— Posts
10 / 10
-
2026 · 03 · 21
Story of Abusing a Fully Secured redirect_uri in an OAuth Flow
-
2026 · 02 · 23
uXSS on Samsung Browser [CVE-2025-58485 · SVE-2025-1879]
-
2025 · 08 · 09
Hacking Veeam: Several CVEs and $30k Bounties
-
2025 · 06 · 01
Puny-Code, 0-Click Account Takeover
-
2025 · 02 · 15
CSS Data Exfiltration to Steal OAuth Token
-
2024 · 11 · 19
From an Android Hook to RCE: $5000 Bounty
-
2024 · 10 · 23
A Weird CSP Bypass led to $3.5k Bounty
-
2024 · 10 · 11
Drilling the redirect_uri in OAuth
-
2024 · 09 · 17
Account Takeover due to DNS Rebinding
-
2023 · 10 · 20
Bug Bounty Roadmap from Scratch