<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:xhtml="http://www.w3.org/1999/xhtml">

  <url>
    <loc>https://medusa0xf.com/posts/mcp-servers-explained/</loc>
    <lastmod>2026-03-17T21:53:25+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/</loc>
    <lastmod>2026-03-17T21:53:25+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/</loc>
    <lastmod>2026-03-17T21:53:25+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/idor-leads-to-unauthorized-deletion-how-i-earned-500-in-bug-bounty/</loc>
    <lastmod>2025-11-08T11:55:35+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/how-i-found-an-account-takeover-bug-in-the-forgot-password-flow/</loc>
    <lastmod>2025-09-23T21:55:35+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/how-i-found-a-3000-idor-vulnerability-in-a-delivery-app/</loc>
    <lastmod>2025-09-13T20:57:35+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/bypassing-rate-limit-in-graphql/</loc>
    <lastmod>2024-12-05T19:43:35+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/exploiting-dom-for-open-redirect-attacks/</loc>
    <lastmod>2024-11-22T22:30:35+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/exploiting-insecure-output-handling-in-llms/</loc>
    <lastmod>2024-07-21T12:42:00+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/indirect-prompt-injection/</loc>
    <lastmod>2024-07-14T12:04:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/policy/</loc>
    <lastmod>2024-07-08T21:34:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/exploiting-vulnerabilities-in-llm-apis/</loc>
    <lastmod>2024-06-29T22:34:07+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/exploiting-llm-apis-with-excessive-agency/</loc>
    <lastmod>2024-06-22T23:04:07+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/what-is-llm-apis-and-how-they-work/</loc>
    <lastmod>2024-06-18T15:04:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/http-parameter-pollution-vs-mass-assignment/</loc>
    <lastmod>2024-06-04T22:20:35+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/testing-auth-methods-in-rest-api/</loc>
    <lastmod>2024-05-09T21:21:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/api-basics-hsg/</loc>
    <lastmod>2024-03-21T21:42:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/sqli-in-graphql-dvga/</loc>
    <lastmod>2024-03-17T21:39:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/api-subdomains/</loc>
    <lastmod>2024-03-12T22:05:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/server-side-parameter-pollution/</loc>
    <lastmod>2024-03-04T11:50:00+00:01</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/csrf-in-graphql/</loc>
    <lastmod>2024-01-16T22:05:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/posts/api-broken-auth/</loc>
    <lastmod>2022-06-13T20:55:37+01:00</lastmod>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/topics/api/</loc>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://medusa0xf.com/topics/web/</loc>
    <changefreq>daily</changefreq>
    <priority>0.5</priority>
  </url>
</urlset>
