Scream at it until it Escalates - XSS to ATO via Server Size Errors Gadgets
Servers and Frameworks, just like us humans, have their own limitations in terms of how much data they can handle at once. Maybe you're are familiar with ...
XSS
Server Errors
Bypass trustedOrigins Protection leads to ATO
Like starting recon scripts from scratch from time to time just because we feel like it, I decided to do that for my blog and it's design in general ...
Open Redirect
Business Logic
Kanboard - Spraying Malicious Tasks
Kanboard is a widely used Kanban project management software with over 10 million downloads on Docker Hub. Today we're going explore how I found ...
Open Redirect
Business Logic
Stealing Credit Card Info with CSS
In this writeup I'll walk you through how I used CSS Injection to steal users Credit Card Info via Post-Messages ...
Web Sockets
CSS Injection
CVE-2022-0478 Wordpress Event-Manager Plugin SQLI
It's been a while since I posted something ... But I plan to bring new content into the blog and to get off on the right foot. We'll start with ...
SQL Injection
Business Logic