Skip to main content

Posts

2025

How I Found an Account Takeover Bug in the Forgot Password Flow
·801 words·4 mins
How I Found a $3000 IDOR Vulnerability in a Delivery App
·1045 words·5 mins

2024

Bypassing Rate Limit in GraphQL
·1526 words·8 mins
Exploiting DOM for Open Redirect Attacks
·1735 words·9 mins
Exploiting insecure output handling in LLMs
·457 words·3 mins
Indirect prompt injection
·740 words·4 mins
Exploiting vulnerabilities in LLM APIs
·838 words·4 mins
Exploiting LLM APIs with excessive agency
·540 words·3 mins
What is LLM APIs and how they work?
·1031 words·5 mins
HTTP Parameter Pollution vs Mass Assignment
·1176 words·6 mins