Tutorials

Step-by-step guides and educational content for learning

4
Posts

Scanning the Access Matrix with Burp Intruder: A Repeatable Setup

Scanning the authorization matrix with two sessions and an ID list: recording a baseline, bulk requests with the attacker cookie, triage by length, single-request confirmation.

Scanning the authorization matrix with two sessions and an ID list: recording a baseline, bulk requests with the attacker cookie, triage by length, single-request confirmation.

16 min read
3,047 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Noindex Is Not Auth: Protecting Private Pages in Next.js

How to separate link-only pages from truly private content in Next.js App Router using robots metadata, middleware, server actions, and HttpOnly cookies.

How to separate link-only pages from truly private content in Next.js App Router using robots metadata, middleware, server actions, and HttpOnly cookies.

8 min read
1,589 words
İS

ibrahimsql

Cybersecurity Engineer

Read More