↓ Skip to main content

Disclosure & practice

Reporting bugs, working with vendors, and life inside bug bounty programmes.

2026

2014

patrik.re Archive

BillMeLater: XSS Through a Style Attribute

A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.

patrik.re

Chrome backslash URLs and XSS filter bypass

Chrome resolves and executes a script URL written as http: followed by any number of backslashes. Firefox does not, and that difference can slip past pattern-matching XSS filters, closed by Chromium as wontfix.

patrik.re Archive

Path Traversal on map.prezi.com ($1,000)

A path traversal issue on Prezi's map.prezi.com subdomain, fixed within two days of reporting and rewarded with a $1,000 bounty.

2013

patrik.re Archive

160 German tax office sites vulnerable to XSS

Reflected cross-site scripting across 160 German tax office websites, disclosed via heise.de and forwarded to CERT-Bund for coordinated remediation.