Unleashing the power of CSS injection: The access key to an internal APIIn this write-up, we will be explaining how a CSS injection point let us access an internal API exposing customer data.Jan 24, 2023A response icon2Jan 24, 2023A response icon2
Escalating SSRF to RCERetrieving AWS metadata and use it for RCEFeb 5, 2021A response icon2Feb 5, 2021A response icon2
Stored XSS on funda, funda desk and funda emailsFull disclosure about how I discovered a Stored XSS vulnerability on funda, funda desk and funda emails.Jul 11, 2018Jul 11, 2018
Personal data of all Dutch public transport cards ("OV-Chipkaart") accessibleFull disclosure about how I discovered a way to access personal data of all Dutch public transport cards ("OV-Chipkaart")Mar 23, 2018Mar 23, 2018