All
Articles 161,071Blog Posts 155,570Tech Tutorials 42,485Research Papers 31,730News 21,029
⚡ AI Lessons

Dev.to · Oopssec Store
🔐 Cybersecurity
⚡ AI Lesson
1mo ago
How a 400 vs 404 gap let me forge a token and read an internal report
A padding oracle in OopsSec Store's share feature leaks whether decryption produced valid PKCS#7...

Dev.to · Oopssec Store
🔧 Backend Engineering
⚡ AI Lesson
2mo ago
Racing a Next.js API route: coupon abuse with Prisma and SQLite
OopsSec Store validates a coupon and increments its counter in two separate database calls. Send...

Dev.to · Oopssec Store
🔐 Cybersecurity
⚡ AI Lesson
2mo ago
The Env Variable Name Was Gone From the Bundle. The Value Wasn't.
Exploiting a misused NEXT_PUBLIC_ environment variable in OopsSec Store to recover a payment secret...

Dev.to · Oopssec Store
🔐 Cybersecurity
⚡ AI Lesson
2mo ago
Recovering a gift card code from its createdAt with a 10-line LCG
OopsSec Store derives gift card codes from a linear congruential generator seeded with the card's...

Dev.to · Oopssec Store
🔧 Backend Engineering
⚡ AI Lesson
3mo ago
Why sameSite: "lax" doesn't save your Next.js admin routes from CSRF
The admin order update endpoint authenticates via cookie and validates nothing else, allowing any...

Dev.to · Oopssec Store
🔧 Backend Engineering
⚡ AI Lesson
3mo ago
The ORM Didn't Save You: SQL Injection in a Prisma Codebase
This writeup walks through a SQL injection in the product search feature of the oss-oopssec-store, an...
DeepCamp AI