Bug Bounty - Cross-site request forgery is a thing

In this post I will explain when CSRF can be a serious issue. I will use an example for which I got promoted $2.400 as bounty.
Read more →

I hacked the german armed forces, and all I got …

This blog post will describe my adventure with the german armed forces and how I earned more than just a lousy T-Shirt. Topic: Vulnerability Disclosure Policy - Deutsche Bundeswehr
Read more →

[CVE-2020-14293] and [CVE-2020-14294] 2 vulnerabilities in Secure File Transfer Solution Qiata by Secudos

The Secure File Transfer Solution Qiata by Secudos suffers from two vulnerabilities. One persistent Cross-Site Scripting and one Authenticated OS Command Injection with Privilege Escalation. This post will describe the vulnerabilities in detail.
Read more →