Open in app

Sign In

Write

Sign In

Jonathan Bouman
Jonathan Bouman

1.7K Followers

Home

Dec 14, 2022

Unprotected API endpoint at HAwebsso.nl leads to data leak of +15k medical doctor usernames & password hashes

Background As some might know, I work as a medical doctor (general practitioner) by day and as a security researcher by night. One of my goals in ethical hacking is to learn as much as possible in order to be able to audit myself healthcare products, apps, websites or infrastructure. Is…

Hacking

11 min read

Unprotected API endpoint at HAwebsso.nl
Unprotected API endpoint at HAwebsso.nl
Hacking

11 min read


Aug 6, 2020

Blind SQL Injection at fasteditor.hema.com

Background These days almost every website uses a database. A server application will formulate a query that is send to the database whenever a visitor requests data from the site. The programming language used in those queries is often SQL. …

Sql Injection

10 min read

Blind SQL Injection at fasteditor.hema.com
Blind SQL Injection at fasteditor.hema.com
Sql Injection

10 min read


Aug 6, 2020

Reflected XSS at fotoservice.hema.nl

Background Reflected XSS bugs are great fun to find; they are everywhere and the impact can be big if the injected payload is carefully crafted. Today we will try to find a Reflected XSS bug and craft a custom payload for it. …

Bug Bounty

11 min read

Reflected XSS at fotoservice.hema.nl
Reflected XSS at fotoservice.hema.nl
Bug Bounty

11 min read


May 12, 2020

Stored XSS in Paytium 3.0.13 WordPress Plugin

Background With a 60% market share WordPress is the most used CMS at this moment. Out of the box WordPress is just a blog. But by installing some plugins you’re able to convert it into a webshop, a crowd funding platform or even a mind reader. Everyone can create and…

Security

6 min read

Stored XSS in Paytium 3.0.13 WordPress Plugin
Stored XSS in Paytium 3.0.13 WordPress Plugin
Security

6 min read


Apr 6, 2019

Email content spoofing at IKEA.com

Background Previously we discussed XSS, open redirect bugs and unrestricted file uploads. Today we will focus on email content spoofing. Phishing someone is way more easy if we are able to send emails from the servers of a well known brand. The email looks legitimate, is digitally signed by the…

Security

4 min read

Email content spoofing at IKEA.com
Email content spoofing at IKEA.com
Security

4 min read


Apr 4, 2019

Leaked Salesforce API access token at IKEA.com

Background Previously we discussed a Local File Inclusion bug at IKEA.com, the bug was quite complicated and showed us that you have to think out of the box in order to exploit it. This time we will learn how a relative simple and easy to spot bug can have a…

IKEA

6 min read

Leaked Salesforce API access token at IKEA.com
Leaked Salesforce API access token at IKEA.com
IKEA

6 min read


Oct 7, 2018

Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com

Are you aware of any (private) bug bounty programs? I would love to get an invite. Please get in touch with me: Jonathan@Protozoan.nl Background In my previous report we learned more about a special type of the persistent XSS attack; the unvalidated oEmbed attack. …

Linked In

8 min read

Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
Linked In

8 min read


Oct 4, 2018

Persistent XSS (Unvalidated oEmbed) at Medium.com

Are you aware of any (private) bug bounty programs? I would love to get an invite. Please get in touch with me: Jonathan@Protozoan.nl Background In one of our previous reports we learned more about reflected XSS; the downside of this attack is that we need to trick an user in visiting…

Security

9 min read

Persistent XSS (Unvalidated oEmbed) at Medium.com
Persistent XSS (Unvalidated oEmbed) at Medium.com
Security

9 min read


Sep 19, 2018

Local file inclusion at IKEA.com

Are you aware of any (private) bug bounty programs? I would love to get an invite. Please get in touch with me: Jonathan@Protozoan.nl Background With a local file inclusion (LFI) attack you trick the server into sharing its private files. Think of the configuration, log and source code files of the…

Security

11 min read

Local file inclusion at IKEA.com
Local file inclusion at IKEA.com
Security

11 min read


Sep 17, 2018

Reflected XSS at Philips.com

Are you aware of any (private) bug bounty programs? I would love to get an invite. Please get in touch with me: Jonathan@Protozoan.nl Background As we learned from previous reports, XSS attacks can have a high impact; you are able to steal cookies, attack the browser of a visitor or use…

Bug Bounty

8 min read

Reflected XSS at Philips.com
Reflected XSS at Philips.com
Bug Bounty

8 min read

Jonathan Bouman

Jonathan Bouman

1.7K Followers

Medical doctor / Web developer / Security researcher - https://Protozoan.nl

Following
  • Valeriy Shevchenko

    Valeriy Shevchenko

  • Jang

    Jang

  • Raushan Raj

    Raushan Raj

  • Paul-Olivier Dehaye

    Paul-Olivier Dehaye

  • emmabruns

    emmabruns

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech