Anonymous View

DEV Community

Oopssec Store profile picture

Oopssec Store

Security training for the apps you actually ship. Open your browser and start hacking.

The Env Variable Name Was Gone From the Bundle. The Value Wasn't.

The Env Variable Name Was Gone From the Bundle. The Value Wasn't.

Comments
5 min read

Want to connect with Oopssec Store?

Create an account to connect with Oopssec Store. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
path.join() Is Not Path Validation: A Next.js Traversal Walkthrough

path.join() Is Not Path Validation: A Next.js Traversal Walkthrough

Comments
4 min read
Recovering a gift card code from its createdAt with a 10-line LCG

Recovering a gift card code from its createdAt with a 10-line LCG

Comments
8 min read
Why sameSite: "lax" doesn't save your Next.js admin routes from CSRF

Why sameSite: "lax" doesn't save your Next.js admin routes from CSRF

Comments
5 min read
How a fake npm package made Cursor backdoor a Next.js admin route

How a fake npm package made Cursor backdoor a Next.js admin route

Comments
8 min read
Client-Side Price Manipulation: Pay Whatever You Want at Checkout

Client-Side Price Manipulation: Pay Whatever You Want at Checkout

Comments
4 min read
Prompt Injection: 5 Ways to Bypass a Regex Blocklist on an LLM

Prompt Injection: 5 Ways to Bypass a Regex Blocklist on an LLM

Comments
5 min read
The ORM Didn't Save You: SQL Injection in a Prisma Codebase

The ORM Didn't Save You: SQL Injection in a Prisma Codebase

Comments
4 min read
loading...