MENU
  • Home
  • Hacking
    • Kali Linux
    • VULNHUB
  • Goods
Hack Lab. 256
  • Home
  • Hacking
    • Kali Linux
    • VULNHUB
  • Goods
Hack Lab. 256
  • Home
  • Hacking
    • Kali Linux
    • VULNHUB
  • Goods
  1. Home
  2. Popular

Popular

  • [XSS Demo] I tried hacking a website in just one line!!
    Other

    [XSS Demo] I tried hacking a website in just one line!!

    "I tried creating a bulletin board app that can use HTML tags!" What if a work by a beginner engineer would be "taken over" with just one line post? This time, we will be using an example of "Cross-site Scripting (XSS)," which is the basics of security, to see how vulnerable they are...
    July 14, 2025
    38
  • [CVE-2015-3306] I enumerated the shared Samba, manipulate a vulnerable version of proftpd, and escalated privileges by manipulating path variables! TryHackMe Kenobi Writeup
    Cyber Weapons

    [CVE-2015-3306] I enumerated the shared Samba, manipulate a vulnerable version of proftpd, and escalated privileges by manipulating path variables! TryHackMe Kenobi Writeup

    This time, we will enumerate shared Samba, manipulate vulnerable versions of proftpd, and escalate privileges by manipulating path variables. "TryHackMe-Kenobi: https://tryhackme.com/room/kenobi" Please note that the explanation is a spoiler. Preparation First, start with "Start Machine...
    August 29, 2023
    33
  • Other

    [SECCON Beginners CTF 2024] WEB Writeup

    It wasn't a very good result, but I participated in the SECCON Beginners CTF 2024, so I'll leave a Writeup as a memo. ssrforlfi source check The folder structure after unzipping tar.gz is as follows. $ find ./ ./ ./docker-compose.yml ./.env ./app...
    July 27, 2024
    23
  • Next.js + React Three Fiber + React Three XR + Variant Launch to develop a WebXR compatible AR app on iOS!
    React

    Next.js + React Three Fiber + React Three XR + Variant Launch to develop a WebXR compatible AR app on iOS!

    I was thinking of creating an AR app with WebXR, but the current situation is that iOS does not officially support WebXR. So, I used Variant Launch, which was also featured in the official React Three XR, to support WebXR AR on iOS as well. Does it work on iOS?WebXR fo...
    June 12, 2025
    20
  • [AI Development Tool] Vibe Coding with Lovable! Full-scale Web App Development with Supabase and AI | How to Get Started & Pricing Plans
    App Generation

    [AI Development Tool] Vibe Coding with Lovable! Full-scale Web App Development with Supabase and AI | How to Get Started & Pricing Plans

    "I want to create a more professional service, but I don't think I can write code..." For non-engineers who want to get serious about vibe coding, Lovable is the perfect development platform for the next step. Recently, there's been a lot of talk about AI-generated landing pages and UIs...
    August 19, 2025
    20
  • [Practical Guide] Hacking with RCE from SSTI Vulnerability on HackTheBox! Learn the Causes and Countermeasures of Vulnerabilities | Spookifier Writeup
    Hacking

    [Practical Guide] Hacking with RCE from SSTI Vulnerability on HackTheBox! Learn the Causes and Countermeasures of Vulnerabilities | Spookifier Writeup

    Template engines are widely used in web applications to combine HTML and data to generate displays. For example, template engines are used on the backend to embed usernames, post contents, and other information into HTML. However,...
    August 7, 2025
    18
  • [Full-stack AI development] My impressions after using Replit and pricing plans explained | It's great, but is it difficult for non-engineers?
    App Generation

    [Full-stack AI development] My impressions after using Replit and pricing plans explained | It's great, but is it difficult for non-engineers?

    "I tried making an app with an AI development tool, but I always got stuck connecting to external services..." Replit is the ideal development environment for such "Vibecoders who want to take it a step further." Recently, many AI tools have appeared that automatically generate UI and code, but...
    August 29, 2025
    18
  • Create.xyz is the best! No API key required, AI app development and mobile app development can be completed with Vibe Coding | How to get started & pricing plan explanation
    App Generation

    Create.xyz is the best! No API key required, AI app development and mobile app development can be completed with Vibe Coding | How to get started & pricing plan explanation

    "I have an idea, but I don't think I can develop an app..." For non-engineers who want to create web or mobile apps, create.xyz is a dream development platform. Recently, there have been many apps that generate UIs in natural language and suggest code snippets...
    August 24, 2025
    17
  • I tried creating a chatbot using the OpenAI API [Next.js + Tailwind CSS]
    React

    I tried creating a chatbot using the OpenAI API [Next.js + Tailwind CSS]

    Recently, more and more people are using OpenAI's API to create their own chatbots and business assistants. This article shows you how to build a simple and easy to customize chat UI using Next.js (App Router) and Tailwind CSS. OpenAI chat...
    July 27, 2025
    15
  • [TryHackMe] Expanding privilege escalation using backups of history files, config files, and important files! Linux PrivEsc Writeup Part 8
    Cyber Weapons

    [TryHackMe] Expanding privilege escalation using backups of history files, config files, and important files! Linux PrivEsc Writeup Part 8

    This time, we will try "Elevation of privileges by misusing backups of history files, config files, and important files." The target machine uses the Room below of TryHackMe. "TryHackMe-Linux PrivEsc: https://tryhackme.com/room/linuxprivesc" here...
    April 15, 2023
    15
1...5678
  • Home
  • Contact
  • Privacy Policy

© Hack Lab. 256.