← All writings
#bounty 17 posts
16 Jul 2015 Shopify: Remote Code Execution 15 Oct 2014 HackerOne Vulnerability: Leaking Common Response Titles 08 Aug 2014 Facebook FriendFeed Stored XSS 08 Aug 2014 Facebook MailChimp Application OAuth 2.0 Misconfiguration 27 Mar 2014 Flipkart.com - Elevation of Privilege 18 Feb 2014 SSRF/XSPA in MailChimp 21 Sep 2013 PayPal CSRF aids in account takeover! 13 Jun 2013 Pwning Facebook accounts, taking a little help from Quora 21 May 2013 Dropbox for Business Mailing List Unsubscribe Users (Permission Issue) 16 May 2013 Dropbox Team Website Open Redirection 04 May 2013 Google Website Translator (Add Editor) CSRF and Google Tasks Clickjacking 12 Mar 2013 File Upload Bug in PayPal's BillMeLater 21 Feb 2013 Facebook Whitehat Vulnerability for 2013: Open Redirection in Facebook Mobile 29 Jan 2013 Blind SQL Injection in PayPal Notifications 18 Oct 2012 Twitter Whitehat Vulnerability for 2012: Translation Center CSRF/XSRF 12 Oct 2012 Adobe Website XSS and Open Redirect Vulnerabilities 15 Aug 2012 Google Website Translator Clickjacking Vulnerability