<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Prakhar Prasad</title><description>Security researcher, author, and bug bounty hunter. Writings on web security, vulnerability research, and exploitation techniques.</description><link>https://prakharprasad.com/</link><language>en-us</language><item><title>Part V: Exploration - Intruder Payload Processing</title><link>https://prakharprasad.com/exploration-intruder-payload-processing/</link><guid isPermaLink="true">https://prakharprasad.com/exploration-intruder-payload-processing/</guid><pubDate>Wed, 01 Aug 2018 17:00:00 GMT</pubDate><category>BurpSuite</category><category>Extension</category><category>Tutorial</category></item><item><title>Part IV: Diving deeper into Extender API Interfaces</title><link>https://prakharprasad.com/diving-deeper-into-extender-api-interfaces/</link><guid isPermaLink="true">https://prakharprasad.com/diving-deeper-into-extender-api-interfaces/</guid><pubDate>Wed, 01 Aug 2018 05:06:00 GMT</pubDate><category>BurpSuite</category><category>Extension</category><category>Tutorial</category></item><item><title>Part III: Extension Project Structure and Fundamentals</title><link>https://prakharprasad.com/burp-project-structure-and-fundamentals/</link><guid isPermaLink="true">https://prakharprasad.com/burp-project-structure-and-fundamentals/</guid><pubDate>Tue, 31 Jul 2018 20:06:00 GMT</pubDate><category>BurpSuite</category><category>Extension</category><category>Tutorial</category></item><item><title>Part II: Setting Up Extension Development Tools</title><link>https://prakharprasad.com/setting-up-extension-development-tools/</link><guid isPermaLink="true">https://prakharprasad.com/setting-up-extension-development-tools/</guid><pubDate>Mon, 30 Jul 2018 17:06:00 GMT</pubDate><category>BurpSuite</category><category>Extension</category><category>Tutorial</category></item><item><title>Part I: Introduction to Burp Extender</title><link>https://prakharprasad.com/introduction-to-burp-extender/</link><guid isPermaLink="true">https://prakharprasad.com/introduction-to-burp-extender/</guid><pubDate>Mon, 30 Jul 2018 12:41:23 GMT</pubDate><category>BurpSuite</category><category>Extension</category><category>Tutorial</category></item><item><title>Burp Suite Extension Development Series</title><link>https://prakharprasad.com/burp-suite-extension-development-series/</link><guid isPermaLink="true">https://prakharprasad.com/burp-suite-extension-development-series/</guid><pubDate>Mon, 30 Jul 2018 11:26:25 GMT</pubDate><category>BurpSuite</category><category>Extension</category><category>Tutorial</category></item><item><title>Shopify: Remote Code Execution</title><link>https://prakharprasad.com/shopify-remote-code-execution/</link><guid isPermaLink="true">https://prakharprasad.com/shopify-remote-code-execution/</guid><pubDate>Thu, 16 Jul 2015 11:58:19 GMT</pubDate><category>Shopify</category><category>RCE</category><category>Bounty</category></item><item><title>HackerOne Vulnerability: Leaking Common Response Titles</title><link>https://prakharprasad.com/hackerone-vulnerability-common-response-title-leak-through-triggers/</link><guid isPermaLink="true">https://prakharprasad.com/hackerone-vulnerability-common-response-title-leak-through-triggers/</guid><pubDate>Wed, 15 Oct 2014 08:33:00 GMT</pubDate><category>HackerOne</category><category>Disclosure</category><category>Bounty</category></item><item><title>Facebook FriendFeed Stored XSS</title><link>https://prakharprasad.com/facebook-friendfeed-stored-xss/</link><guid isPermaLink="true">https://prakharprasad.com/facebook-friendfeed-stored-xss/</guid><pubDate>Fri, 08 Aug 2014 09:27:00 GMT</pubDate><category>Facebook</category><category>XSS</category><category>Bounty</category></item><item><title>Facebook MailChimp Application OAuth 2.0 Misconfiguration</title><link>https://prakharprasad.com/facebook-mailchimp-application-oauth-2-0-misconfiguration/</link><guid isPermaLink="true">https://prakharprasad.com/facebook-mailchimp-application-oauth-2-0-misconfiguration/</guid><pubDate>Fri, 08 Aug 2014 09:27:00 GMT</pubDate><category>Facebook</category><category>MailChimp</category><category>OAuth</category><category>Bounty</category></item><item><title>Flipkart.com - Elevation of Privilege</title><link>https://prakharprasad.com/flipkart-com-elevation-of-privilege/</link><guid isPermaLink="true">https://prakharprasad.com/flipkart-com-elevation-of-privilege/</guid><pubDate>Thu, 27 Mar 2014 09:27:00 GMT</pubDate><category>Flipkart</category><category>PrivEsc</category><category>Bounty</category></item><item><title>SSRF/XSPA in MailChimp</title><link>https://prakharprasad.com/ssrf-xspa-in-mailchimp/</link><guid isPermaLink="true">https://prakharprasad.com/ssrf-xspa-in-mailchimp/</guid><pubDate>Tue, 18 Feb 2014 09:27:00 GMT</pubDate><category>MailChimp</category><category>SSRF</category><category>Bounty</category></item><item><title>PayPal CSRF aids in account takeover!</title><link>https://prakharprasad.com/paypal-csrf-aids-in-account-takeover/</link><guid isPermaLink="true">https://prakharprasad.com/paypal-csrf-aids-in-account-takeover/</guid><pubDate>Sat, 21 Sep 2013 10:11:00 GMT</pubDate><category>PayPal</category><category>CSRF</category><category>Takeover</category><category>Bounty</category></item><item><title>Triggering an unexploitable DOM-based XSS in Rediff Blogs automagically</title><link>https://prakharprasad.com/triggering-an-unexploitable-dom-based-xss-in-rediff-blogs-automagically/</link><guid isPermaLink="true">https://prakharprasad.com/triggering-an-unexploitable-dom-based-xss-in-rediff-blogs-automagically/</guid><pubDate>Fri, 28 Jun 2013 22:19:00 GMT</pubDate><category>XSS</category><category>DOMXSS</category><category>Research</category></item><item><title>Pwning Facebook accounts, taking a little help from Quora</title><link>https://prakharprasad.com/pwning-facebook-accounts-taking-a-little-help-from-quora/</link><guid isPermaLink="true">https://prakharprasad.com/pwning-facebook-accounts-taking-a-little-help-from-quora/</guid><pubDate>Thu, 13 Jun 2013 22:19:00 GMT</pubDate><category>Facebook</category><category>Quora</category><category>Takeover</category><category>Bounty</category></item><item><title>Flash-based XSS Mayhem: Most Security Solution Vendors Vulnerable</title><link>https://prakharprasad.com/flash-based-xss-mayhem-most-security-solution-vendors-vulnerable/</link><guid isPermaLink="true">https://prakharprasad.com/flash-based-xss-mayhem-most-security-solution-vendors-vulnerable/</guid><pubDate>Thu, 06 Jun 2013 22:19:00 GMT</pubDate><category>XSS</category><category>Flash</category><category>Research</category></item><item><title>Dropbox for Business Mailing List Unsubscribe Users (Permission Issue)</title><link>https://prakharprasad.com/dropbox-for-business-mailing-list-unsubscribe-users-permission-issue/</link><guid isPermaLink="true">https://prakharprasad.com/dropbox-for-business-mailing-list-unsubscribe-users-permission-issue/</guid><pubDate>Tue, 21 May 2013 22:19:00 GMT</pubDate><category>Dropbox</category><category>Authorization</category><category>Bounty</category></item><item><title>Dropbox Team Website Open Redirection</title><link>https://prakharprasad.com/dropbox-team-website-open-redirection/</link><guid isPermaLink="true">https://prakharprasad.com/dropbox-team-website-open-redirection/</guid><pubDate>Thu, 16 May 2013 22:19:00 GMT</pubDate><category>Dropbox</category><category>Redirect</category><category>Bounty</category></item><item><title>Google Website Translator (Add Editor) CSRF and Google Tasks Clickjacking</title><link>https://prakharprasad.com/google-website-translator-add-editor-csrf-and-google/</link><guid isPermaLink="true">https://prakharprasad.com/google-website-translator-add-editor-csrf-and-google/</guid><pubDate>Sat, 04 May 2013 22:19:00 GMT</pubDate><category>Google</category><category>CSRF</category><category>Clickjacking</category><category>Bounty</category></item><item><title>File Upload Bug in PayPal&apos;s BillMeLater</title><link>https://prakharprasad.com/file-upload-bug-in-paypals-billmelater/</link><guid isPermaLink="true">https://prakharprasad.com/file-upload-bug-in-paypals-billmelater/</guid><pubDate>Tue, 12 Mar 2013 22:19:00 GMT</pubDate><category>PayPal</category><category>Upload</category><category>Bounty</category></item><item><title>Facebook Whitehat Vulnerability for 2013: Open Redirection in Facebook Mobile</title><link>https://prakharprasad.com/facebook-whitehat-vulnerability-for-2013-open-redirection-in-facebook-mobile/</link><guid isPermaLink="true">https://prakharprasad.com/facebook-whitehat-vulnerability-for-2013-open-redirection-in-facebook-mobile/</guid><pubDate>Thu, 21 Feb 2013 22:19:00 GMT</pubDate><category>Facebook</category><category>Redirect</category><category>Bounty</category></item><item><title>Blind SQL Injection in PayPal Notifications</title><link>https://prakharprasad.com/blind-sql-injection-in-paypal-notifications/</link><guid isPermaLink="true">https://prakharprasad.com/blind-sql-injection-in-paypal-notifications/</guid><pubDate>Tue, 29 Jan 2013 22:19:00 GMT</pubDate><category>PayPal</category><category>SQLi</category><category>Bounty</category></item><item><title>Twitter Whitehat Vulnerability for 2012: Translation Center CSRF/XSRF</title><link>https://prakharprasad.com/twitter-translation-center-csrf/</link><guid isPermaLink="true">https://prakharprasad.com/twitter-translation-center-csrf/</guid><pubDate>Thu, 18 Oct 2012 22:19:00 GMT</pubDate><category>Twitter</category><category>CSRF</category><category>Bounty</category></item><item><title>Adobe Website XSS and Open Redirect Vulnerabilities</title><link>https://prakharprasad.com/adobe-website-xss-and-open-redirect-vulnerabilities/</link><guid isPermaLink="true">https://prakharprasad.com/adobe-website-xss-and-open-redirect-vulnerabilities/</guid><pubDate>Fri, 12 Oct 2012 22:19:00 GMT</pubDate><category>Adobe</category><category>XSS</category><category>Redirect</category><category>Bounty</category></item><item><title>Google Website Translator Clickjacking Vulnerability</title><link>https://prakharprasad.com/google-website-translator-clickjacking-vulnerability/</link><guid isPermaLink="true">https://prakharprasad.com/google-website-translator-clickjacking-vulnerability/</guid><pubDate>Wed, 15 Aug 2012 22:19:00 GMT</pubDate><category>Google</category><category>Clickjacking</category><category>Bounty</category></item><item><title>Introduction to SQL Injection and Exploitation (MySQL 5 error based)</title><link>https://prakharprasad.com/introduction-to-sql-injection-and-exploitation-mysql-5-error-based/</link><guid isPermaLink="true">https://prakharprasad.com/introduction-to-sql-injection-and-exploitation-mysql-5-error-based/</guid><pubDate>Mon, 23 Jul 2012 22:19:00 GMT</pubDate><category>SQLi</category><category>MySQL</category><category>Tutorial</category></item><item><title>Facebook Porn Scam Attack: The Complete Story</title><link>https://prakharprasad.com/facebook-porn-scam-attack-the-complete-story/</link><guid isPermaLink="true">https://prakharprasad.com/facebook-porn-scam-attack-the-complete-story/</guid><pubDate>Wed, 21 Dec 2011 22:19:00 GMT</pubDate><category>Facebook</category><category>Scam</category></item><item><title>Windows password cracking using John The Ripper</title><link>https://prakharprasad.com/windows-password-cracking-using-john-the-ripper/</link><guid isPermaLink="true">https://prakharprasad.com/windows-password-cracking-using-john-the-ripper/</guid><pubDate>Sat, 01 Oct 2011 22:19:00 GMT</pubDate><category>Cracking</category><category>Windows</category><category>Tutorial</category></item><item><title>CRLF Injection / HTTP Response Splitting Explained</title><link>https://prakharprasad.com/crlf-injection-http-response-splitting-explained/</link><guid isPermaLink="true">https://prakharprasad.com/crlf-injection-http-response-splitting-explained/</guid><pubDate>Wed, 24 Aug 2011 22:19:00 GMT</pubDate><category>CRLF</category><category>Vulnerability</category></item></channel></rss>