Pocas Notes.

($10,890) What is XSS in the ML/AI ecosystem, not only web3.0?


The article is about how i have got $10k via xss vulnerability in the ML/AI ecosystem. i am sure that many researcher on web2.0 found the xss vulnerability but not all guys gets big bounty for xss. so today i wanna introduce what we need to do after finding xss. Actually every bug can give you guys nice bounty > even if it's xss
Read more ⟶

0-Day, Copy and Paste ReDoS in github.com


The article is about 0-day, ReDos vulnerability in github.com. ReDoS vulnerability is a type of DoS vulnerability that occurs within a regular expression engine. This vulnerability occurred in the paste-markdown module on GitHub.
Read more ⟶

Line CTF 2023 Write Up


This article is about write-up for the Line ctf 2023. there is only two web challenges, both of which contain an SSRF bug
Read more ⟶

HTB apocalypse CTF 2023 spybug Write Up


This article is about write-up for the HTB apocalypse CTF 2023. there is only one web challenges, which contain an XXS bug
Read more ⟶

b01lers CTF 2023 Write Up


This article is about write-up for the b01lers CTF 20233. there is only one web challenge, which contain an XXS bug
Read more ⟶