Bez kategorii, bug bounty, csp, write-upWAF bypass and credential theft with XSS and Google Analytics2025-10-310CommentsHello In this post, I will tell you how I was able to escalate the bug from HTML injection to stealing credentials via Google Analytics... well,…
Bez kategorii, bug bounty, csp, ssrf, write-upThe story of exposed service, SSRF, CSP bypass and credentials stealing via XSS2024-03-200CommentsHello there Another day, another bug :) I started looking at the portal at redacted.com. The portal was written with PHP so I started fuzzing it…