<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Thuri - Author - LaByte</title><link>https://thuri10.github.io/authors/thuri/</link><description>Thuri - Author - LaByte</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>thuri@thuri.dev (Thuri)</managingEditor><webMaster>thuri@thuri.dev (Thuri)</webMaster><lastBuildDate>Wed, 03 Sep 2025 00:59:32 +0300</lastBuildDate><atom:link href="https://thuri10.github.io/authors/thuri/" rel="self" type="application/rss+xml"/><item><title>Insecure Deserialization Basics</title><link>https://thuri10.github.io/posts/deserialization/</link><pubDate>Wed, 03 Sep 2025 00:59:32 +0300</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/deserialization/</guid><description>Insecure deserialization occurs when attacker-controlled data is deserialized by the website, allowing an attacker to manipulate serialized objects in order to pass harmful data.</description></item><item><title>Cross-Site Scripting Basics: Portswigger XSS Labs</title><link>https://thuri10.github.io/posts/xsslabs/</link><pubDate>Thu, 21 Aug 2025 12:59:32 +0300</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/xsslabs/</guid><description>Cross-site scripting (XSS) is a web security vulnerability that allows an attacker to compromise interactions that users have with the vulnerable application.</description></item><item><title>Drozer Security Testing Framework</title><link>https://thuri10.github.io/posts/drozer/</link><pubDate>Sat, 30 Mar 2024 11:37:15 +0300</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/drozer/</guid><description>Drozer is an Android security test framework developed by WithSecure Labs to test security vulnerabilities in Android applications and devices by assuming the role of the target application and interaction with Android Runtime, other applications IPC.</description></item><item><title>GraphQL Vulnerabilities</title><link>https://thuri10.github.io/posts/vulnerable-graphql/</link><pubDate>Thu, 15 Dec 2022 14:27:14 +0000</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/vulnerable-graphql/</guid><description>GraphQL is an open source, data query and manipulation language for APIs. It enables serving API data for both mobile and web applications. GraphQL is an alternative to REST and grPc.</description></item><item><title>Information Disclosure</title><link>https://thuri10.github.io/posts/informationdisclosure/</link><pubDate>Mon, 31 Oct 2022 14:27:14 +0000</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/informationdisclosure/</guid><description>Information disclosure is a web vulnerability that allows leakage of sensitive information to it&amp;rsquo;s users. Information leaked may include other user&amp;rsquo;s sensitive information, passwords and username, Intellectual property, source code, etc depending on the context of the application.</description></item><item><title>Path Traversal Vulnerabilities</title><link>https://thuri10.github.io/posts/directory-traversal/</link><pubDate>Mon, 24 Oct 2022 14:27:14 +0000</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/directory-traversal/</guid><description>Directory traversal is a web vulnerability that allows an attacker to access unauthorized resources outside the root server directory due to the way server handles files.</description></item><item><title>Reversing Basic c++ Templates</title><link>https://thuri10.github.io/posts/reverse-c-templates/</link><pubDate>Sat, 16 Jul 2022 14:27:14 +0000</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/reverse-c-templates/</guid><description>Template is a c++ entity that accepts different data types but performs the same functionality.</description></item><item><title>Redliner - Information Stealer Analysis</title><link>https://thuri10.github.io/posts/redlinestealer-stealer/</link><pubDate>Mon, 07 Feb 2022 14:27:14 +0000</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/redlinestealer-stealer/</guid><description>Redline malware is an Information Stealer written in c#, targeting windows victims. It is used for gathering victims information ranging from the Browser cookies, saved credentials, Discord tokens, OS information,Languages, VPN profiles, Installed Programs and Network configurations.</description></item><item><title>RemcosRat Malware Analysis</title><link>https://thuri10.github.io/posts/remcosrat-macros/</link><pubDate>Tue, 25 Jan 2022 14:27:14 +0000</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/remcosrat-macros/</guid><description>RemcosRAT is a Fileless multi-stage malware that is distributed through malicious macros in Excel files. The malware enables remote administration of infected systems to perform unintended actions</description></item><item><title>RopEmporium - callme</title><link>https://thuri10.github.io/posts/rop-callme/</link><pubDate>Mon, 20 Dec 2021 14:27:14 +0000</pubDate><author><name>Thuri</name><uri>https://thuri10.github.io/authors/thuri/</uri></author><guid>https://thuri10.github.io/posts/rop-callme/</guid><description>RopEmporium - callme goal is understanding how more than one argument is passed in x64 function.</description></item></channel></rss>