PinnedPublished inInfoSec Write-upsHow I Found My First High-Severity Bug and Got Rewarded with 3 Trays of Red Bull!Free link๐Feb 24A response icon19Feb 24A response icon19
๐ API-pocalypse Now: When an Internal Swagger File Opened the Floodgates ๐๐Hey there!๐7h ago7h ago
Published inInfoSec Write-upsShodanโt Have Shown That: How an Exposed Device Led to Source Code ๐ก๐Hey there!๐1d agoA response icon11d agoA response icon1
No Captcha? No Problem! How I Mass-Registered 10K Accounts and Took Over the App ๐ค๐จHey there!๐2d ago2d ago
Published inInfoSec Write-upsToken of My Affection: How Reset Links Let Me Hijack Any Account ๐๐Hey there!๐3d agoA response icon33d agoA response icon3
Published inInfoSec Write-upsHead(er) Games: How I Turned CORS Misconfig into a Full Data Dump ๐๐Free Link ๐4d ago4d ago
Itโs Just a Previewโฆ Until It Isnโt: File Previews That Leaked Everything ๐๐Free Link ๐5d ago5d ago
Published inInfoSec Write-upsBehind the Scenes: How Pre-Prod Leaks Led Me to Prod Secrets ๐ฎ๐Hey there!๐6d ago6d ago
Published inInfoSec Write-upsNot-So-Private Parts: How Public Buckets Spilled Internal Dashboards ๐ชณ๐Hey there!๐Jul 3A response icon2Jul 3A response icon2
Published inInfoSec Write-upsThe Hidden Graph: How API Rate Limits Lied and Let Me Scrape Millions ๐๐ธHey there!๐Jul 2Jul 2