Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Feeld dating app – Your nudes and data were publicly available- 1494

Bogdan Tiron - FortbridgePosted 1 Year Ago

Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS- 1493

Mikko KenttalaPosted 1 Year Ago

URL validation bypass cheat sheet- 1492

PortswiggerPosted 1 Year Ago

Writeup of CWA-2023-004- 1491

CertiKPosted 1 Year Ago

Exploiting Misconfigured GitLab OIDC AWS IAM Roles- 1490

Nick FrichettePosted 1 Year Ago

Unauthenticated Access to GCP Dataproc Can Lead to Data Leak- 1489

Roi NisimiPosted 1 Year Ago

Persistent XSS on Microsoft Bing.com by poisoning Bingbot indexing- 1488

Supakiad S. (m3ez)Posted 1 Year Ago

Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN- 1487

Sudhanshu RajbharPosted 1 Year Ago

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default - 1486

flask-corsPosted 1 Year Ago

Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities- 1485

Yaniv Nizry - Sonar SourcePosted 1 Year Ago