The N45HT Blog

  • HOME
  • LEARNING
  • TOOLS
  • NEWS
  • RESEARCH
  • Hacking AI with Markdown: How We Triggered XSS in DeepSeek’s Chat

    Hacking AI with Markdown: How We Triggered XSS in DeepSeek’s Chat

    Choirur Rizal

    •

    May 9, 2025

    AI-generated chat messages are becoming a cornerstone of modern digital interaction. From customer support to creative writing, platforms…

  • Critical SQL Injection in a Major Indonesian Web Hosting Platform

    Critical SQL Injection in a Major Indonesian Web Hosting Platform

    Choirur Rizal

    •

    November 20, 2024

    While exploring vulnerabilities in a major web hosting company in Indonesia, I discovered a critical SQL injection vulnerability…

  • Breaking Vercel’s Clone URL with a Simple XSS Exploit

    Breaking Vercel’s Clone URL with a Simple XSS Exploit

    XAdmin

    •

    August 6, 2024

    During my exploration of Vercel’s platform, I discovered a reflected XSS vulnerability in the “clone project” functionality. This…

  • Bypassing Razer’s WAF for XSS

    Bypassing Razer’s WAF for XSS

    Choirur Rizal

    •

    January 24, 2024

    While testing Razer’s web application, I identified an XSS vulnerability in their /ajax endpoint. The issue arises due…

  • Finding WordPress Vulnerabilities on CarGurus with WPScan

    Finding WordPress Vulnerabilities on CarGurus with WPScan

    XAdmin

    •

    August 19, 2023

    While exploring CarGurus’ bug bounty program, I discovered a reflected XSS vulnerability on their subdomain dealercentre.cargurus.co.uk. This writeup…

  • N45HTCTF2023

    N45HTCTF2023

    XAdmin

    •

    July 21, 2023

    N45HTCTF2023 | “Cyber Security and Indonesian History” N45HT held a CTF (Capture the Flag) event to celebrate independence…

  • Stored XSS on Chess24.com

    Stored XSS on Chess24.com

    Choirur Rizal

    •

    June 24, 2023

    I recently registered on Chess24.com and, after playing a few games, decided to conduct a quick security analysis…

  • XSS: Bypass CloudFront WAF

    XSS: Bypass CloudFront WAF

    Choirur Rizal

    •

    June 21, 2023

    In this article, we will share how we successfully bypassed the CloudFront WAF (Web Application Firewall) to exploit…


Next→

Recent Posts

  • Hacking AI with Markdown: How We Triggered XSS in DeepSeek’s Chat
    AI-generated chat messages are becoming a cornerstone of modern digital… Read more: Hacking AI with Markdown: How We Triggered XSS in DeepSeek’s Chat
  • Critical SQL Injection in a Major Indonesian Web Hosting Platform
    While exploring vulnerabilities in a major web hosting company in… Read more: Critical SQL Injection in a Major Indonesian Web Hosting Platform
  • Breaking Vercel’s Clone URL with a Simple XSS Exploit
    During my exploration of Vercel’s platform, I discovered a reflected… Read more: Breaking Vercel’s Clone URL with a Simple XSS Exploit
  • Bypassing Razer’s WAF for XSS
    While testing Razer’s web application, I identified an XSS vulnerability… Read more: Bypassing Razer’s WAF for XSS
  • Finding WordPress Vulnerabilities on CarGurus with WPScan
    While exploring CarGurus’ bug bounty program, I discovered a reflected… Read more: Finding WordPress Vulnerabilities on CarGurus with WPScan

Social Media

  • Twitter
  • Instagram
  • LinkedIn
  • Facebook

Advertisement

Tags

API Bug Bounty Capture The Flag Cross-site Scripting CTF ExifTool HTML JavaScript Markdown Open Redirection PHP SQL Injection VDP WAF Web Application Firewall XSS XSSR XSSRush

Connect With Us

  • Bali, Indonesia
  • [email protected]
  • Twitter
  • Instagram
  • Facebook

Categories

  • Learning
  • Tools
  • News
  • Research

N45HT

  • About
  • Contact
  • Products
  • Security

Search

Looking for something specific? Try a search below!

Copyright © 2023 | Made with love by SuperbThemes