Research is worth more when it is shared.
Publish findings, explain how you found them, and tell other researchers which programs are actually worth their time. You control what is disclosed, per finding.
Latest findings
View allUnverified Email Registration and Google OAuth Account Collision Lead Pre ATO
0xnotnull
·
1 week ago
·
1
Unverified account can reserve another user's email address lead to Pre ATO
0xnotnull
·
1 week ago
·
1
Privilege Escalation Vulnerability Led me to be Application admin
nyx0r
·
1 week ago
·
4
Unauthenticated IDOR allows enumeration of employee information
elkashawi
·
1 week ago
·
2
Stored XSS ----- organization control Via an automatic invitation to the organization
ghaziroot
·
2 weeks ago
Academy
All topicsLearn one vulnerability class at a time, then break it yourself in a hands-on lab that runs in your browser. Free, no setup.
Recent writeups
View allOpening a coding agent in a folder the attacker chose
A crafted link can make a desktop app launch a coding-agent CLI inside a directory the attacker controls. The victim only has to click the app's normal "open in terminal?" prompt. Once the agent starts in that folder and the victim trusts i...
Blind SSRF via MCP OAuth Discovery — Redirect-Based Bypass of a Private-IP Guard
Cracking an Intigriti target in under 24 Hours with two vulnerabilities
This is the story of a focused bug-hunting session in collaboration with my teammate @Rashed on an Intigriti target that led to two security findings -- in under 24 hours. --
Unauthenticated SSRF with Response Disclosure on a Secrets-Retrieval Gateway
Two endpoints, POST /get-secret1 and POST /get-secret3, on a target I’ll refer to as [REDACTED], took a JSON body with a field called gatewayHost. That field was meant to point at some internal secrets-retrieval service, but there was no va...