↓ Skip to main content

Web exploitation

Bugs in web applications, APIs, and the software behind them.

2026

2020

2016

patrik.re Archive

.htpasswd exposed, DES hash cracked

Directory brute-forcing a private bug bounty target turned up a world-readable .htpasswd whose descrypt hash, once cracked, opened four staging and development subdomains.

patrik.re

Google Cloud Console: dormant stored XSS

An XSS payload stored as a Google Cloud project name executed months later in the unfiltered project-deletion error message, earning a $5,000 VRP reward, plus the impact argument that got it past a self-XSS classification.

2015

patrik.re

Shopify POS firmware: extracting a root hash

An in-scope Shopify POS endpoint exposed the card reader's firmware bundles, which unpack via binwalk, a dd carve at 0x202024 and jffs2dump into a JFFS2 root filesystem containing a salted MD5 root hash.

patrik.re Archive

Stop OS X Spotlight Leaking Your Location

Proxying OS X Spotlight through Burp showed it shipping the user's latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.

patrik.re

XSS via XML File Upload on PayPal

PayPal's invoicing feature accepted .xml attachments, and an XHTML-namespaced script element inside the XML executed when the file was served back. Includes the exploitability argument needed to qualify it for a bounty.

2014

patrik.re Archive

PayPal merchant directory reflected XSS

A duplicated q parameter in PayPal's merchant directory let an injected payload break out of script context, producing a reflected XSS that PayPal patched within days.

patrik.re Archive

Hijacking a Prezi Subdomain Redirect ($500)

mailroom.prezi.com concatenated the request path onto its own hostname when redirecting, so a request to /.attacker-domain sent victims to a lookalike attacker-controlled host.

patrik.re Archive

BillMeLater: XSS Through a Style Attribute

A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.

patrik.re Archive

Two Weeks of a Kippo SSH Honeypot

Results from two weeks of a Kippo SSH honeypot in November 2014: roughly 4,000 brute-force attempts, 2,500 distinct credential pairs, and a source distribution dominated by hosts in China.

patrik.re

PayPal Stored XSS via a Signup Flow Bypass

A stored XSS in PayPal's account name field, delivered to arbitrary users through invoices after bypassing the signup flow's security check by truncating the workflow URL to /webapps/.

patrik.re Archive

DOM XSS on PayPal's Main Domain

A payload placed in the URL fragment reached a DOM sink on PayPal's main domain and executed; PayPal closed the report as a duplicate.

patrik.re

XSS in Google Tag Manager via JSON Import

Google Tag Manager validated macro names in the web UI but not in the JSON container import path, so a payload smuggled through a file upload executed and earned a $5,000 bounty.

patrik.re

Chrome backslash URLs and XSS filter bypass

Chrome resolves and executes a script URL written as http: followed by any number of backslashes. Firefox does not, and that difference can slip past pattern-matching XSS filters, closed by Chromium as wontfix.

patrik.re Archive

Path Traversal on map.prezi.com ($1,000)

A path traversal issue on Prezi's map.prezi.com subdomain, fixed within two days of reporting and rewarded with a $1,000 bounty.

patrik.re Archive

Seven PayPal Bugs, Zero Bounties

A 2014 run through PayPal's bug bounty scope: seven confirmed issues across paypal.com, financing.paypal.com, apps.paypal.com and the paypal-*.com family, all closed as duplicate or invalid.

2013

patrik.re Archive

160 German tax office sites vulnerable to XSS

Reflected cross-site scripting across 160 German tax office websites, disclosed via heise.de and forwarded to CERT-Bund for coordinated remediation.

patrik.re Archive

PHP 5.3.3–5.3.6 socket_connect Bind Shell

A public PHP 5.3.3-5.3.6 socket_connect exploit carrying a bind-TCP shell payload, dropped as an uploaded PHP file and located with an nmap sweep of ports 4000-4500.

patrik.re Archive

SQL injection to root on a 2013 lab box

Chaining a login-form SQL injection through sqlmap's --os-shell into a Linux 2.6.32 local root exploit to go from the 'nobody' user to full control of the server.

patrik.re Archive

Yahoo's /14 and an exposed phpinfo.php

Pivoting from Yahoo's main A record to its ARIN netblock and sweeping all 260,000 addresses in the /14 for an exposed phpinfo.php.