Security Notes
⌘Ctrlk
Security Notes
  • Whoami
  • Notes
  • Portswigger Labs
    • A10 Mishandling of Exceptional Conditions
    • A09 Security Logging and Alerting Failures
    • A08 Software or Data Integrity Failures
    • A07 Authentication Failures
    • A06 Insecure Design
    • A05 Injection
    • A04 Cryptographic Failures
      • Weak Algorithms and Inadequate Hashing
      • PRNG Failures and Predictable Secrets
      • Cryptographic Failure
      • Weak Encoding for Password
      • Improper Following of a Certificate's Chain of Trust
      • Clear Text Transmission Of Sensitive Data
      • Cryptographic Key Management and Implementation
    • A03 Software Supply Chain Failures
    • A02 Security Misconfiguration
    • A01 Broken Access Control
  • Uploading an Image Was All I Needed for Full Server Access
  • How I Discovered a Dependency Confusion Vulnerability in a Ruby Application Leading to RCE
  • Privilege Escalation via Impersonation Features feature
  • How I Escalated Simple HTML Injection to SSRF via PDF Rendering
  • How I was able to discover ATO Via IDOR vulnerability
  • how I Bypassed SAML Authentication, and had access to Admin Panel.
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. owsap-top-10:2025

A04 Cryptographic Failures

Weak Algorithms and Inadequate HashingPRNG Failures and Predictable SecretsCryptographic FailureWeak Encoding for PasswordImproper Following of a Certificate's Chain of TrustClear Text Transmission Of Sensitive DataCryptographic Key Management and Implementation
PreviousCommand InjectionNextWeak Algorithms and Inadequate Hashing

Last updated 6 months ago