Top 10 Web Hacking Techniques of 2017
https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017
  
  https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017
PortSwigger Research
  
  Top 10 Web Hacking Techniques of 2017
  The verdict is in! Following 37 nominations whittled down to a shortlist of 15 by a community vote, our panel of experts has conferred and selected the top 10 web hacking techniques of 2017 (and 2016)
  Extending Burp to Find Struts and XXE Vulnerabilities
https://www.irongeek.com/i.php?page=videos/derbycon8/stable-21-extending-burp-to-find-struts-and-xxe-vulnerabilities-chris-elgee
  
  https://www.irongeek.com/i.php?page=videos/derbycon8/stable-21-extending-burp-to-find-struts-and-xxe-vulnerabilities-chris-elgee
Irongeek
  
  Extending Burp to Find Struts and XXE Vulnerabilities - Chris Elgee Derbycon 2018 (Hacking Illustrated Series InfoSec Tutorial…
  Irongeek's Information Security site with tutorials, articles and other information.
  Windows oneliners to download remote payload and execute arbitrary code
https://arno0x0x.wordpress.com/2017/11/20/windows-oneliners-to-download-remote-payload-and-execute-arbitrary-code/
  
  https://arno0x0x.wordpress.com/2017/11/20/windows-oneliners-to-download-remote-payload-and-execute-arbitrary-code/
arno0x0x
  
  Windows oneliners to download remote payload and execute arbitrary code
  In the wake of the recent buzz and trend in using DDE for executing arbitrary command lines and eventually compromising a system, I asked myself « what are the coolest command lines an a…
  Packet capture on Windows without drivers
https://www.nospaceships.com/2018/09/19/packet-capture-on-windows-without-drivers.html
  
  https://www.nospaceships.com/2018/09/19/packet-capture-on-windows-without-drivers.html
NoSpaceships Ltd
  
  Packet capture on Windows without drivers
  Introduction
  exploitation notes for CVE-2018-17456 (.gitmodules RCE)
CVE-2018-17456
https://gist.github.com/joernchen/38dd6400199a542bc9660ea563dcf2b6
  
  CVE-2018-17456
https://gist.github.com/joernchen/38dd6400199a542bc9660ea563dcf2b6
Gist
  
  CVE-2018-17456
  CVE-2018-17456. GitHub Gist: instantly share code, notes, and snippets.
  Abusing the COM Registry Structure: CLSID, LocalServer32, & InprocServer32
https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/
  https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/
Abusing the COM Registry Structure (Part 2): Hijacking & Loading Techniques
https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/
  https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/