BBP Writeup Series #1 – Turning “useless” HTMLi on [REDACTED] into a P1 |
|
|
|
Full Disclosure - DOM-based XSS And Failures In Bug Bounty Hunting |
|
|
|
CSS Injection via PostMessages to stealing Credit Card Info |
|
|
|
Unleashing the power of CSS injection: The access key to an internal API |
|
|
|
Practical Client Side Path Traversal Attacks |
|
|
|
A 250$ CSS Injection — My First Finding on Hackerone! |
|
|
|
Getting Paid With Just Picking Color — Bug Bounty |
|
|
|
The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF… |
|
|
|
Keylogging users via Slack themes |
|
|
|
Exfiltration via CSS Injection |
|
|
|
Yahoo Login Protection Seal – Stored CSS Injection |
|
|
|