bug bounty, rce, tutorial, write-up, zip symlinkTwo crits, one zip2025-12-230CommentsHo,ho, ho Merry Christmas everyone :) Xmas is coming, and I am bringing the write-up on the RCE I found in Zip upload functionality. I tested the…
Bez kategorii, bug bounty, csp, write-upWAF bypass and credential theft with XSS and Google Analytics2025-10-310CommentsHello In this post, I will tell you how I was able to escalate the bug from HTML injection to stealing credentials via Google Analytics... well,…
write-up, zip symlinkHow two dollars and one zip file let me read the server files2025-09-120CommentsHi there There was an app which allowed me to buy domains and offered different types of hosting. First I was testing the free features of…
Bez kategorii, bug bounty, write-upSubdomain takeover – easy $150 for five minutes of work2025-08-070CommentsHello The title might have been clickbait but it is not. I started from recon and discovered as many subdomains as possible of the target.com company.…
vdp, write-upHow I hacked XXXX for fun and !profit2025-02-090CommentsI am a little bit late but Happy New Year :) In the beginning of the year I decided to hack one company, let's call it…
Bez kategorii, bug bounty, write-upAccessing admin panel with fuzzing, digging and guessing2024-10-160CommentsHello folks This time I want to tell you the story how I gained access to some admin functionalities and leaked some sensitive info using FUFF,…
Bez kategorii, vdp, write-upFrom AngularJS CSTI to credentials theft2024-07-030CommentsHello again This time I will tell you about the easy way of credentials theft. I was doing some recon on some sites. I stumbled upon a…
Bez kategorii, bug bounty, csp, ssrf, write-upThe story of exposed service, SSRF, CSP bypass and credentials stealing via XSS2024-03-200CommentsHello there Another day, another bug :) I started looking at the portal at redacted.com. The portal was written with PHP so I started fuzzing it…
bug bounty, write-upBroken links hijacking and CDN takeover2023-02-280CommentsHello again This time I want to tell you about the broken links hijacking technique which I decided to give a chance after reading some blog…
Bez kategorii, vdp, write-upHow I found multiple critical bugs in Red Bull2022-12-260CommentsAuth misconfiguration One afternoon I decided to try my luck on the Red Bull VDP program. I gathered the subdomains and looked at interesting ones…