes to become root. It shows how one unsanitized input and one&#10;over-privileged binary are enough to take a host from an open port to root.&lt;/p&gt;</description></item><item><title>Server-Side Template Injection in a Sandboxed Environment</title><link>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-sandboxed-environment/</link><pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-sandboxed-environment/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Server-side template injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;SSTI in a sandboxed environment&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Expert&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Engine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;FreeMarker (Java), sandboxed&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Read &lt;code&gt;/home/carlos/my_password.txt&lt;/code&gt; and submit it&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Browser, the Java API docs, a bytes-to-ASCII converter&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="the-idea"&gt;The idea&lt;/h2&gt;&#10;&lt;p&gt;In the &lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-documentation/"&gt;documentation lab&lt;/a&gt;&#10; we escaped&#10;FreeMarker with &lt;code&gt;?new&lt;/code&gt; to instantiate &lt;code&gt;Execute&lt;/code&gt; and run commands. Here that door&#10;is shut: the engine is &lt;strong&gt;sandboxed&lt;/strong&gt;, so &lt;code&gt;?new&lt;/code&gt; and the dangerous helper classes&#10;are blocked. No arbitrary code execution.&lt;/p&gt;</description></item><item><title>Server-Side Template Injection via User-Supplied Objects</title><link>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-user-supplied-objects/</link><pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-user-supplied-objects/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Server-side template injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;SSTI with information disclosure via user-supplied objects&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Practitioner&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Engine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Django (Python)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Leak the framework&amp;rsquo;s &lt;code&gt;SECRET_KEY&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Browser, the engine&amp;rsquo;s own documentation&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="the-idea"&gt;The idea&lt;/h2&gt;&#10;&lt;p&gt;Not every SSTI ends in remote code execution. Django&amp;rsquo;s template language is&#10;deliberately &lt;strong&gt;sandboxed&lt;/strong&gt;, there&amp;rsquo;s no &lt;code&gt;{{7*7}}&lt;/code&gt; arithmetic, no imports, no&#10;&lt;code&gt;os.system&lt;/code&gt;. But a sandbox that blocks &lt;em&gt;code&lt;/em&gt; doesn&amp;rsquo;t necessarily block &lt;em&gt;data&lt;/em&gt;:&#10;if a sensitive object is reachable from the template context, you can still read&#10;it. This lab leaks Django&amp;rsquo;s &lt;code&gt;SECRET_KEY&lt;/code&gt; by doing exactly that.&lt;/p&gt;</description></item><item><title>Server-Side Template Injection with a Custom Exploit</title><link>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-custom-exploit/</link><pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-custom-exploit/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Server-side template injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;SSTI with a custom exploit&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Expert&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Engine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Twig (PHP)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Delete &lt;code&gt;/home/carlos/.ssh/id_rsa&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Browser, Burp Repeater, a text editor&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="the-idea"&gt;The idea&lt;/h2&gt;&#10;&lt;p&gt;Not every SSTI ends in a copy-paste payload for a known engine. This one is a&#10;&lt;em&gt;custom&lt;/em&gt; exploit: we fingerprint the engine from its errors, notice that a real&#10;&lt;strong&gt;application object&lt;/strong&gt; (&lt;code&gt;user&lt;/code&gt;) is exposed inside the template, read the&#10;application&amp;rsquo;s own source code to learn what methods that object offers, and then&#10;chain two of those methods into exactly the primitive we need. No public payload&#10;exists for this; we build it from the app&amp;rsquo;s own code.&lt;/p&gt;</description></item><item><title>Basic Server-Side Template Injection (Code Context)</title><link>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-code-context/</link><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-code-context/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Server-side template injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Basic server-side template injection (code context)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Practitioner&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Engine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Tornado (Python)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Delete &lt;code&gt;morale.txt&lt;/code&gt; from Carlos&amp;rsquo;s home directory&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="plaintext-context-vs-code-context"&gt;Plaintext context vs code context&lt;/h2&gt;&#10;&lt;p&gt;In the &lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-basic/"&gt;basic case&lt;/a&gt;&#10;, our input became the&#10;whole template, so we could inject template syntax directly. Here it&amp;rsquo;s different:&#10;our input is dropped into an &lt;strong&gt;existing template expression&lt;/strong&gt;, something like&#10;&lt;code&gt;{{ our_input }}&lt;/code&gt;. That&amp;rsquo;s a &lt;em&gt;code context&lt;/em&gt;. To inject, we first have to &lt;strong&gt;break&#10;out&lt;/strong&gt; of the current expression with &lt;code&gt;}}&lt;/code&gt;, then add our own.&lt;/p&gt;</description></item><item><title>Cataract: Tiered Web Enumeration</title><link>https://www.yusufalmahmeed.com/posts/tools/cataract/</link><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/tools/cataract/</guid><description>&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Repo:&lt;/strong&gt; &lt;a href="https://github.com/YusufAlMahmeed/cataract" target="_blank" rel="noopener noreferrer"&gt;github.com/YusufAlMahmeed/cataract&lt;/a&gt;&#10;.&#10;Star it and &lt;strong&gt;keep an eye on the GitHub page for updates&lt;/strong&gt;. Bug reports,&#10;feature ideas, and suggestions are welcome: open an&#10;&lt;a href="https://github.com/YusufAlMahmeed/cataract/issues" target="_blank" rel="noopener noreferrer"&gt;issue&lt;/a&gt;&#10; on the repo.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;Cataract is actively maintained, so this page describes how it works rather than&#10;any one release. For the current flags, defaults, and release history, the&#10;&lt;a href="https://github.com/YusufAlMahmeed/cataract" target="_blank" rel="noopener noreferrer"&gt;repository&lt;/a&gt;&#10; and its&#10;&lt;a href="https://github.com/YusufAlMahmeed/cataract/blob/main/CHANGELOG.md" target="_blank" rel="noopener noreferrer"&gt;changelog&lt;/a&gt;&#10; are&#10;always the source of truth.&lt;/p&gt;&#10;&lt;h2 id="what-it-is"&gt;What it is&lt;/h2&gt;&#10;&lt;p&gt;&lt;strong&gt;Cataract&lt;/strong&gt; is a small Bash tool for &lt;strong&gt;authorized&lt;/strong&gt; web penetration testing. Its&#10;one-liner:&lt;/p&gt;</description></item><item><title>Server-Side Template Injection in an Unknown Language</title><link>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-unknown-language/</link><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-unknown-language/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Server-side template injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;SSTI in an unknown language with a documented exploit&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Practitioner&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Engine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Handlebars (Node.js)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Delete &lt;code&gt;morale.txt&lt;/code&gt; from Carlos&amp;rsquo;s home directory&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Repeater + Decoder)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="the-idea"&gt;The idea&lt;/h2&gt;&#10;&lt;p&gt;You won&amp;rsquo;t always recognize the template syntax in front of you. That&amp;rsquo;s fine: the&#10;job is to make the server throw an error, read the stack trace to learn the&#10;engine, and then find a &lt;strong&gt;documented&lt;/strong&gt; exploit for that engine. No prior&#10;knowledge of the language is required.&lt;/p&gt;</description></item><item><title>Server-Side Template Injection Using Documentation</title><link>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-documentation/</link><pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-documentation/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Server-side template injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Server-side template injection using documentation&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Practitioner&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Engine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;FreeMarker (Java)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Delete &lt;code&gt;morale.txt&lt;/code&gt; from Carlos&amp;rsquo;s home directory&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Browser, the engine&amp;rsquo;s own documentation&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="the-idea"&gt;The idea&lt;/h2&gt;&#10;&lt;p&gt;Sometimes you don&amp;rsquo;t need a memorised payload. Once you know &lt;strong&gt;which&lt;/strong&gt; template&#10;engine is running, its official documentation will often hand you everything you&#10;need, including the features that turn template rendering into command execution.&#10;This lab is exactly that: identify the engine from an error message, then read&#10;the docs to build the exploit.&lt;/p&gt;</description></item><item><title>Basic Server-Side Template Injection</title><link>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-basic/</link><pubDate>Mon, 28 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-basic/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Server-side template injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Basic server-side template injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Apprentice&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Engine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;ERB (Ruby)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Delete &lt;code&gt;morale.txt&lt;/code&gt; from Carlos&amp;rsquo;s home directory&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="what-is-server-side-template-injection"&gt;What is server-side template injection?&lt;/h2&gt;&#10;&lt;p&gt;Server-side template injection (SSTI) happens when user input is embedded into a&#10;server-side template and then evaluated as template code rather than plain data.&#10;Because templates can run expressions (and often reach the underlying language),&#10;a successful injection usually leads to information disclosure or full remote code&#10;execution.&lt;/p&gt;</description></item><item><title>Blind OS Command Injection with Output Redirection</title><link>https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-output-redirection/</link><pubDate>Sun, 27 Sep 2026 14:30:00 +0300</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-output-redirection/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;OS command injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Blind OS command injection with output redirection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Practitioner&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Run &lt;code&gt;whoami&lt;/code&gt; and read its output&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="the-idea"&gt;The idea&lt;/h2&gt;&#10;&lt;p&gt;This is another &lt;strong&gt;blind&lt;/strong&gt; injection: the feedback function runs a shell command&#10;with our input but returns nothing useful. Last time we proved execution with a&#10;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-time-delay/"&gt;time delay&lt;/a&gt;&#10;. This time&#10;we actually want the &lt;em&gt;output&lt;/em&gt; of &lt;code&gt;whoami&lt;/code&gt;, so we redirect it into a file inside a&#10;directory the web server will happily serve back to us, then just request that&#10;file.&lt;/p&gt;</description></item><item><title>Blind OS Command Injection with Time Delays</title><link>https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-time-delay/</link><pubDate>Sun, 27 Sep 2026 14:00:00 +0300</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-time-delay/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;OS command injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Blind OS command injection with time delays&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Practitioner&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Cause a 10-second delay to prove command execution&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="what-makes-this-one-blind"&gt;What makes this one &amp;ldquo;blind&amp;rdquo;?&lt;/h2&gt;&#10;&lt;p&gt;In the &lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-simple/"&gt;simple case&lt;/a&gt;&#10; the&#10;command&amp;rsquo;s output came straight back in the response. Here it doesn&amp;rsquo;t: the&#10;application runs a shell command with your input but never returns the result.&#10;That means we can&amp;rsquo;t just read the output of &lt;code&gt;whoami&lt;/code&gt;, so we need an &lt;em&gt;inference&lt;/em&gt;&#10;technique to confirm the injection actually ran.&lt;/p&gt;</description></item><item><title>OS Command Injection: Simple Case</title><link>https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-simple/</link><pubDate>Sat, 26 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-simple/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PortSwigger Web Security Academy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;OS command injection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Lab&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;OS command injection, simple case&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Apprentice&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Goal&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Execute &lt;code&gt;whoami&lt;/code&gt; to retrieve the current user&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Tools&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Burp Suite (Proxy + Repeater)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="what-is-os-command-injection"&gt;What is OS command injection?&lt;/h2&gt;&#10;&lt;p&gt;OS command injection (also called shell injection) happens when a web&#10;application passes user-controlled input into a system shell command without&#10;sanitizing it. If an attacker can inject shell metacharacters, they can append&#10;their own commands and have the server execute them, often with the privileges&#10;of the web application.&lt;/p&gt;</description></item><item><title>Potato</title><link>https://www.yusufalmahmeed.com/posts/potato/</link><pubDate>Fri, 25 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/posts/potato/</guid><description>&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Machine&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Potato&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Platform&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;OffSec Proving Grounds (Practice)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Difficulty&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Easy&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;OS&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Linux&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Learning Path&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Web fundamentals / OSCP prep&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Key Techniques&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;PHP type juggling, LFI, hash cracking, sudo wildcard privesc&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;strong&gt;Est. Time to Complete&lt;/strong&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;~30–45 min&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;&#10;&lt;p&gt;Potato is an easy-rated Linux box on OffSec Proving Grounds Practice. Despite the low difficulty, it strings together several instructive techniques: an exposed source-code backup leaks the login logic, a PHP type-juggling flaw bypasses authentication, the admin panel&amp;rsquo;s Logs page is vulnerable to Local File Inclusion, and a careless &lt;code&gt;sudo&lt;/code&gt; wildcard rule provides the final step to root. It is a compact box where careful enumeration, not brute force, opens each step.&lt;/p&gt;</description></item><item><title>awards.md</title><link>https://www.yusufalmahmeed.com/awards/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/awards/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;cat awards.md&lt;/p&gt;&#10;&lt;h2 id="isaca-cdpse-top-scorer"&gt;ISACA CDPSE Top Scorer&lt;/h2&gt;&#10;&lt;p&gt;Recognized as the &lt;strong&gt;global Top Scorer&lt;/strong&gt; for the Certified Data Privacy Solutions&#10;Engineer (CDPSE) examination by ISACA.&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;A certification that bridges technical security work and legal privacy&#10;requirements.&lt;/li&gt;&#10;&lt;li&gt;Covered &lt;strong&gt;privacy governance, data life-cycle management, and&#10;privacy-enhancing technologies&lt;/strong&gt;.&lt;/li&gt;&#10;&lt;li&gt;Reflects how I approach privacy: &lt;strong&gt;built into systems from the design stage&lt;/strong&gt;,&#10;not bolted on afterwards.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="al-baraka-islamic-bank-recognition"&gt;Al Baraka Islamic Bank Recognition&lt;/h2&gt;&#10;&lt;p&gt;Formally recognized for exceptional performance as Information Security Section&#10;Head and Data Protection Guardian, and as a key driver of the bank&amp;rsquo;s strategic&#10;goals.&lt;/p&gt;</description></item><item><title>contact.md</title><link>https://www.yusufalmahmeed.com/contact/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/contact/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;cat contact.md&lt;/p&gt;&#10;&lt;p&gt;Feel free to reach out directly. I&amp;rsquo;m happy to talk cybersecurity, governance,&#10;data protection, or collaborating on relevant projects.&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Email:&lt;/strong&gt; &lt;a href="mailto:yusuf.almahmeed@outlook.com"&gt;yusuf.almahmeed@outlook.com&lt;/a&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;LinkedIn:&lt;/strong&gt; &lt;a href="https://www.linkedin.com/in/yusuf-almahmeed-62aa9927/" target="_blank" rel="noopener noreferrer"&gt;linkedin.com/in/yusuf-almahmeed&lt;/a&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/YusufAlMahmeed" target="_blank" rel="noopener noreferrer"&gt;github.com/YusufAlMahmeed&lt;/a&gt;&#10;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;gpg &amp;ndash;show-keys yusuf-almahmeed.asc&lt;/p&gt;&#10;&lt;p&gt;For sensitive messages, encrypt to my PGP key.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Fingerprint:&lt;/strong&gt; &lt;code&gt;1AA9 0ABC 0328 CF1A 3DDF 2C3C 0048 D251 1D85 421B&lt;/code&gt;&lt;/p&gt;&#10;&lt;p&gt;&lt;a href="https://www.yusufalmahmeed.com/keys/yusuf-almahmeed.asc"&gt;⤓ Download public key (.asc)&lt;/a&gt;&#10;&lt;/p&gt;&#10;&lt;pre class="pgp-key"&gt;-----BEGIN PGP PUBLIC KEY BLOCK-----&#10;&#10;mDMEarfIvRYJKwYBBAHaRw8BAQdAOJHMbvnCuG/VPM7lxPXcYk5T3yvvXxUCWOKR&#10;ls+vzg+0LVl1c3VmIEFsTWFobWVlZCA8eXVzdWYuYWxtYWhtZWVkQG91dGxvb2su&#10;Y29tPoi1BBMWCgBdFiEEGqkKvAMozxo93yw8AEjSUR2FQhsFAmq3yL0bFIAAAAAA&#10;BAAObWFudTIsMi41KzEuMTIsMiwxAhsDBQkFpKzTBQsJCAcCAiICBhUKCQgLAgQW&#10;AgMBAh4HAheAAAoJEABI0lEdhUIbXZ4A/0eHVtOoNyPU0rNaxuoRIk0z0Ew1t9eg&#10;Iyto/sE1ZUrnAP9bH69ip6xCTq0eGWMWXvAFYPdu9akCD2xdTNsoqYkaBrg4BGq3&#10;yL0SCisGAQQBl1UBBQEBB0CZp9jFgJwNP7zfinS/JfxScDxrN7TelAY+dKFwWU4q&#10;OAMBCAeImgQYFgoAQhYhBBqpCrwDKM8aPd8sPABI0lEdhUIbBQJqt8i9GxSAAAAA&#10;AAQADm1hbnUyLDIuNSsxLjEyLDIsMQIbDAUJBaSs0wAKCRAASNJRHYVCG+UdAQDS&#10;AKkp4EtCuJ3d0D5BmmNgxndgXAP+qguI+e2beh699gEAyzBbTsZgKluuJyebvXSU&#10;DCZTn/lnBshFLZIeFtSgFgc=&#10;=1fJN&#10;-----END PGP PUBLIC KEY BLOCK-----&lt;/pre&gt;&#10;&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;&lt;span class="cursor"&gt;&lt;/span&gt;&lt;/p&gt;</description></item><item><title>education.md</title><link>https://www.yusufalmahmeed.com/education/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/education/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;cat education.md&lt;/p&gt;&#10;&lt;h2 id="university-degrees"&gt;University Degrees&lt;/h2&gt;&#10;&lt;h3 id="msc-in-cybersecurity-university-of-bahrain"&gt;M.Sc. in Cybersecurity, University of Bahrain&lt;/h3&gt;&#10;&lt;p&gt;&lt;code&gt;2021 – 2023 · First-Class Honours&lt;/code&gt;&lt;/p&gt;&#10;&lt;p&gt;A Master&amp;rsquo;s in Cybersecurity at the University of Bahrain, taken to put a stronger&#10;theoretical foundation under existing hands-on experience. Graduated with&#10;First-Class Honours, alongside two published academic papers. The thesis,&#10;&lt;em&gt;&amp;ldquo;Zero-day Attacks Detection Using a Threat Hunting Intelligence Approach&amp;rdquo;&lt;/em&gt;, looked&#10;at catching zero-day attacks earlier by improving detection with threat-hunting&#10;techniques.&lt;/p&gt;&#10;&lt;h3 id="bsc-information--communication-technology-bahrain-polytechnic"&gt;B.Sc. Information &amp;amp; Communication Technology, Bahrain Polytechnic&lt;/h3&gt;&#10;&lt;p&gt;&lt;code&gt;2015 – 2020&lt;/code&gt;&lt;/p&gt;</description></item><item><title>experience.md</title><link>https://www.yusufalmahmeed.com/experience/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/experience/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;cat experience.md&lt;/p&gt;&#10;&lt;p&gt;A timeline of roles across banking security, governance, data protection,&#10;consulting and teaching.&lt;/p&gt;&#10;&lt;h2 id="full-time"&gt;Full-Time&lt;/h2&gt;&#10;&lt;h3 id="founder-rogsec-technology-solutions"&gt;Founder, RogSec Technology Solutions&lt;/h3&gt;&#10;&lt;p&gt;&lt;code&gt;2025 – present&lt;/code&gt;&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Why launch RogSec?&lt;/strong&gt; After more than five years in the banking industry,&#10;holding roles spanning end-to-end security from infrastructure to governance&#10;(infrastructure security, business continuity, disaster recovery, data privacy,&#10;information security), I founded RogSec to serve a broader range of clients and&#10;gain experience across different sectors and projects.&lt;/p&gt;</description></item><item><title>labs</title><link>https://www.yusufalmahmeed.com/labs/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/labs/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;ls -R labs/&lt;/p&gt;&#10;&lt;p&gt;Hands-on lab writeups, grouped by series. Each series is a set of related labs&#10;worked through in order.&lt;/p&gt;&#10;&lt;h3 class="series-list__name"&gt;PortSwigger: OS Command Injection&lt;/h3&gt;&#10; &lt;ol class="series-list__items"&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-simple/"&gt;OS Command Injection: Simple Case&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-time-delay/"&gt;Blind OS Command Injection with Time Delays&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/os-command-injection/lab-output-redirection/"&gt;Blind OS Command Injection with Output Redirection&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3 class="series-list__name"&gt;PortSwigger: Server-Side Template Injection&lt;/h3&gt;&#10; &lt;ol class="series-list__items"&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-basic/"&gt;Basic Server-Side Template Injection&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-code-context/"&gt;Basic Server-Side Template Injection (Code Context)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-unknown-language/"&gt;Server-Side Template Injection in an Unknown Language&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-documentation/"&gt;Server-Side Template Injection Using Documentation&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-sandboxed-environment/"&gt;Server-Side Template Injection in a Sandboxed Environment&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-user-supplied-objects/"&gt;Server-Side Template Injection via User-Supplied Objects&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/ssti/lab-custom-exploit/"&gt;Server-Side Template Injection with a Custom Exploit&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h3 class="series-list__name"&gt;PortSwigger: XML External Entity Injection&lt;/h3&gt;&#10; &lt;ol class="series-list__items"&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-retrieve-files/"&gt;Exploiting XXE to Retrieve Files&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/portswigger/xxe/lab-xxe-to-ssrf/"&gt;Exploiting XXE to Perform SSRF&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&#10;&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;&lt;span class="cursor"&gt;&lt;/span&gt;&lt;/p&gt;</description></item><item><title>machines</title><link>https://www.yusufalmahmeed.com/machines/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/machines/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;ls -R machines/&lt;/p&gt;&#10;&lt;p&gt;Machine and box walkthroughs, grouped by platform.&lt;/p&gt;&#10;&lt;h3 class="series-list__name"&gt;OffSec Proving Grounds&lt;/h3&gt;&#10; &lt;ul class="series-list__items"&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/shakabrah/"&gt;Shakabrah&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.yusufalmahmeed.com/posts/potato/"&gt;Potato&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&#10;&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;&lt;span class="cursor"&gt;&lt;/span&gt;&lt;/p&gt;</description></item><item><title>privacy.md</title><link>https://www.yusufalmahmeed.com/privacy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/privacy/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;cat privacy.md&lt;/p&gt;&#10;&lt;p&gt;&lt;em&gt;Last updated: 2026-09-28&lt;/em&gt;&lt;/p&gt;&#10;&lt;p&gt;What this site collects.&lt;/p&gt;&#10;&lt;h2 id="in-your-browser"&gt;In your browser&lt;/h2&gt;&#10;&lt;p&gt;The site stores a few functional preferences on your device, through your&#10;browser&amp;rsquo;s local and session storage:&lt;/p&gt;&#10;&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;Key&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;Purpose&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;crt-disabled&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Your retro-CRT effects on/off choice&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;crt-booted&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Whether the boot animation has played this session&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;privacy-notice&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Whether you dismissed this notice this session&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h2 id="server-logs"&gt;Server logs&lt;/h2&gt;&#10;&lt;p&gt;The site is hosted on &lt;strong&gt;Cloudflare&lt;/strong&gt;, which records standard server logs,&#10;including your &lt;strong&gt;IP address&lt;/strong&gt; and basic request metadata (such as the requested&#10;URL, timestamp, and user agent), to deliver and secure the site. See the&#10;&lt;a href="https://www.cloudflare.com/privacypolicy/" target="_blank" rel="noopener noreferrer"&gt;Cloudflare Privacy Policy&lt;/a&gt;&#10;.&lt;/p&gt;</description></item><item><title>publications.md</title><link>https://www.yusufalmahmeed.com/publications/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/publications/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;cat publications.md&lt;/p&gt;&#10;&lt;h2 id="zero-day-attack-solutions-using-threat-hunting-intelligence-extensive-survey"&gt;Zero-day Attack Solutions Using Threat Hunting Intelligence: Extensive Survey&lt;/h2&gt;&#10;&lt;p&gt;As technology advances, the attack surface grows and new threats become harder to&#10;mitigate, with zero-day attacks chief among them. Threat hunting is one technique&#10;used to detect them. This paper presents an extensive survey of the main approaches,&#10;challenges, and benefits of threat-hunting intelligence, and reviews&#10;state-of-the-art solutions for mitigating zero-day attacks, including SIEM tools,&#10;machine-learning solutions, and honeypot-based approaches.&lt;/p&gt;</description></item><item><title>tools</title><link>https://www.yusufalmahmeed.com/tools/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.yusufalmahmeed.com/tools/</guid><description>&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;ls -la tools/&lt;/p&gt;&#10;&lt;p&gt;Tools I&amp;rsquo;ve built for security work, mostly small, focused command-line&#10;utilities. Each entry links to a writeup here and to the source on&#10;&lt;a href="https://github.com/YusufAlMahmeed" target="_blank" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;&#10;.&lt;/p&gt;&#10;&lt;ul class="series-list__items"&gt;&lt;li&gt;&#10; &lt;a href="https://www.yusufalmahmeed.com/posts/tools/cataract/"&gt;Cataract: Tiered Web Enumeration&lt;/a&gt; &lt;span class="tools-list__desc"&gt;— Cataract is a Bash tool that cascades escalating wordlist tiers through feroxbuster while running nmap in the background, for authorized web enumeration.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&#10;&lt;p&gt;&lt;span class="prompt"&gt;&lt;/span&gt;&lt;span class="cursor"&gt;&lt;/span&gt;&lt;/p&gt;</description></item></channel></rss>