Open in app

Sign in

Medium Logo
Write

Sign in

Master SEC
Master SEC

129 followers

Home

About

The beauty of chaining client-side bugs

This is part of a report of a bug that I sent back in 2020, changing of course the program name for obvious reasons.

May 28, 2021
The beauty of chaining client-side bugs
The beauty of chaining client-side bugs
May 28, 2021

Weaponizing BURP to work as an evil SSRF Confluence Server.

I was doing bounty on a private H1 program that interacts with various external services one of them was Atlassian Confluence and Jira.

Dec 14, 2019
Weaponizing BURP to work as an evil SSRF Confluence Server.
Weaponizing BURP to work as an evil SSRF Confluence Server.
Dec 14, 2019

Bypass Uppercase filters like a PRO (XSS Advanced Methods)

While we are not working on Pentesting for companies, we love to Bug Hunting on Hackerone.

Oct 11, 2019
2
Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Oct 11, 2019
2
Master SEC

Master SEC

129 followers

It Security company from Argentina. Penetration Testing, Red Team, Bug Bounty, Training.

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech