Skip to contentSkip to sidebarSkip to footer
Bergee's Stories on Bug Huntinghacking, cyber security and programming
  • Blog
  • Books
  • About Me
  • Blog
  • Books
  • About Me
bug bounty, prompt injection

Hacking AI chatbot adventure

2026-08-050Comments
Hi there This time, a story of my first AI hacking adventure. Well, it all started when, on some private BB program, I found a domain,…
bug bounty, rce, tutorial, write-up, zip symlink

Two crits, one zip

2025-12-230Comments
Ho,ho, ho Merry Christmas everyone :) Xmas is coming, and I am bringing the write-up on the RCE I found in  Zip upload functionality. I tested the…
Bez kategorii

Why do you need the VPS for bug bounty

2025-11-250Comments
When I started doing bug bounty I've been using my home computer for all. Recon, host scanning, domain bruteforcing, port scanning, subdomains enumeration, screenshoting websites.…
Bez kategorii, bug bounty, csp, write-up

WAF bypass and credential theft with XSS and Google Analytics

2025-10-310Comments
Hello In this post, I will tell you how I was able to escalate the bug from HTML injection to stealing credentials via Google Analytics... well,…
write-up, zip symlink

How two dollars and one zip file let me read the server files

2025-09-120Comments
Hi there There was an app which allowed me to buy domains and offered different types of hosting. First I was testing the free features of…
Bez kategorii, bug bounty, write-up

Subdomain takeover – easy $150 for five minutes of work

2025-08-070Comments
Hello The title might have been clickbait but it is not. I started from recon and discovered as many subdomains as possible of the target.com company.…
vdp, write-up

How I hacked XXXX for fun and !profit

2025-02-090Comments
I am a little bit late but Happy New Year :) In the beginning of the year I decided to hack one company, let's call it…
Bez kategorii, bug bounty, write-up

Accessing admin panel with fuzzing, digging and guessing

2024-10-160Comments
Hello folks This time I want to tell you the story how I gained access to some admin functionalities  and leaked some sensitive info using FUFF,…
Bez kategorii, vdp, write-up

From AngularJS CSTI to credentials theft

2024-07-030Comments
Hello again This time I will tell you about the easy way of credentials theft. I was doing some recon on some sites. I stumbled upon a…
Bez kategorii, bug bounty, csp, ssrf, write-up

The story of exposed service, SSRF, CSP bypass and credentials stealing via XSS

2024-03-200Comments
Hello there Another day, another bug :)  I started looking at the portal at redacted.com. The portal was written with PHP so I started fuzzing it…

Posts pagination

Page 1Page 2Page 3>
  • Hacking AI chatbot adventure
  • Two crits, one zip
  • Why do you need the VPS for bug bounty
  • WAF bypass and credential theft with XSS and Google Analytics
  • How two dollars and one zip file let me read the server files
  • Subdomain takeover – easy $150 for five minutes of work
  • How I hacked XXXX for fun and !profit
  • Accessing admin panel with fuzzing, digging and guessing
  • From AngularJS CSTI to credentials theft
  • The story of exposed service, SSRF, CSP bypass and credentials stealing via XSS
  • “Hacking” the hotel room TV
  • Broken links hijacking and CDN takeover
  • How I found multiple critical bugs in Red Bull
  • Chaining multiple vulnerabilities for credential stealing
  • Blind account takeover
  • Turning cookie based XSS into account takeover
  • Blind os command injection
  • Five-minute hunting for hidden XSS
  • URL filter bypass, RFI and XSS
  • The forgotten API and XSS filter bypass
  • XSS via Angular Template Injection
  • Breaking things legally for fun and profit

Hackers' playground


https://www.tryhackme.com
https://www.pentesterlab.com
https://www.hackthebox.com
https://portswigger.net/web-security/all-labs
Copyright © 2026. All rights reserved.