Posts

29 posts
27 Mar 2014 Flipkart.com - Elevation of Privilege #Flipkart #PrivEsc #Bounty 18 Feb 2014 SSRF/XSPA in MailChimp #MailChimp #SSRF #Bounty 21 Sep 2013 PayPal CSRF aids in account takeover! #PayPal #CSRF #Takeover 28 Jun 2013 Triggering an unexploitable DOM-based XSS in Rediff Blogs automagically #XSS #DOMXSS #Research 13 Jun 2013 Pwning Facebook accounts, taking a little help from Quora #Facebook #Quora #Takeover 06 Jun 2013 Flash-based XSS Mayhem: Most Security Solution Vendors Vulnerable #XSS #Flash #Research 21 May 2013 Dropbox for Business Mailing List Unsubscribe Users (Permission Issue) #Dropbox #Authorization #Bounty 16 May 2013 Dropbox Team Website Open Redirection #Dropbox #Redirect #Bounty 04 May 2013 Google Website Translator (Add Editor) CSRF and Google Tasks Clickjacking #Google #CSRF #Clickjacking 12 Mar 2013 File Upload Bug in PayPal's BillMeLater #PayPal #Upload #Bounty