0xSilentGhost
Muhammad Husnain Zargar AKA 0xSilentGhost

Currently working as a Jr. Penetration Tester specialising in web application and API security. Actively working on real-world assessments, CTF challenges, and security research. Find me on X or Linkedin.

eJPTv2 PT1

“I write so others can skip the parts I had to figure out the hard way.”

Recent Posts

Sep 20, 2026 BLOG by 0xSilentGhost

Bypassing SameSite Cookie Restrictions Using On-Site Gadgets – A Practical CSRF Bypass

SameSite=Strict Cookies are supposed to be a strong shield against CSRF (Cross-Site Request Forgery). When a cookie has this attribute, the browser refuses to send it on cross-site requests. In...

Sep 19, 2026 BLOG by 0xSilentGhost

Bypassing CSRF Protection by Injecting a Forged Token via Cookie Injection

Most CSRF protections tie a token to the user's session. If the token and the session don't match, the request gets rejected. Simple, effective - usually. But what if the...

Jun 23, 2026 BLOG by 0xSilentGhost

I Turned a Client Admin Into a Superadmin With One Parameter Change

Hey everyone! I'm Husnain, a Jr. Penetration Tester, and during one of my recent engagements I came across a Vertical Privilege Escalation bug that honestly surprised me with how simple...

May 31, 2026 BLOG by 0xSilentGhost

How I Turned a Low-Risk XSS into a Tenant-Wide Lockout

Hey everyone! I'm Husnain, a Jr. Penetration Tester, and I love sharing my experiences from real-world pentests. Today, I want to talk about something cool that happened in one of...

May 27, 2026 CTF by 0xSilentGhost

Reactor HTB – Machine Walkthrough

Hi everyone, in this Reactor HTB Machine, I will give u a detailed walkthrough to get the user and root flag in this machine, so sit back and read! 🔒...

May 25, 2026 CTF by 0xSilentGhost

Content Discovery – TryHackMe Walkthrough

Content discovery is about finding things on a web server that aren't meant to be publicly visible - hidden directories, sensitive files, old endpoints, subdomains, and misconfigured paths. This TryHackMe...

May 24, 2026 BLOG by 0xSilentGhost

How I’d Learn Ethical Hacking in 2026 If I Started Over

Let me be straight with you. Most "ethical hacking roadmaps" online are either too vague, outdated, or written by someone who hasn't actually done the work. I've been there, I...

Apr 10, 2026 CTF by 0xSilentGhost

KoBold HTB – Machine Walkthrough

Hi everyone, in this Kobold HTB Machine, I will give u a detailed walkthrough to get the user and root flag in this machine, so sit back and read! Reconnaissance...

Apr 1, 2026 BLOG by 0xSilentGhost

Why Most Cybersecurity Certifications Are a Waste of Time (And Which Ones Aren’t)

Let me be real with you. I have seen a lot of people in this field: beginners, students, even some experienced folks, chasing certifications like they are some kind of...

Mar 22, 2026 BLOG by 0xSilentGhost

Will AI Replace Pentesters? A Pentester’s Honest Take

Hi guys! and future hackers! Will AI replace pentesters? As a Jr. Penetration Tester, I want to give you my honest take so you can better understand where things actually...