lessons/
41 pages · Updated June 14, 2026
Pages
- Explore Lessons
- Reflected XSS
- DOM-based XSS
- Mass Assignment
- Unencrypted Communication
- Server-Side Request Forgery
- Weak Session IDs
- XML Bombs
- User Enumeration
- Session Fixation
- Regex Injection
- XML External Entities
- Insecure Design
- SQL Injection
- Subdomain Squatting
- Prototype Pollution
- Toxic Dependencies
- SSL Stripping
- Remote Code Execution
- Password Mismanagement
- Open Redirects
- Privilege Escalation
- Host Header Poisoning
- Logging and Monitoring
- Malvertising
- Lax Security Settings
- Information Leakage
- DNS Poisoning
- File Upload Vulnerabilities
- Email Spoofing
- Downgrade Attacks
- Denial of Service Attacks
- Directory Traversal
- Broken Access Control
- AI: Data Extraction Attacks
- Cross-Site Request Forgery
- Command Execution
- Clickjacking
- AI: Prompt Injection
- Buffer Overflows
- AI: Bias and Unreliability