Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Exploiting Misconfigured GitLab OIDC AWS IAM Roles- 1490

Nick FrichettePosted 1 Year Ago

Unauthenticated Access to GCP Dataproc Can Lead to Data Leak- 1489

Roi NisimiPosted 1 Year Ago

Persistent XSS on Microsoft Bing.com by poisoning Bingbot indexing- 1488

Supakiad S. (m3ez)Posted 1 Year Ago

Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN- 1487

Sudhanshu RajbharPosted 1 Year Ago

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default - 1486

flask-corsPosted 1 Year Ago

Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities- 1485

Yaniv Nizry - Sonar SourcePosted 1 Year Ago

Breaking Down Barriers: Exploiting Pre-Auth SQL Injection in WhatsUp Gold- 1484

SinSinologyPosted 1 Year Ago

Due to the use of msg.value in for loop, anyone can drain all the funds from the THORChain_Router contract- 1483

Code4RenaPosted 1 Year Ago

ThorChain will be informed wrongly about the unsuccessful ETH transfers due to the incorrect events emissions- 1482

Code4RenaPosted 1 Year Ago

Government Emails at Risk: Critical Cross-Site Scripting Vulnerability in Roundcube Webmail- 1481

Oskar Zeino-Mahmalat - Sonar SourcePosted 1 Year Ago