<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>/posts/SHA-1-Implementation-in-C-programming-language/</loc>
<lastmod>2025-04-29T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/DNS-Explained/</loc>
<lastmod>2025-05-18T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Source-Writeup-TryHackMe/</loc>
<lastmod>2025-10-12T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/FlagCommand-writeup-HackTheBox/</loc>
<lastmod>2025-11-13T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Spookifier-writeup-HackTheBox/</loc>
<lastmod>2025-11-13T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Monster-Cookie-Secret-Recipe-Writeup-PicoCTF/</loc>
<lastmod>2025-11-14T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/XSS-From-Browser-Parsing-to-Exploitation/</loc>
<lastmod>2025-12-01T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Reflected-XSS-into-HTML-context-with-nothing-encoded/</loc>
<lastmod>2026-01-17T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/DOM-XSS-in-document.write-sink-using-source-location.search/</loc>
<lastmod>2026-01-18T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/DOM-XSS-in-innerHTML-sink-using-source-location.search/</loc>
<lastmod>2026-01-18T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/DOM-XSS-in-jQuery-anchor-href-attribute-sink-using-location.search-source/</loc>
<lastmod>2026-01-18T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Stored-XSS-into-HTML-context-with-nothing-encoded/</loc>
<lastmod>2026-01-18T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/DOM-XSS-in-AngularJS-expression-with-angle-brackets-and-double-quotes-HTML-encoded/</loc>
<lastmod>2026-01-19T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/DOM-XSS-in-document.write-sink-using-source-location.search-inside-a-select-element/</loc>
<lastmod>2026-01-19T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/DOM-XSS-in-jQuery-selector-sink-using-a-hashchange-event/</loc>
<lastmod>2026-01-19T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Reflected-DOM-XSS/</loc>
<lastmod>2026-01-19T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Reflected-XSS-into-a-JavaScript-string-with-angle-brackets-HTML-encoded/</loc>
<lastmod>2026-01-19T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Reflected-XSS-into-attribute-with-angle-brackets-HTML-encoded/</loc>
<lastmod>2026-01-19T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Stored-XSS-into-anchor-href-attribute-with-double-quotes-HTML-encoded/</loc>
<lastmod>2026-01-19T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Reflected-XSS-into-HTML-context-with-most-tags-and-attributes-blocked/</loc>
<lastmod>2026-01-20T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Stored-DOM-XSS/</loc>
<lastmod>2026-01-20T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Lab-Reflected-XSS-into-HTML-context-with-all-tags-blocked-except-custom-ones/</loc>
<lastmod>2026-01-22T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Lab-Reflected-XSS-with-some-SVG-markup-allowed/</loc>
<lastmod>2026-02-04T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Writeup-of-head-dump-PicoCTF-challegne/</loc>
<lastmod>2026-02-05T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Product-Writeup-MOJOJO-CTF/</loc>
<lastmod>2026-02-09T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Zzz-Challenge-Writeup-mojoJOJO-CTF/</loc>
<lastmod>2026-02-09T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Exploiting-XSS-To-Steal-cookies/</loc>
<lastmod>2026-03-20T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/posts/Startup-Room-THM-Using-PTES/</loc>
<lastmod>2026-03-30T00:00:00+08:00</lastmod>
</url>
<url>
<loc>/categories/</loc>
<lastmod>2026-03-31T15:47:19+08:00</lastmod>
</url>
<url>
<loc>/tags/</loc>
<lastmod>2026-03-31T15:47:19+08:00</lastmod>
</url>
<url>
<loc>/archives/</loc>
<lastmod>2026-03-31T15:47:19+08:00</lastmod>
</url>
<url>
<loc>/about/</loc>
<lastmod>2026-03-31T15:47:19+08:00</lastmod>
</url>
<url>
<loc>/certifications/</loc>
<lastmod>2026-03-31T15:47:19+08:00</lastmod>
</url>
<url>
<loc>/</loc>
</url>
<url>
<loc>/tags/cryptography/</loc>
</url>
<url>
<loc>/tags/networking/</loc>
</url>
<url>
<loc>/tags/dns/</loc>
</url>
<url>
<loc>/tags/dns-zone-transfer/</loc>
</url>
<url>
<loc>/tags/nmap/</loc>
</url>
<url>
<loc>/tags/msf/</loc>
</url>
<url>
<loc>/tags/cve-2019-15107/</loc>
</url>
<url>
<loc>/tags/webexploitation/</loc>
</url>
<url>
<loc>/tags/hackthebox/</loc>
</url>
<url>
<loc>/tags/ctfs/</loc>
</url>
<url>
<loc>/tags/ssti/</loc>
</url>
<url>
<loc>/tags/picoctf/</loc>
</url>
<url>
<loc>/tags/head/</loc>
</url>
<url>
<loc>/tags/xss/</loc>
</url>
<url>
<loc>/tags/cross-site-scripting/</loc>
</url>
<url>
<loc>/tags/labs/</loc>
</url>
<url>
<loc>/tags/sqli/</loc>
</url>
<url>
<loc>/tags/race-conditions/</loc>
</url>
<url>
<loc>/tags/portswigger/</loc>
</url>
<url>
<loc>/tags/storedxss/</loc>
</url>
<url>
<loc>/tags/cookiestealing/</loc>
</url>
<url>
<loc>/tags/csrf/</loc>
</url>
<url>
<loc>/tags/thm/</loc>
</url>
<url>
<loc>/tags/boot2root/</loc>
</url>
<url>
<loc>/tags/ftp/</loc>
</url>
<url>
<loc>/tags/anonymouslogin/</loc>
</url>
<url>
<loc>/tags/reverseshell/</loc>
</url>
<url>
<loc>/tags/pcap/</loc>
</url>
<url>
<loc>/tags/privilegeescalation/</loc>
</url>
<url>
<loc>/tags/pwnkit/</loc>
</url>
<url>
<loc>/tags/cve-2021-4034/</loc>
</url>
<url>
<loc>/tags/linux/</loc>
</url>
<url>
<loc>/categories/cryptography/</loc>
</url>
<url>
<loc>/categories/hash-functions/</loc>
</url>
<url>
<loc>/categories/c-programming/</loc>
</url>
<url>
<loc>/categories/networking/</loc>
</url>
<url>
<loc>/categories/dns/</loc>
</url>
<url>
<loc>/categories/information-gathering/</loc>
</url>
<url>
<loc>/categories/writeups/</loc>
</url>
<url>
<loc>/categories/msf/</loc>
</url>
<url>
<loc>/categories/webmin/</loc>
</url>
<url>
<loc>/categories/cves/</loc>
</url>
<url>
<loc>/categories/pentesting/</loc>
</url>
<url>
<loc>/categories/webexploitation/</loc>
</url>
<url>
<loc>/categories/vulnerabilities/</loc>
</url>
<url>
<loc>/categories/mojojojo/</loc>
</url>
<url>
<loc>/categories/cybersecurity/</loc>
</url>
<url>
<loc>/categories/penetration-testing/</loc>
</url>
<url>
<loc>/page2/</loc>
</url>
<url>
<loc>/page3/</loc>
</url>
<url>
<loc>/assets/KoussayDhifi_Resume.pdf</loc>
<lastmod>2026-03-31T15:46:53+08:00</lastmod>
</url>
<url>
<loc>/assets/certs/IUDC7.pdf</loc>
<lastmod>2026-03-31T15:46:53+08:00</lastmod>
</url>
<url>
<loc>/assets/reports/SpiceHut_Report.pdf</loc>
<lastmod>2026-03-31T15:46:53+08:00</lastmod>
</url>
<url>
<loc>/assets/reports/Xss_csrf_portlab.pdf</loc>
<lastmod>2026-03-31T15:46:53+08:00</lastmod>
</url>
</urlset>
