Sander Wind·Oct 14, 2025Intigriti 1025 Challenge: SSRF to RCE via File Upload BypassChallenge OverviewA response icon1A response icon1
Sander Wind·Jan 24, 2023Unleashing the power of CSS injection: The access key to an internal APIIn this write-up, we will be explaining how a CSS injection point let us access an internal API exposing customer data.A response icon2A response icon2
Sander Wind·Feb 5, 2021Escalating SSRF to RCERetrieving AWS metadata and use it for RCEA response icon2A response icon2
Sander Wind·Jul 11, 2018Stored XSS on funda, funda desk and funda emailsFull disclosure about how I discovered a Stored XSS vulnerability on funda, funda desk and funda emails.
Sander Wind·Mar 23, 2018Personal data of all Dutch public transport cards ("OV-Chipkaart") accessibleFull disclosure about how I discovered a way to access personal data of all Dutch public transport cards ("OV-Chipkaart")