Skip to content

Pentesting reports

Notes on penetration testing journeys

Tag: javascript

Keep JavaScript disabled, and strange things could happen

Posted on 2019/02/01 by trouble

Have you ever surfed the web with JavaScript disabled? It is another web, faster for sure. It is a must if you’re surfing the Tor network. It is a strong suggestion even when surfing the clearnet. JavaScript can expose some personal info about us, it is a fact.

Well long story short, some days ago I was looking for login forms to bypass and as usual I was browsing with JavaScript disabled. I’ve opened the next google result and boom! The admin area was in front of me! Wait… where is the login form? I’ve tried to enable JavaScript and… There is the login form. So, disabling JS again would let me enter the admin area. The easiest exploit ever done.

 

Posted in Bypass loginTagged bypass login, javascript, javascript disabled, js, no javascript, no js

Music from Soundcloud

Pages

  • Manifesto
  • Get in touch

Categories

  • Arbitrary file download
  • Bash one-liners
  • Bypass login
  • PHP snippets

RSS feed: RSS Feed from Exploit DB RSS Feed from Exploit DB

  • [remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
  • [remote] PCMan 2.0.7 - Buffer Overflow
  • [webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
  • [webapps] Nodemailer 9.0.0 - File Read/ SSRF
  • [webapps] flyto-core 2.26.7 - Arbitrary File Write
  • [dos] NanaZip 6.5 - DoS
  • [remote] D-Link DNS_340L - OS Command Injection
  • [remote] ipTIME A3004T - Remote Code Execution
  • [webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
  • [dos] Nmap 7.99 - Extension Header Integer Underflow

RSS feed: RSS Feed from Packetstorm RSS Feed from Packetstorm

RSS feed: Rss Feed from Nist Rss Feed from Nist

Proudly powered by WordPress | Theme: micro, developed by DevriX.