First blog post: How I could have pwned my highschool (SQLi, CSRF, ...