PayPal Pays Me A Total Bounty Of 10,000 For The Command Execution Bug 9:00 AM Recently, I wrote about the command execution vulnerability i found in Paypal for which they sent me an initial payme...
RHA XSS Challenge 1 - Writeup 9:00 AM Update - The challenge is still up on hack.me - https://hack.me/101575/bypass-blacklist-based-waf-challenge.html On 7th January 201...
Paypal Mobile Verification And Payment Restrictions Bypass 8:53 AM In this post, i would like to share a very simple logic flaw I found earlier this year I have found a way to circumvent mobile verificat...
Sucuri WAF XSS Filter Bypass 8:50 AM Introduction Sucuri Cloud Proxy is a very well known WAF capable of preventing DOS, SQL Injection, XSS and malware detection and preve...
Puffin Web Browser Address Bar Spoofing Vulnerability 8:41 AM During my recent research on Mobile browsers i have managed to find couple of interesting vulnerabilities such as SOP bypass, Denial of...
DOM XSS Explained 8:37 AM Cross Site scripting (XSS) has been a problem for well over a decade now, XSS just like other well known security issues such a...
Hacker's Dome - First Blood CTF 8:36 AM When it comes to Information Security, there's a great way to learn, train and keep sharp your skills. This can be done using gamific...
A Tale Of A DOM Based XSS In Paypal 8:36 AM Introduction We have already disclosed lots of findings related to DOM Based XSS and this article talks about a pretty interesting ...
Understanding This Technique Called MySQL Injection 8:32 AM ABSTRACT It is known that computers and software are developed and designed by humans, human error is a reflection of a mental response...
Kali Linux DOM Based XSS Writeup 7:43 AM Recently, I have been on a mission to find XSS in popular security training websites, Since these are the ones who care about their secu...
DOM Based XSS In Microsoft 7:36 AM Lately, i have been researching on DOM based XSS a bit, In my previous post i talked about the DOM based XSS i found inside A...