($10,890) What is XSS in the ML/AI ecosystem, not only web3.0?

The article is about how i have got $10k via xss vulnerability in the ML/AI ecosystem. i am sure that many researcher on web2.0 found the xss vulnerability but not all guys gets big bounty for xss. so today i wanna introduce what we need to do after finding xss. Actually every bug can give you guys nice bounty > even if it’s xss
Read more →

0-Day, Copy and Paste ReDoS in github.com

The article is about 0-day, ReDos vulnerability in github.com. ReDoS vulnerability is a type of DoS vulnerability that occurs within a regular expression engine. This vulnerability occurred in the paste-markdown module on GitHub.
Read more →

CCE 2022 Write Up

This article is about write-up for the CCE 2022. there is only three web challenges, all of which contain RCE, XSS, SSRF. Actually someone ask to me paly it but i couldn’t join with him.
Read more →