7 Jul 2026, 09:42 UTC417 views5 reactionsread 8 August 2026 🚀 Client-Side Path Traversal (CSPT) — How Deleting a Spam Post Deleted the Org Owner's Own Content
🔗 Link: Read Full Writeup
🛡 Vulnerability: Client-Side Path Traversal (CSPT)
📝 Summary:
An attacker exploited a pure Client-Side Path Traversal (CSPT) vulnerability on a collaboration platform to trick organization owners into deleting their own posts. By injecting a path traversal payload into the _id of a newly cre…
🔥3❤1👍1
7 Jul 2026, 09:42 UTC298 views1 reactionsread 8 August 2026 🚀 I Wasted 3 Days Intercepting a Flutter App. Here’s What Actually Works.
🔗 Link: Read Full Writeup
🛡 Vulnerability: Mobile Interception / SSL Pinning Bypass
📝 Summary:
A deep dive into intercepting Flutter application traffic using Burp Suite. Standard SSL pinning bypass methods often fail on Flutter because it uses a statically compiled BoringSSL library instead of Android's system certificate store, and because…
🔥1
7 Jul 2026, 09:38 UTC169 views1 reactionsread 8 August 2026 🚀 Disclosing YouTube Creator Emails for a $20k Bounty
🔗 Link: Read Full Writeup
🛡 Vulnerability: Information Disclosure, API Parameter Leakage, IDOR/Broken Access Control
📝 Summary:
A chained vulnerability allowing attackers to disclose the private email addresses of any monetized YouTube creator. By abusing an undocumented API parameter leakage vector using ProtoJson, the attacker discovered a hidden parameter th…
🔥1
7 Jul 2026, 09:38 UTC118 viewsread 8 August 2026 🚀 Who's SHA is it Anyway: Bypassing Google Cloud Build Comment Control
🔗 Link: Read Full Writeup
🛡 Vulnerability: TOCTOU, Poisoned Pipeline Execution, Race Condition
📝 Summary:
A TOCTOU race condition in Google Cloud Build's GitHub integration allowed untrusted contributors to bypass the /gcbrun maintainer approval mechanism. By pushing a malicious commit immediately after a maintainer commented on a benign Pull R…
7 Jul 2026, 09:32 UTC95 viewsread 8 August 2026 🚀 Old New Email Attacks
🔗 Link: Read Full Writeup
🛡 Vulnerability: Email Spoofing, CRLF Injection, SMTP Injection
📝 Summary:
An exploration of email protocol parsing vulnerabilities caused by discrepancies between RFC standards and real-world implementations in major programming libraries (Python, JS, C#) and email providers (Gmail, Outlook). These flaws enable severe attacks including SMTP Injection and convincin…
7 Jul 2026, 09:32 UTC68 viewsread 8 August 2026 🚀 Prompt Injection Isn't a Vulnerability
🔗 Link: Read Full Writeup
🛡 Vulnerability: Architectural Flaw, Data Exfiltration
📝 Summary:
An analysis arguing that Prompt Injection should be viewed as a delivery mechanism rather than a root vulnerability. The true vulnerabilities lie in the architectural decisions that grant AI models the authority to perform unsafe actions, such as rendering untrusted markdown, sending…
7 Jul 2026, 09:32 UTC58 viewsread 8 August 2026 🚀 Exploring IPv6 Zone Identifier
🔗 Link: Read Full Writeup
🛡 Vulnerability: Input Validation Bypass, SSRF, Command Injection, CRLF
📝 Summary:
An analysis of the security risks introduced by IPv6 Zone Identifiers (%zone_id). Inconsistent implementations across URL parsers in Python, Go, and C# allow attackers to inject arbitrary strings, leading to hostname validation bypasses, SSRF, and in some contexts, Command I…
7 Jul 2026, 09:32 UTC55 viewsread 8 August 2026 🚀 Breaking Down Multipart Parsers: File Upload Validation Bypass
🔗 Link: Read Full Writeup
🛡 Vulnerability: WAF Bypass, File Upload Bypass, Multipart Parser Exploitation
📝 Summary:
An extensive analysis of how multipart/form-data parsers across various languages (PHP, Node.js, Flask) and Web Application Firewalls (HAProxy, FortiWeb, Barracuda, ModSecurity) deviate from RFC standards. These discrepancies allow atta…
7 Jul 2026, 09:32 UTC41 viewsread 8 August 2026 🚀 Bypassing WAFs for Fun and JS Injection with Parameter Pollution
🔗 Link: Read Full Writeup
🛡 Vulnerability: WAF Bypass, XSS (Cross-Site Scripting), HTTP Parameter Pollution
📝 Summary:
A deep dive into bypassing strict Web Application Firewalls (WAFs) to exploit reflected XSS in an ASP.NET application. By combining HTTP Parameter Pollution with the Javascript comma operator, attackers were able to split payloads …
7 Jul 2026, 09:31 UTC39 viewsread 8 August 2026 🚀 Cross-Site ETag Length Leak
🔗 Link: Read Full Writeup
🛡 Vulnerability: XS-Leak (Cross-Site Leak), Information Disclosure
📝 Summary:
A novel XS-Leak technique utilizing the length of the HTTP ETag header to detect cross-site search hits or misses. By manipulating the total response size via CSRF padding, an attacker can reliably control the ETag generation logic so its length differs based on the presence of a ta…
7 Jul 2026, 09:31 UTC38 viewsread 8 August 2026 🔥 Impact:
Enables the exploitation of otherwise unexploitable vulnerabilities, such as leaking OAuth codes for account takeover or bypassing client-side redirect protections to trigger XSS.
#Bypasses #Redirect #OAuth #Exploitation
7 Jul 2026, 09:31 UTC48 viewsread 8 August 2026 🚀 Stopping Redirects
🔗 Link: Read Full Writeup
🛡 Vulnerability: OAuth Exploitation, Redirect Bypasses
📝 Summary:
A collection of advanced browser techniques to stop or pause client-side and server-side redirects. These techniques are crucial for exploiting niche scenarios like leaking OAuth codes during the 'dirty dance' attack or pausing fast-redirecting pages to exploit interaction-based XSS.
🕵️♂️ Recon Steps …
Showing the 12 most recent of 20 posts we hold for @WGPE0o0. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.