Easy $$$ via API params manipulation leading to bypassing the email verification block |
|
|
|
How I Used JS files inspection and Fuzzing to do admins/supports stuff |
|
|
|
Discovering 5 XSS Vulnerabilities In a Simple Way With Xssor.go |
|
|
|
CSRF + Stored XSS Leading to Full Account Takeover |
|
|
|