<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Phat Mai - Security Research &amp; Writeups</title>
    <link>https://pzhat.id.vn</link>
    <description>Security research publication, vulnerability disclosures, CVE analyses, and technical writeups by Phat Mai.</description>
    <language>en</language>
    <atom:link href="https://pzhat.id.vn/feed.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title>CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE</title>
      <link>https://pzhat.id.vn/research/cve-2026-40478</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-40478</guid>
      <pubDate>Thu, 04 Jun 2026 17:00:00 GMT</pubDate>
      <description># CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE

![image](https://hackmd.io/uploads/BkLrCXJZzg.png)

## Overview
...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
    </item>

    <item>
      <title>CVE-2026-3359 WordPress Form Maker by 10Web Plugin &lt;= 1.15.42 is vulnerable to a high priority SQL Injection</title>
      <link>https://pzhat.id.vn/research/cve-2026-3359</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-3359</guid>
      <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
      <description># Critical SQL Injection (CVE-2026-3359) in WordPress Form Maker by 10Web

![image](https://hackmd.io/uploads/rJC0RXuRbg.png)

## Overview

   Published: ...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-2628 WordPress All-in-One Microsoft 365 &amp;amp; Entra ID / Azure AD SSO Login Plugin &lt;= 2.2.5 is vulnerable to a high priority Bypass Vulnerability</title>
      <link>https://pzhat.id.vn/research/cve-2026-2628</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-2628</guid>
      <pubDate>Sun, 03 May 2026 17:00:00 GMT</pubDate>
      <description># WordPress All-in-One Microsoft 365 &amp;amp; Entra ID / Azure AD SSO Login Plugin &lt;= 2.2.5 is vulnerable to a high priority Bypass Vulnerability

![image](https...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-2942 WordPress ProSolution WP Client Plugin &lt;= 1.9.9 is vulnerable to a high priority Arbitrary File Upload</title>
      <link>https://pzhat.id.vn/research/cve-2026-2942</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-2942</guid>
      <pubDate>Sun, 12 Apr 2026 17:00:00 GMT</pubDate>
      <description>## CVE-2026-2942 WordPress ProSolution WP Client Plugin &lt;= 1.9.9 is vulnerable to a high priority Arbitrary File Upload

![image](https://hackmd.io/uploads/H1...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-3658 WordPress Simply Schedule Appointments Plugin &lt;= 1.6.10.0 is vulnerable to a high priority SQL Injection</title>
      <link>https://pzhat.id.vn/research/cve-2026-3658</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-3658</guid>
      <pubDate>Sun, 12 Apr 2026 17:00:00 GMT</pubDate>
      <description>## CVE-2026-3658 WordPress Simply Schedule Appointments Plugin &lt;= 1.6.10.0 is vulnerable to a high priority SQL Injection

![image](https://hackmd.io/uploads/...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-1581 WordPress wpForo Forum Plugin is vulnerable to a high priority SQL Injection</title>
      <link>https://pzhat.id.vn/research/cve-2026-1581</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-1581</guid>
      <pubDate>Tue, 30 Dec 2025 17:00:00 GMT</pubDate>
      <description># CVE-2026-1581 WordPress wpForo Forum Plugin is vulnerable to a high priority SQL Injection

![image](https://hackmd.io/uploads/BJipTiSdbe.png)

## Overvie...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-0702 WordPress VidShop Plugin &lt;= 1.1.4 is vulnerable to a high priority SQL Injection</title>
      <link>https://pzhat.id.vn/research/cve-2026-0702</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-0702</guid>
      <pubDate>Mon, 29 Dec 2025 17:00:00 GMT</pubDate>
      <description># CVE-2026-0702 WordPress VidShop Plugin &lt;= 1.1.4 is vulnerable to a high priority SQL Injection

![image](https://hackmd.io/uploads/rkhOvm9vWg.png)

# VidS...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-23550 WordPress Modular DS Plugin &lt;= 2.5.1 is vulnerable to a high priority Privilege Escalation</title>
      <link>https://pzhat.id.vn/research/cve-2026-23550</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-23550</guid>
      <pubDate>Sun, 28 Dec 2025 17:00:00 GMT</pubDate>
      <description># CVE-2026-23550 WordPress Modular DS Plugin &lt;= 2.5.1 is vulnerable to a high priority Privilege Escalation

![image](https://hackmd.io/uploads/HyLArhXPZg.png...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-3459 WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin &lt;= 1.3.9.5 is vulnerable to a high priority Arbitrary File Upload</title>
      <link>https://pzhat.id.vn/research/cve-2026-3459</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-3459</guid>
      <pubDate>Sat, 27 Dec 2025 17:00:00 GMT</pubDate>
      <description>## CVE-2026-3459 WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin &lt;= 1.3.9.5 is vulnerable to a high priority Arbitrary File Upload

![ima...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-2511 WordPress JS Help Desk Plugin &lt;= 3.0.4 is vulnerable to a high priority SQL Injection</title>
      <link>https://pzhat.id.vn/research/cve-2026-2511</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-2511</guid>
      <pubDate>Fri, 26 Dec 2025 17:00:00 GMT</pubDate>
      <description># CVE-2026-2511 JS Help Desk – AI-Powered Support &amp; Ticketing System &lt;= 3.0.4 - Unauthenticated SQL Injection via &apos;multiformid&apos; Parameter

![image](https://ha...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2026-2232 Product Table and List Builder for WooCommerce Lite Vulnerable To Unauthenticated Time-Based SQL Injection</title>
      <link>https://pzhat.id.vn/research/cve-2026-2232</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2026-2232</guid>
      <pubDate>Thu, 25 Dec 2025 17:00:00 GMT</pubDate>
      <description># CVE-2026-2232 Product Table and List Builder for WooCommerce Lite Vulnerable To Unauthenticated Time-Based SQL Injection via &apos;search&apos; Parameter

![image](ht...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>WordPress HT Contact Form 7 Plugin &lt;= 2.2.1 is vulnerable to a high priority Arbitrary File Upload</title>
      <link>https://pzhat.id.vn/research/cve-2025-7340</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2025-7340</guid>
      <pubDate>Wed, 24 Dec 2025 17:00:00 GMT</pubDate>
      <description># WordPress HT Contact Form 7 Plugin &lt;= 2.2.1 is vulnerable to a high priority Arbitrary File Upload

![image](https://hackmd.io/uploads/HJ5TohCu-g.png)

##...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2025-13329 File Uploader for WooCommerce</title>
      <link>https://pzhat.id.vn/research/cve-2025-13329</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2025-13329</guid>
      <pubDate>Tue, 23 Dec 2025 17:00:00 GMT</pubDate>
      <description># CVE-2025-13329 File Uploader for WooCommerce &lt;= 1.0.3 - Unauthenticated Arbitrary File Upload via add-image-data

![image](https://hackmd.io/uploads/SJGvzVA...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2025-68519 WordPress Brands for WooCommerce Plugin</title>
      <link>https://pzhat.id.vn/research/cve-2025-68519</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2025-68519</guid>
      <pubDate>Mon, 22 Dec 2025 17:00:00 GMT</pubDate>
      <description># CVE-2025-68519 WordPress Brands for WooCommerce Plugin &lt;= 3.8.6.3 is vulnerable to SQL Injection

![image](https://hackmd.io/uploads/ByI6-ltIbg.png)

# Wo...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>CVE-2025-14770 – Unauthenticated SQL Injection via “city” Parameter</title>
      <link>https://pzhat.id.vn/research/cve-2025-14770</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/cve-2025-14770</guid>
      <pubDate>Sun, 21 Dec 2025 17:00:00 GMT</pubDate>
      <description>![image](https://hackmd.io/uploads/r1isJ3HLZl.png)

# WordPress Shipping Rate By Cities Plugin

## Overview

- CVE ID: CVE-2025-14770
- Affected Plugin: ...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CVE</category>
      <category>Web</category>
      <category>WordPress</category>
    </item>

    <item>
      <title>Ysoserial Common Collections 3 Analyst (CC3)</title>
      <link>https://pzhat.id.vn/research/ysoserial-cc3-analyst</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/ysoserial-cc3-analyst</guid>
      <pubDate>Sat, 20 Dec 2025 17:00:00 GMT</pubDate>
      <description># Ysoserial Common Collections 3 Analyst (CC3)

### Tổng quan

CC3 (CommonsCollections3) trong ysoserial là một gadget chain dựa trên thư viện Apache Common...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>ysoserial</category>
      <category>Web</category>
    </item>

    <item>
      <title>Velocity Server Side Template Injection Challenge</title>
      <link>https://pzhat.id.vn/writeups/ssti-velocity</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/ssti-velocity</guid>
      <pubDate>Fri, 19 Dec 2025 17:00:00 GMT</pubDate>
      <description># Velocity Server Side Template Injection Challenge

### Tổng quan về lab Velocity SSTI

Đây là một lab mình thiết kế ra để demo và học về SSTI. Bên trong l...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CTF</category>
      <category>Web</category>
    </item>

    <item>
      <title>Tryhackme Hammer challenge WriteUp</title>
      <link>https://pzhat.id.vn/writeups/tryhackme-hammer</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/tryhackme-hammer</guid>
      <pubDate>Wed, 17 Dec 2025 17:00:00 GMT</pubDate>
      <description># TryHackMe Hammer Web Challenge WriteUp

![image-14](https://hackmd.io/uploads/S1-1mNlzbl.png)

### Enumeration 

![image-15](https://hackmd.io/uploads/r...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>RedTeam</category>
      <category>Pentest</category>
    </item>

    <item>
      <title>IredTeam AS-REP Roasting</title>
      <link>https://pzhat.id.vn/writeups/iredteam-as-rep-roasting</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/iredteam-as-rep-roasting</guid>
      <pubDate>Tue, 16 Dec 2025 17:00:00 GMT</pubDate>
      <description># IredTeam AS-REP Roasting 

### AS-REP là gì?

AS-REP (viết tắt của Authentication Service Reply) là một thông điệp trong giao thức xác thực Kerberos. Đây ...</description>
      <category>RedTeam</category>
      <category>pentesting</category>
      <category>Pentest</category>
      <category>iredteam</category>
    </item>

    <item>
      <title>ServerSide Template Injection (SSTI) Lab</title>
      <link>https://pzhat.id.vn/writeups/ssti-lab</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/ssti-lab</guid>
      <pubDate>Mon, 15 Dec 2025 17:00:00 GMT</pubDate>
      <description># ServerSide Template Injection (SSTI) Lab

### SSTI là gì

Server-Side Template Injection (SSTI) là một lỗ hổng bảo mật web nghiêm trọng cho phép kẻ tấn cô...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>GraphQL API Vulnerability</title>
      <link>https://pzhat.id.vn/writeups/graphql-api-vulnerability</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/graphql-api-vulnerability</guid>
      <pubDate>Sun, 14 Dec 2025 17:00:00 GMT</pubDate>
      <description># GraphQL API Vulnerability PortSwigger Challenge

### Overview về GraphQL

GraphQL là một ngôn ngữ truy vấn cho API (Query Language for APIs) và cũng là mộ...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
      <category>PortSwigger</category>
    </item>

    <item>
      <title>PortSwigger CORS (Cross-Origin Resource Sharing) challenge WriteUp</title>
      <link>https://pzhat.id.vn/writeups/cors-portswigger</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/cors-portswigger</guid>
      <pubDate>Sat, 13 Dec 2025 17:00:00 GMT</pubDate>
      <description># PortSwigger CORS (Cross-Origin Resource Sharing) challenge WriteUp

### Overview về CORS

#### CORS là gì? Vì sao lại xuất hiện
- CORS (Cross-Origin Reso...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
      <category>PortSwigger</category>
    </item>

    <item>
      <title>Ired.Team Kerberos Silver Ticket Execution</title>
      <link>https://pzhat.id.vn/writeups/i-redteam-kerberos-silver-ticket</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/i-redteam-kerberos-silver-ticket</guid>
      <pubDate>Fri, 12 Dec 2025 17:00:00 GMT</pubDate>
      <description># Ired.Team Kerberos Silver Ticket

Tiếp tục chuỗi series AD abuse thì tiếp theo ta tiến tới Kerberos Silver Ticket có nghĩa là ta sẽ hack quyền từ Kerberos n...</description>
      <category>RedTeam</category>
      <category>pentesting</category>
      <category>Pentest</category>
      <category>iredteam</category>
    </item>

    <item>
      <title>PortSwigger CSRF Challenge WriteUps</title>
      <link>https://pzhat.id.vn/writeups/csrf-portswigger-challenge</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/csrf-portswigger-challenge</guid>
      <pubDate>Thu, 11 Dec 2025 17:00:00 GMT</pubDate>
      <description># PortSwigger CSRF Challenge WriteUp

### Giới thiệu về CSRF (Cross-Site Request Forgery)

#### Lỗ hổng CSRF là gì :

- Cross-Site Request Forgery hay còn...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
      <category>PortSwigger</category>
    </item>

    <item>
      <title>Ysoserial Commons Collections 5 Analyst</title>
      <link>https://pzhat.id.vn/research/ysoserial-cc5</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/ysoserial-cc5</guid>
      <pubDate>Wed, 10 Dec 2025 17:00:00 GMT</pubDate>
      <description># Ysoserial Commons Collections 5 Analyst

### Tổng quan CommonsCollections 5 trong Ysoserial

CommonsCollections là một trong những gadget chain nổi tiếng ...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
      <category>ysoserial</category>
    </item>

    <item>
      <title>Ired.Team Kerberos Golden Tickets Lab</title>
      <link>https://pzhat.id.vn/writeups/i-redteam-kerberos-golden-ticket</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/i-redteam-kerberos-golden-ticket</guid>
      <pubDate>Tue, 09 Dec 2025 17:00:00 GMT</pubDate>
      <description># Ired.Team Kerberos: Golden Tickets Lab

### Overview
Lab này khám phá một cuộc tấn công vào Kerberos Authentication của Active Directory(AD). Chính xác hơn...</description>
      <category>RedTeam</category>
      <category>pentesting</category>
      <category>Pentest</category>
      <category>iredteam</category>
    </item>

    <item>
      <title>Tryhackme Basic Pentesting Challenge</title>
      <link>https://pzhat.id.vn/writeups/thm-basic-pentesting</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/thm-basic-pentesting</guid>
      <pubDate>Mon, 08 Dec 2025 17:00:00 GMT</pubDate>
      <description># Tryhackme Basic Pentesting Challenge

![image](https://hackmd.io/uploads/BkgEBzP1Zx.png)

Sử dụng nmap để scan các port đang mở của target ở đây tôi sử dụ...</description>
      <category>pentesting</category>
      <category>RedTeam</category>
      <category>Pentest</category>
    </item>

    <item>
      <title>Ired.Team Kerberoasting (Credential Access)</title>
      <link>https://pzhat.id.vn/writeups/i-redteam-kerberoasting</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/i-redteam-kerberoasting</guid>
      <pubDate>Sun, 07 Dec 2025 17:00:00 GMT</pubDate>
      <description># Ired.Team Kerberoasting (Credential Access)

### Giải thích về các khái niệm

#### Kerberos trong Active Directory

- Trong môi trường Windows Active Di...</description>
      <category>RedTeam</category>
      <category>pentesting</category>
      <category>Pentest</category>
      <category>iredteam</category>
    </item>

    <item>
      <title>Ired.Team From Domain Admin to Enterprise Admin</title>
      <link>https://pzhat.id.vn/writeups/iredteam-from-da-to-ea</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/iredteam-from-da-to-ea</guid>
      <pubDate>Sat, 06 Dec 2025 17:00:00 GMT</pubDate>
      <description># Ired.Team From Domain Admin to Enterprise Admin 

### Overview

Ở lab này ta sẽ lợi dụng mối quan hệ giữa Parent-Child domain từ đó lợi dụng mối quan hệ đ...</description>
      <category>RedTeam</category>
      <category>pentesting</category>
      <category>Pentest</category>
      <category>iredteam</category>
    </item>

    <item>
      <title>Java Deserialze - URLDNS Chain analysis (ysoserial)</title>
      <link>https://pzhat.id.vn/research/ysoserial-urldns</link>
      <guid isPermaLink="true">https://pzhat.id.vn/research/ysoserial-urldns</guid>
      <pubDate>Fri, 05 Dec 2025 17:00:00 GMT</pubDate>
      <description># Java Deserialze - URLDNS Chain analysis (ysoserial)

![image](https://hackmd.io/uploads/r1R3sp6Rgl.png)

### Java Deserialize là gì?

- Java cung cấp ch...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>ysoserial</category>
      <category>Web</category>
    </item>

    <item>
      <title>Spring Time CTF challenge WriteUp</title>
      <link>https://pzhat.id.vn/writeups/cscv-spring-time-challenge</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/cscv-spring-time-challenge</guid>
      <pubDate>Thu, 04 Dec 2025 17:00:00 GMT</pubDate>
      <description># Spring Time CTF challenge WriteUp

![image](https://hackmd.io/uploads/r14Z7wRgx.png)

Web App được chia làm 2 services khác nhau bao gồm:

- gateman : p...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CTF</category>
      <category>Web</category>
    </item>

    <item>
      <title>Java Deserialize CBJS Lab</title>
      <link>https://pzhat.id.vn/writeups/cbjs-java-deserialize</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/cbjs-java-deserialize</guid>
      <pubDate>Wed, 03 Dec 2025 17:00:00 GMT</pubDate>
      <description># Java Deserialize CBJS Lab 

### Giải thích chi tiết về lỗ hổng Deserialization

1. Deserialization là gì?
- Serialization là quá trình chuyển đổi một obj...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CTF</category>
      <category>Web</category>
    </item>

    <item>
      <title>Pentester Lab From Sql Injection to Shell</title>
      <link>https://pzhat.id.vn/writeups/pentesterlab-from-sql-to-shell</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/pentesterlab-from-sql-to-shell</guid>
      <pubDate>Tue, 02 Dec 2025 17:00:00 GMT</pubDate>
      <description># Pentester Lab From Sql Injection to Shell

### Fingerprinting

![image](https://hackmd.io/uploads/SyqcWYLTeg.png)

Sử dụng nmap với cú pháp:

shell
s...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>RedTeam</category>
      <category>Pentest</category>
    </item>

    <item>
      <title>Web Cache Deception Demo Lab</title>
      <link>https://pzhat.id.vn/writeups/web-cache-deception</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/web-cache-deception</guid>
      <pubDate>Mon, 01 Dec 2025 17:00:00 GMT</pubDate>
      <description># Web Cache Deception Demo Lab

### Tổng quan Web Cache Deception 

Lỗ hổng &quot;web cache deception&quot; (đánh lừa bộ nhớ đệm web) là một dạng lỗ hổng bảo mật web,...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>NoSQL Injection Vulnerability Challenge Java</title>
      <link>https://pzhat.id.vn/writeups/nosql-injection-lab</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/nosql-injection-lab</guid>
      <pubDate>Sun, 30 Nov 2025 17:00:00 GMT</pubDate>
      <description># NoSQL Injection Vulnerability Challenge Java

### Tổng quan về NoSQL Injection

- Tấn công NoSQL injection là một lỗ hổng bảo mật trong các ứng dụng web s...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>Broken Access Control Vulnerability Lab</title>
      <link>https://pzhat.id.vn/writeups/brokenaccess-control</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/brokenaccess-control</guid>
      <pubDate>Sat, 29 Nov 2025 17:00:00 GMT</pubDate>
      <description># Broken Access Control Vulnerability Lab

### What is Broken Access Control (BAC)

Broken Access Control là một loại lỗ hổng bảo mật web xảy ra khi người d...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>XXE Injection Vulnerability Lab</title>
      <link>https://pzhat.id.vn/writeups/xxe-injection</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/xxe-injection</guid>
      <pubDate>Fri, 28 Nov 2025 17:00:00 GMT</pubDate>
      <description># XXE Injection Vulnerability Lab

### XXE Injection là gì?

XXE (XML External Entity) Injection là một lỗ hổng bảo mật web cho phép kẻ tấn công can thiệp v...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>WebSec.fr level 1 CTF challenge</title>
      <link>https://pzhat.id.vn/writeups/websecfr-level1</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/websecfr-level1</guid>
      <pubDate>Thu, 27 Nov 2025 17:00:00 GMT</pubDate>
      <description># WebSec.fr level 1 CTF challenge

### Overview

![image](https://hackmd.io/uploads/Sk1nSnX3xg.png)

Giao diện chức năng của level này ta có thể thấy nó l...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CTF</category>
      <category>Web</category>
    </item>

    <item>
      <title>Server Side Request Forgery (Java)</title>
      <link>https://pzhat.id.vn/writeups/ssrf-challenge</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/ssrf-challenge</guid>
      <pubDate>Wed, 26 Nov 2025 17:00:00 GMT</pubDate>
      <description># Server Side Request Forgery (Java) 

### Source Code

Github: https://github.com/pzhat/SSRFvulndemo

### What is SSRF

Giới thiệu về Server-Side Reque...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>Java Servlet Path Traversal vulnerability</title>
      <link>https://pzhat.id.vn/writeups/path-traversal-servlet</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/path-traversal-servlet</guid>
      <pubDate>Tue, 25 Nov 2025 17:00:00 GMT</pubDate>
      <description># Java Servlet Path Traversal vulnerability

### Source Code:

[[Github Link](https://github.com/pzhat/PathTraversalLab)]

### Overview

![image](https:...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>CyberCon 2025 SafeUpload Web Challenge</title>
      <link>https://pzhat.id.vn/writeups/seccon-safeupload-web-challenge</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/seccon-safeupload-web-challenge</guid>
      <pubDate>Mon, 24 Nov 2025 17:00:00 GMT</pubDate>
      <description># CyberCon 2025 SafeUpload Web Challenge 

### Tổng quan challenge

![image](https://hackmd.io/uploads/Hkm8uTIjll.png)

Mở challenge lên thì ta thấy nó cấ...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CTF</category>
      <category>Web</category>
    </item>

    <item>
      <title>WebSec.fr Level 28 CTF challenge</title>
      <link>https://pzhat.id.vn/writeups/websec-fr-level28</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/websec-fr-level28</guid>
      <pubDate>Sun, 23 Nov 2025 17:00:00 GMT</pubDate>
      <description># WebSec.fr Level 28 CTF challenge

### Tổng quan:

![image](https://hackmd.io/uploads/Syc1KLLjxl.png)

php
&lt;?php
if(isset($POST[&apos;submit&apos;])) {
  if ($F...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CTF</category>
      <category>Web</category>
    </item>

    <item>
      <title>Tryhackme EvilGPT challenge WriteUp by @phatmh</title>
      <link>https://pzhat.id.vn/writeups/thm-evilgpt</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/thm-evilgpt</guid>
      <pubDate>Sat, 22 Nov 2025 17:00:00 GMT</pubDate>
      <description># Tryhackme EvilGPT challenge WriteUp by @phatmh

![image](https://hackmd.io/uploads/SJs0f-gLgl.png)
![image](https://hackmd.io/uploads/BJbzEWeIle.png)
Dùng...</description>
      <category>pentesting</category>
      <category>RedTeam</category>
      <category>Pentest</category>
    </item>

    <item>
      <title>Java Servlet Sql Injection Vulnerability by @Phatmh</title>
      <link>https://pzhat.id.vn/writeups/servlet-sql-injection</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/servlet-sql-injection</guid>
      <pubDate>Fri, 21 Nov 2025 17:00:00 GMT</pubDate>
      <description># Java Servlet Sql Injection Vulnerability by @Phatmh

### Tổng quan cấu trúc file java
  
  
+---.idea
   +---dataSources
+---.mvn
   +---wrapper
+---...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>Java Servlet Command Injection Vulnerability Challenges</title>
      <link>https://pzhat.id.vn/writeups/servlet-cmdi</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/servlet-cmdi</guid>
      <pubDate>Thu, 20 Nov 2025 17:00:00 GMT</pubDate>
      <description># Java Servlet Command Injection Vulnerability Challenges

### Cấu trúc Project

&lt;summary&gt;
Cấu trúc Project
&lt;/summary&gt;

text
+---.idea
+---.mvn
ª   +...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>TryHackme Pickle Rick Challenge WriteUp by Phatmh.</title>
      <link>https://pzhat.id.vn/writeups/pickle-rick-thm</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/pickle-rick-thm</guid>
      <pubDate>Wed, 19 Nov 2025 17:00:00 GMT</pubDate>
      <description># TryHackme Pickle Rick Challenge WriteUp by Phatmh.
![image](https://hackmd.io/uploads/HyFRp7ONel.png)
[link challenge]:https://tryhackme.com/room/picklerick...</description>
      <category>pentesting</category>
      <category>RedTeam</category>
      <category>Pentest</category>
    </item>

    <item>
      <title>Java Servlet FileUpload Vulnerability</title>
      <link>https://pzhat.id.vn/writeups/fileupload-servlet</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/fileupload-servlet</guid>
      <pubDate>Tue, 18 Nov 2025 17:00:00 GMT</pubDate>
      <description># Java Servlet FileUpload Vulnerability by @Phatmh

### Lỗ hổng File Upload

Bản chất của File Upload: File Upload đối với tôi nó đơn giản chỉ là lợi
dụng ...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>Web</category>
    </item>

    <item>
      <title>Cookie Arena Challenges WU (@Phatmh)</title>
      <link>https://pzhat.id.vn/writeups/cookie-arena-cmdi</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/cookie-arena-cmdi</guid>
      <pubDate>Mon, 17 Nov 2025 17:00:00 GMT</pubDate>
      <description># Cookie Arena Web Challenges WriteUp by (@Phatmh)

### NSLookup (Level 1)
Đây là một Website có chức năng là nslookup sử dụng hàm shellexec của php để thực ...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CTF</category>
      <category>Web</category>
    </item>

    <item>
      <title>CanteenFood CTF Challenge WriteUp</title>
      <link>https://pzhat.id.vn/writeups/canteenfood-ctf-challenge-writeup</link>
      <guid isPermaLink="true">https://pzhat.id.vn/writeups/canteenfood-ctf-challenge-writeup</guid>
      <pubDate>Sun, 16 Nov 2025 17:00:00 GMT</pubDate>
      <description># CanteenFood CTF Challenge WriteUp by @Phatmh
## Tiến hành phân tích chức năng theo kiểu BlackBox

![image](https://hackmd.io/uploads/SJOQlrxHxx.png)

Đây...</description>
      <category>pentesting</category>
      <category>Web-Exploitation</category>
      <category>CTF</category>
      <category>Web</category>
    </item>
  </channel>
</rss>