Week 1

Intro :children_crossing:
(no 6843 lecture)

Break 1: *.nsnagency (Solution)

Week 2

Recon :eyes:
Intro (6843)

Week 3

Authentication :customs:
Advanced Recon :mag:

Break 2: (Solution)

    dev.ns.agency 
    team.ns.agency
    admin.ns.agency

Ext Break 1: (Solution)

    oauth-really-secret.jp.ns.agency
    very-secret.jp.ns.agency

Week 4

Session Management :cookie:
OAuth and SAML :poop:

Week 5

Access Control :u7981:
XXE + PHP Unserialize :dart:

Break 3: (Solution)

    yipple.ns.agency
    yipple-dev.ns.agency
    pre-flighting.ns.agency
    yipple-qa.ns.agency

Ext Break 2: (Solution)

    sharp-edges.ru.ns.agency
    saml-super-secret.eu.ns.agency
    hush-hush-con.eu.ns.agency
    cereal.dev.ns.agency
    8xxxxxxxxml.redline.jp.ns.agency

Week 6

XSS :fishing_pole_and_fish:
XSS, CSP, SOP

Week 7

Revision – no slides wtf
(Shubs and Naffy guest talk)

Week 8

SQLi :syringe:
Injections And Spooks

Break 4: (Solution)

    gov.ns.agency 
    yuan.ns.agency
    ru.ns.agency 

Ext Break 3: (Solution)

    internship.dev.ns.agency
    cspdomain1.dev.ns.agency
    cspxss1.dev.ns.agency
    cspdomain2.dev.ns.agency

Week 9

ServerSideMagic :crystal_ball:
SSRF :satellite:

Week 10

WebServices + REST APIs
Cloud :cloud:

Break 5: (Solution)

    smartcontracts.dev1-x.ns.agency
    math.group.ns.agency
    vault5.gov.ns.agency

Ext Break 4: (Solution)

    moonshot.oneshot.ns.agency
    ssrfsquared.ns.agency

Week 11

Environment :globe_with_meridians:
Vuln Research (not examinable?)

Week 12

Revision
(no 6843 lecture)

Dont expect these links to resolve outside of session.

7xxxxxxxml.redline.eu.ns.agency xxe
logfile.lecture.ns.agency logfile injection
chain.demo.ns.agency CSRF
ssrf1.lecture.ns.agency SSRF
ssrfphp.lecture.ns.agency SSRF
xml.lecture.ns.agency xxe into ssrf
xxe-xss.demo.ns.agency/testxml xxee to xss
ssti.lecture.ns.agency Template Injection / __mro__


Other

Sean’s 2017 Exam Writeup (broken)

stuff that WAFs don’t expect

Holy Grail of XSS payloads

Cloud Metadata cheatsheet stuff

DIY RequestBin

SQLi cheatsheet

RCE no spaces (broken)

Sean’s XXE example

XXE Payloads