<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Disclosure &amp; practice · Patrik Grobshäuser</title>
    <link>https://patrik.re/topics/disclosure/</link>
    <description>Reporting bugs, working with vendors, and life inside bug bounty programmes.</description>
    <language>en-GB</language>
    <atom:link href="https://patrik.re/topics/disclosure/index.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Wed, 20 May 2026 00:00:00 &#43;0000</lastBuildDate>
    <item>
      <title>To Kara, Alex, and Michiel — Your Researchers Are Leaving</title>
      <link>https://patrik.re/to-kara-alex-and-michiel-your-researchers-are-leaving/</link>
      <guid isPermaLink="true">https://patrik.re/to-kara-alex-and-michiel-your-researchers-are-leaving/</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 &#43;0000</pubDate>
      <description>Bug bounty platforms never humanized researchers or triage. Now they&#39;re drowning in AI slop and wondering why their best people are leaving.</description>
      <category>patrik.re</category><category>disclosure</category><category>ai-security</category>
    </item>
    <item>
      <title>BillMeLater: XSS Through a Style Attribute</title>
      <link>https://patrik.re/bugbounty-reflected-cross-site-scripting-billmelater/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-reflected-cross-site-scripting-billmelater/</guid>
      <pubDate>Mon, 17 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Stored XSS in Three WordPress Chat Plugins</title>
      <link>https://patrik.re/wordpress-3x-vulnerable-chat-plugins-3/</link>
      <guid isPermaLink="true">https://patrik.re/wordpress-3x-vulnerable-chat-plugins-3/</guid>
      <pubDate>Thu, 02 Oct 2014 00:00:00 &#43;0000</pubDate>
      <description>WP Live Chat Support, MyLiveChat and Provide Support all accepted stored cross-site scripting during a 2014 customer install.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Chrome backslash URLs and XSS filter bypass</title>
      <link>https://patrik.re/google-chrome-security-multiple-leading-slashes-in-urls-may-confuse-some-server-side-xss-filters/</link>
      <guid isPermaLink="true">https://patrik.re/google-chrome-security-multiple-leading-slashes-in-urls-may-confuse-some-server-side-xss-filters/</guid>
      <pubDate>Tue, 17 Jun 2014 00:00:00 &#43;0000</pubDate>
      <description>Chrome resolves and executes a script URL written as http: followed by any number of backslashes. Firefox does not, and that difference can slip past pattern-matching XSS filters, closed by Chromium as wontfix.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Path Traversal on map.prezi.com ($1,000)</title>
      <link>https://patrik.re/bug-bounty-prezi-map-prezi-com-path-traversal/</link>
      <guid isPermaLink="true">https://patrik.re/bug-bounty-prezi-map-prezi-com-path-traversal/</guid>
      <pubDate>Wed, 21 May 2014 00:00:00 &#43;0000</pubDate>
      <description>A path traversal issue on Prezi&#39;s map.prezi.com subdomain, fixed within two days of reporting and rewarded with a $1,000 bounty.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>160 German tax office sites vulnerable to XSS</title>
      <link>https://patrik.re/were-on-heise-german-found-160-sites-vulnerable-to-xss/</link>
      <guid isPermaLink="true">https://patrik.re/were-on-heise-german-found-160-sites-vulnerable-to-xss/</guid>
      <pubDate>Mon, 11 Nov 2013 00:00:00 &#43;0000</pubDate>
      <description>Reflected cross-site scripting across 160 German tax office websites, disclosed via heise.de and forwarded to CERT-Bund for coordinated remediation.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
  </channel>
</rss>
