<feed xmlns="http://www.w3.org/2005/Atom"> <id>/</id><title>T4T4R1S</title><subtitle>A minimal, responsive and feature-rich Jekyll theme for technical writing.</subtitle> <updated>2026-05-24T09:59:05+00:00</updated> <author> <name>Mustafa Eltayeb Saad</name> <uri>/</uri> </author><link rel="self" type="application/atom+xml" href="/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Mustafa Eltayeb Saad </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>MonitorsFour</title><link href="/posts/monitor4/" rel="alternate" type="text/html" title="MonitorsFour" /><published>2026-05-24T00:01:00+00:00</published> <updated>2026-05-24T09:58:44+00:00</updated> <id>/posts/monitor4/</id> <content type="text/html" src="/posts/monitor4/" /> <author> <name>mustafa_altayeb</name> </author> <category term="Hack The Box" /> <summary>Walkthrough of the MonitorsFour machine – web app enumeration, Cacti RCE, Docker API abuse for root</summary> </entry> <entry><title>Infinity - SQL Injection - Opengate</title><link href="/posts/Infinity-SQL-injection-Opengate/" rel="alternate" type="text/html" title="Infinity - SQL Injection - Opengate" /><published>2026-05-20T00:07:00+00:00</published> <updated>2026-05-22T07:56:21+00:00</updated> <id>/posts/Infinity-SQL-injection-Opengate/</id> <content type="text/html" src="/posts/Infinity-SQL-injection-Opengate/" /> <author> <name>mustafa_altayeb</name> </author> <category term="Infinity" /> <category term="Web_Security" /> <category term="SQLI" /> <summary>A walkthrough of exploiting SQL Injection in a login form on Infinity platform. By injecting a boolean condition and switching comment syntax from -- to `#`, we bypassed authentication and gained access to the application.</summary> </entry> <entry><title>Infinity - SQL Injection - Second Strike</title><link href="/posts/Infinity-SQL-injection-Second-Strike/" rel="alternate" type="text/html" title="Infinity - SQL Injection - Second Strike" /><published>2026-05-20T00:06:00+00:00</published> <updated>2026-05-22T07:56:21+00:00</updated> <id>/posts/Infinity-SQL-injection-Second-Strike/</id> <content type="text/html" src="/posts/Infinity-SQL-injection-Second-Strike/" /> <author> <name>mustafa_altayeb</name> </author> <category term="Infinity" /> <category term="Web_Security" /> <category term="SQLI" /> <summary>A walkthrough of exploiting Second-Order SQL Injection in an update username feature on Infinity platform. By injecting into an UPDATE query, we escalated privileges from a regular user to admin without needing to know any credentials.</summary> </entry> <entry><title>Infinity - SQL Injection - Username</title><link href="/posts/Infinity-SQL-injection-Username/" rel="alternate" type="text/html" title="Infinity - SQL Injection - Username" /><published>2026-05-20T00:04:00+00:00</published> <updated>2026-05-22T07:56:21+00:00</updated> <id>/posts/Infinity-SQL-injection-Username/</id> <content type="text/html" src="/posts/Infinity-SQL-injection-Username/" /> <author> <name>mustafa_altayeb</name> </author> <category term="Infinity" /> <category term="Web_Security" /> <category term="SQLI" /> <summary>A walkthrough of exploiting Boolean-based SQL Injection in a registration form on Infinity platform. By crafting true/false conditions and automating character extraction with Python, we recovered user passwords from the database.</summary> </entry> <entry><title>Infinity - SQL Injection - Login_Logic</title><link href="/posts/Infinity-SQL-injection-Login_login/" rel="alternate" type="text/html" title="Infinity - SQL Injection - Login_Logic" /><published>2026-05-20T00:04:00+00:00</published> <updated>2026-05-22T07:56:21+00:00</updated> <id>/posts/Infinity-SQL-injection-Login_login/</id> <content type="text/html" src="/posts/Infinity-SQL-injection-Login_login/" /> <author> <name>mustafa_altayeb</name> </author> <category term="Infinity" /> <category term="Web_Security" /> <category term="SQLI" /> <summary>A walkthrough of exploiting a Boolean-based SQL Injection vulnerability in a login form on Infinity platform. By injecting a true condition into the username field, we bypassed authentication without knowing any credentials.</summary> </entry> </feed>
