<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
    <channel>
      <title>Haiyahhh Hack Vault</title>
      <link>https://haiyahhh-hack-vault.pages.dev</link>
      <description>Last 10 notes on Haiyahhh Hack Vault</description>
      <generator>Quartz -- quartz.jzhao.xyz</generator>
      <item>
    <title>HTB Project Nightfall - Korvia Vault</title>
    <link>https://haiyahhh-hack-vault.pages.dev/05---Content/HTB-Project-Nightfall---Korvia-Vault</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/05---Content/HTB-Project-Nightfall---Korvia-Vault</guid>
    <description><![CDATA[ 🚩 HTB Project Nightfall - Korvia Vault Tóm tắt Hệ điều hành: Linux Tóm tắt kỹ thuật: Trang web có lỗ hổng trong quá trình xử lí session của người dùng, cho sử dụng session_id để trỏ đến file session trong server mà không làm sạch hoặc kiểm tra dữ liệu cookie, cho tạo điều kiện để kẻ tấn công sử dụn... ]]></description>
    <pubDate>Sat, 30 May 2026 07:27:52 GMT</pubDate>
  </item><item>
    <title>SQLi Context - INSERT and UPDATE</title>
    <link>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi-Context---INSERT-and-UPDATE</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi-Context---INSERT-and-UPDATE</guid>
    <description><![CDATA[ 🧠 SQLi Context - INSERT and UPDATE Vulnerable Code Example &amp; Theory Vulnerable Code INSERT and UPDATE statements are typically found in features that modify database state (e.g., registration, profile edits, password changes). ]]></description>
    <pubDate>Fri, 22 May 2026 20:42:42 GMT</pubDate>
  </item><item>
    <title>SQLi - UNION-based</title>
    <link>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi---UNION-based</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi---UNION-based</guid>
    <description><![CDATA[ 🧠 SQLi - UNION-based Theory What is it? Concept: Basically using the UNION instruction in order to exfiltrate arbitrary data. ]]></description>
    <pubDate>Fri, 22 May 2026 20:36:43 GMT</pubDate>
  </item><item>
    <title>SQLi Context - WHERE and HAVING</title>
    <link>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi-Context---WHERE-and-HAVING</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi-Context---WHERE-and-HAVING</guid>
    <description><![CDATA[ 🧠 SQLi Context - WHERE and HAVING Vulnerable Code Example &amp; Theory Vulnerable Code Developers often fail to parameterize input used for data filtering. ]]></description>
    <pubDate>Fri, 22 May 2026 20:28:13 GMT</pubDate>
  </item><item>
    <title>SQLi Context - ORDER BY</title>
    <link>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi-Context---ORDER-BY</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi-Context---ORDER-BY</guid>
    <description><![CDATA[ 🧠 SQLi Context - ORDER BY Vulnerable Code Example &amp; Theory Vulnerable Code Because Prepared Statements (?) cannot parameterize column names, developers often fall back to dangerous string concatenation when implementing sorting features. ]]></description>
    <pubDate>Fri, 22 May 2026 20:27:56 GMT</pubDate>
  </item><item>
    <title>SQLi Context - LIKE (wildcards)</title>
    <link>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi-Context---LIKE-(wildcards)</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi-Context---LIKE-(wildcards)</guid>
    <description><![CDATA[ 🧠 SQLi Context - LIKE (wildcards) Vulnerable Code Example &amp; Theory Vulnerable Code LIKE clauses are heavily used in search features. ]]></description>
    <pubDate>Fri, 22 May 2026 20:27:35 GMT</pubDate>
  </item><item>
    <title>SQLi - Time-based Blind</title>
    <link>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi---Time-based-Blind</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/05---Content/SQLi---Time-based-Blind</guid>
    <description><![CDATA[ 🧠 SQLi - Time-based Blind Theory What is it? Concept: A technique used when an application is completely blind. ]]></description>
    <pubDate>Fri, 22 May 2026 20:26:59 GMT</pubDate>
  </item><item>
    <title>index</title>
    <link>https://haiyahhh-hack-vault.pages.dev/</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/</guid>
    <description><![CDATA[ Personal CyberSec Vault This is where I store my notes when doing the CTF challengers as well as whenever I research new topic on the Internet. ]]></description>
    <pubDate>Fri, 22 May 2026 20:13:18 GMT</pubDate>
  </item><item>
    <title>README</title>
    <link>https://haiyahhh-hack-vault.pages.dev/README</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/README</guid>
    <description><![CDATA[ Personal CyberSec Vault This is where I store my notes when doing the CTF challengers as well as whenever I research new topic on the Internet. ]]></description>
    <pubDate>Fri, 22 May 2026 20:13:18 GMT</pubDate>
  </item><item>
    <title>UMassCTF - Turncoat&#039;s Treasure</title>
    <link>https://haiyahhh-hack-vault.pages.dev/05---Content/UMassCTF---Turncoat's-Treasure</link>
    <guid>https://haiyahhh-hack-vault.pages.dev/05---Content/UMassCTF---Turncoat's-Treasure</guid>
    <description><![CDATA[ 🚩 UMassCTF - Turncoat’s Treasure Executive Summary OS: Linux Key Technique: The challenge does contain a XSS vulnerability inside the forum’s /user/:username endpoint where it blindly display unfiltered user input post content without our implementing any kind of CSP. ]]></description>
    <pubDate>Fri, 22 May 2026 20:13:18 GMT</pubDate>
  </item>
    </channel>
  </rss>