Challenge 1 - Stored cross-site scripting attack

Practice stored XSS in a vulnerable lab and learn how malicious input can be saved and shown to other users.

13 December 2022 · 5 min

XSS Explained - Learn cross-site scripting with examples

A beginner-friendly guide to cross-site scripting using Kurukshetra, an intentionally vulnerable XSS practice lab.

25 November 2022 · 4 min

DVWA - Brute Force Attack and Prevention Explained

Learn how brute force attacks work in DVWA, what makes them dangerous, and which defenses help reduce risk.

30 September 2022 · 13 min

Mitigating XSS Vulnerability

Learn practical ways to reduce cross-site scripting risk with output encoding, validation, CSP, and safer development habits.

20 August 2022 · 5 min

Mitigating Command Injection

Understand command injection risks and learn practical mitigation steps for safer handling of system commands.

10 August 2022 · 4 min

DVWA Brute Force Attack - High Severity

Walk through DVWA high-severity brute force testing and see how weak fixes can still be bypassed with BurpSuite.

4 August 2022 · 10 min

DVWA Brute Force Attack - Medium Severity

Walk through DVWA medium-severity brute force testing and learn how partial defenses can be bypassed in practice.

3 August 2022 · 5 min

Lab Setup - Docker DVWA

Set up a local DVWA lab with Docker so you can safely practice common web application security testing techniques.

30 July 2022 · 7 min

BurpSuite Overview

A beginner-friendly overview of BurpSuite and the core tools used during web application security testing.

29 July 2022 · 9 min

BurpSuite Installation

Install BurpSuite on Linux, understand available packages, and prepare the tool for web application security testing.

28 July 2022 · 3 min