TLS Handshake Notes for Defenders

Lab openssl s_client -msg against a loopback nginx: handshake record dump, redacted CN, alert on a bad name — not a MITM cookbook.

September 18, 2026 · 6 min · 1198 words · Jose Adalberto Gutierrez Ochoa

Financial Apps: Concurrency Bugs vs Authorization Flaws

Lab SQLite ledger: UPDATE without a version column vs WITH version, plus an IDOR that is not a race — no money-drain client.

April 11, 2026 · 6 min · 1207 words · Jose Adalberto Gutierrez Ochoa

Tabnabbing, target=_blank, and Related XSS Edges

Lab HTML: target=_blank without rel, opener check in the opened tab, rel=noopener fix, harmless location rewrite — no phishing kit.

September 12, 2025 · 6 min · 1169 words · Jose Adalberto Gutierrez Ochoa

YAML Parser Footguns Across Languages

Lab PyYAML: yaml.safe_load vs yaml.load, implicit typing, billion-laughs-sized crash — no os.system gadget via YAML tags.

November 30, 2024 · 6 min · 1145 words · Jose Adalberto Gutierrez Ochoa

Web Race Conditions: Coupons, Balances, and Workflows

Lab Go counter without a mutex, then with one; HTTP coupon handler; lost-update logs — no inventory-drain exploit script.

May 19, 2023 · 6 min · 1231 words · Jose Adalberto Gutierrez Ochoa

Apache HTTP Path Confusion Notes (CVE-2021-41773 Class)

Lab Apache Alias map: raw vs normalized paths as text, Require/Alias mismatch, 403/404 artifacts — no working traversal into /etc.

June 11, 2022 · 6 min · 1202 words · Jose Adalberto Gutierrez Ochoa

Lessons from the JNDI / Log4Shell Class of Bugs

Lab Java snippet that logs a lookup string, how to disable JNDI/message lookups, sanitized crash on a bad URL — no LDAP exploit server.

January 28, 2022 · 6 min · 1240 words · Jose Adalberto Gutierrez Ochoa

DOM XSS and DOM Clobbering as Trust Problems

Lab HTML+JS page: location.hash into innerHTML, name=form clobber of a config object, harmless redacted payload, CSP as the fix.

April 14, 2021 · 6 min · 1203 words · Jose Adalberto Gutierrez Ochoa