This repo contains the code for my Secure Code Review challenges
- Open Redirect
- SSRF
- Weak Password Hashing
- Hardcoded Credentials
- XXE
- XSS
- Host Header Injection
- Nginx Off-By-Slash
- Broken Access Control
- Broken Access Control (JWT missing verification)
- Path Normalization Bypass
- Unquoted Bash Variables
- SQL Injection
- Race Condition
- ...
- ...
- ...
- ...
- ...
- ...