Menu

Skip to content
  • BLOG
  • RESUME
  • TWITTER

Go Go XSS Gadgets: Chaining a DOM Clobbering Exploit in the Wild

February 23, 2024February 28, 2024

Reversing and Tooling a Signed Request Hash in Obfuscated JavaScript

January 16, 2024February 25, 2024

Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More

January 3, 2023June 30, 2025

BT’s Metaversal Album Treasure Hunt Solution

October 12, 2021February 25, 2024

Cr0wnGhoul 1ETH Puzzle: You’ve Got Mail Write-up

May 13, 2021February 25, 2024

coin_artist 50k Follower Puzzle – Write-up

May 5, 2021February 25, 2024

DEFCON 29 CTF Qualifier: 3FACTOOORX Write-up

May 3, 2021February 25, 2024

We Hacked Apple for 3 Months: Here’s What We Found

October 7, 2020June 30, 2025

coin_artist – 34700 $coin Puzzle Write-Up ($20,000)

September 11, 2020February 25, 2024

h@cktivitycon – Pizza Time (Web 750)

July 31, 2020February 25, 2024

NahamCon – Trash the Cache Write-up (Web 1000)

June 14, 2020February 25, 2024

JosieBellini’s Yours Truly Puzzle Walkthrough

March 3, 2020February 25, 2024

A Tale of Exploitation in Spreadsheet File Conversions

October 18, 2019February 25, 2024

H1-5411 CTF Write-up by erbbysam and ziot

October 8, 2018February 25, 2024

Montecrypto – ARGSS Write-Up

April 24, 2018February 25, 2024

Escalating XSS in PhantomJS Image Rendering to SSRF/Local-File Read

June 29, 2017February 25, 2024

Airbnb – Web to App Phone Notification IDOR to view Everyone’s Airbnb Messages

March 31, 2017February 25, 2024

Airbnb – Ruby on Rails String Interpolation led to Remote Code Execution

March 13, 2017February 25, 2024

Airbnb – Chaining Third-Party Open Redirect into Server-Side Request Forgery (SSRF) via LivePerson Chat

March 9, 2017February 25, 2024

Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities

March 8, 2017February 25, 2024

DEFCON 24 Badge Challenge Walkthrough

August 10, 2016February 25, 2024

Google CTF – Web Write-Ups (11/15)

May 1, 2016February 25, 2024

Google CTF – Web 11 – Flag Storage Service

May 1, 2016February 25, 2024

ESEA Server-Side Request Forgery and Querying AWS Meta Data

April 18, 2016February 25, 2024

Yahoo Login Protection Seal – Stored CSS Injection

April 18, 2016February 25, 2024

CSAW 2015 – Web 500 (Weebdate) Writeup

September 20, 2015February 25, 2024

DEFCON 23 Badge Challenge

August 11, 2015February 25, 2024

Google.com – Mobile Feedback URL Redirect Regex/Validation Flaw

February 3, 2015February 25, 2024

Flickr API Explorer – Force users to execute any API request.

February 3, 2015February 25, 2024

admin.google.com Reflected Cross-Site Scripting (XSS)

January 21, 2015February 25, 2024

Yahoo – Root Access SQL Injection – tw.yahoo.com

January 15, 2015February 25, 2024

DEFCON 22 Badge Challenge

August 12, 2014February 25, 2024

Facebook – Stored Cross-Site Scripting (XSS) – Badges

June 16, 2014February 25, 2024

Facebook – Send Notifications to any User Exploit

April 7, 2014February 25, 2024