Chaining Bugs to Steal Yahoo Contacts!

👨🏻‍💻 Introduction & Background:

This is a write-up of how I chained two vulnerabilities (an XSS and a CORS misconfiguration) that allowed me to steal contacts from a victim’s contact book. This data included: names,...

Read More

SQL Injection in rog.asus.com

🔎 Introduction & Background

        To get started, I’ll give a bit of backstory behind this. I found this bug back in January of 2017 and was one of the first reports I made to...

Read More

Tricky CORS Bypass in Yahoo! View

Recently, HackerOne hosted their second Hack The World competition. During this time I decided to take a look at Yahoo’s bug bounty program because I have heard good things about them and also due to...

Read More

Stored XSS in BandCamp

        Recently, while my friend Alyssa Herrera and I were collaborating on finding ffmpeg vulnerabilities in bug bounty programs, we came to learn that Bandcamp ran a bug bounty program. If you...

Read More