<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Web exploitation · Patrik Grobshäuser</title>
    <link>https://patrik.re/topics/web-exploitation/</link>
    <description>Bugs in web applications, APIs, and the software behind them.</description>
    <language>en-GB</language>
    <atom:link href="https://patrik.re/topics/web-exploitation/index.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Thu, 25 Jun 2026 00:00:00 &#43;0000</lastBuildDate>
    <item>
      <title>CargoWise WebTracker — The Keys Were in the Cargo</title>
      <link>https://slcyber.io/research-center/cargowise-webtracker-the-keys-were-in-the-cargo/</link>
      <guid isPermaLink="true">https://slcyber.io/research-center/cargowise-webtracker-the-keys-were-in-the-cargo/</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 &#43;0000</pubDate>
      <description>Credentials recoverable from a logistics platform&#39;s own tracking interface.</description>
      <category>Searchlight Cyber</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Keys to the Kingdom: Anonymous SQL Injection in Drupal Core</title>
      <link>https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/</link>
      <guid isPermaLink="true">https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 &#43;0000</pubDate>
      <description>Unauthenticated SQL injection reachable in Drupal core.</description>
      <category>Searchlight Cyber</category><category>web-exploitation</category>
    </item>
    <item>
      <title>New Age of Collisions: Pre-Auth Arbitrary File Read as root in cPanel</title>
      <link>https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205/</link>
      <guid isPermaLink="true">https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205/</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 &#43;0000</pubDate>
      <description>Reading arbitrary files pre-authentication, as root, on cPanel.</description>
      <category>Searchlight Cyber</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Jolokia endpoints: JNDI RCE and heap dumps</title>
      <link>https://patrik.re/how-i-made-more-than-30k-with-jolokia-cves/</link>
      <guid isPermaLink="true">https://patrik.re/how-i-made-more-than-30k-with-jolokia-cves/</guid>
      <pubDate>Tue, 16 Jun 2020 00:00:00 &#43;0000</pubDate>
      <description>A full lab build and exploitation walkthrough for exposed Jolokia JMX endpoints: reflected XSS (CVE-2018-1000129), JNDI remote code execution via a rogue LDAP server (CVE-2018-1000130), and dumping the Java heap to recover credentials.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>.htpasswd exposed, DES hash cracked</title>
      <link>https://patrik.re/bugbounty-decoding-a--f0-9f-98-b1-00000-htpasswd-bounty/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-decoding-a--f0-9f-98-b1-00000-htpasswd-bounty/</guid>
      <pubDate>Thu, 08 Sep 2016 00:00:00 &#43;0000</pubDate>
      <description>Directory brute-forcing a private bug bounty target turned up a world-readable .htpasswd whose descrypt hash, once cracked, opened four staging and development subdomains.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
    <item>
      <title>Google Cloud Console: dormant stored XSS</title>
      <link>https://patrik.re/bugbounty-sleeping-stored-google-xss-awakens-a-5000-bounty/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-sleeping-stored-google-xss-awakens-a-5000-bounty/</guid>
      <pubDate>Tue, 17 May 2016 00:00:00 &#43;0000</pubDate>
      <description>An XSS payload stored as a Google Cloud project name executed months later in the unfiltered project-deletion error message, earning a $5,000 VRP reward, plus the impact argument that got it past a self-XSS classification.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Shopify POS firmware: extracting a root hash</title>
      <link>https://patrik.re/digging-into-the-shopify-pos-firmware-part-1/</link>
      <guid isPermaLink="true">https://patrik.re/digging-into-the-shopify-pos-firmware-part-1/</guid>
      <pubDate>Fri, 09 Oct 2015 00:00:00 &#43;0000</pubDate>
      <description>An in-scope Shopify POS endpoint exposed the card reader&#39;s firmware bundles, which unpack via binwalk, a dd carve at 0x202024 and jffs2dump into a JFFS2 root filesystem containing a salted MD5 root hash.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>Stop OS X Spotlight Leaking Your Location</title>
      <link>https://patrik.re/research-stop-osx-spotlight-from-sending-your-location/</link>
      <guid isPermaLink="true">https://patrik.re/research-stop-osx-spotlight-from-sending-your-location/</guid>
      <pubDate>Mon, 15 Jun 2015 00:00:00 &#43;0000</pubDate>
      <description>Proxying OS X Spotlight through Burp showed it shipping the user&#39;s latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>XSS via XML File Upload on PayPal</title>
      <link>https://patrik.re/bugbounty-papyal-xml-upload-cross-site-scripting-vulnerability/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-papyal-xml-upload-cross-site-scripting-vulnerability/</guid>
      <pubDate>Wed, 07 Jan 2015 00:00:00 &#43;0000</pubDate>
      <description>PayPal&#39;s invoicing feature accepted .xml attachments, and an XHTML-namespaced script element inside the XML executed when the file was served back. Includes the exploitability argument needed to qualify it for a bounty.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>PayPal merchant directory reflected XSS</title>
      <link>https://patrik.re/bugbounty-reflected-cross-site-scripting-at-paypal-com/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-reflected-cross-site-scripting-at-paypal-com/</guid>
      <pubDate>Mon, 15 Dec 2014 00:00:00 &#43;0000</pubDate>
      <description>A duplicated q parameter in PayPal&#39;s merchant directory let an injected payload break out of script context, producing a reflected XSS that PayPal patched within days.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Hijacking a Prezi Subdomain Redirect ($500)</title>
      <link>https://patrik.re/bugbounty-malicious-redirect-on-mailroom-prezi-com/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-malicious-redirect-on-mailroom-prezi-com/</guid>
      <pubDate>Wed, 10 Dec 2014 00:00:00 &#43;0000</pubDate>
      <description>mailroom.prezi.com concatenated the request path onto its own hostname when redirecting, so a request to /.attacker-domain sent victims to a lookalike attacker-controlled host.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>BillMeLater: XSS Through a Style Attribute</title>
      <link>https://patrik.re/bugbounty-reflected-cross-site-scripting-billmelater/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-reflected-cross-site-scripting-billmelater/</guid>
      <pubDate>Mon, 17 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Two Weeks of a Kippo SSH Honeypot</title>
      <link>https://patrik.re/research-ssh-honeypot-honey-wss-sh-com/</link>
      <guid isPermaLink="true">https://patrik.re/research-ssh-honeypot-honey-wss-sh-com/</guid>
      <pubDate>Mon, 17 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>Results from two weeks of a Kippo SSH honeypot in November 2014: roughly 4,000 brute-force attempts, 2,500 distinct credential pairs, and a source distribution dominated by hosts in China.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
    <item>
      <title>PayPal Stored XSS via a Signup Flow Bypass</title>
      <link>https://patrik.re/bugbounty-paypal-stored-xss-security-bypass/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-paypal-stored-xss-security-bypass/</guid>
      <pubDate>Tue, 11 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>A stored XSS in PayPal&#39;s account name field, delivered to arbitrary users through invoices after bypassing the signup flow&#39;s security check by truncating the workflow URL to /webapps/.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>DOM XSS on PayPal&#39;s Main Domain</title>
      <link>https://patrik.re/bugbounty-paypal-dom-xss-main-domain/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-paypal-dom-xss-main-domain/</guid>
      <pubDate>Wed, 05 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>A payload placed in the URL fragment reached a DOM sink on PayPal&#39;s main domain and executed; PayPal closed the report as a duplicate.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>XSS in Google Tag Manager via JSON Import</title>
      <link>https://patrik.re/bugbounty-the-5000-google-xss/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-the-5000-google-xss/</guid>
      <pubDate>Fri, 31 Oct 2014 00:00:00 &#43;0000</pubDate>
      <description>Google Tag Manager validated macro names in the web UI but not in the JSON container import path, so a payload smuggled through a file upload executed and earned a $5,000 bounty.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Stored XSS in Three WordPress Chat Plugins</title>
      <link>https://patrik.re/wordpress-3x-vulnerable-chat-plugins-3/</link>
      <guid isPermaLink="true">https://patrik.re/wordpress-3x-vulnerable-chat-plugins-3/</guid>
      <pubDate>Thu, 02 Oct 2014 00:00:00 &#43;0000</pubDate>
      <description>WP Live Chat Support, MyLiveChat and Provide Support all accepted stored cross-site scripting during a 2014 customer install.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Chrome backslash URLs and XSS filter bypass</title>
      <link>https://patrik.re/google-chrome-security-multiple-leading-slashes-in-urls-may-confuse-some-server-side-xss-filters/</link>
      <guid isPermaLink="true">https://patrik.re/google-chrome-security-multiple-leading-slashes-in-urls-may-confuse-some-server-side-xss-filters/</guid>
      <pubDate>Tue, 17 Jun 2014 00:00:00 &#43;0000</pubDate>
      <description>Chrome resolves and executes a script URL written as http: followed by any number of backslashes. Firefox does not, and that difference can slip past pattern-matching XSS filters, closed by Chromium as wontfix.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Path Traversal on map.prezi.com ($1,000)</title>
      <link>https://patrik.re/bug-bounty-prezi-map-prezi-com-path-traversal/</link>
      <guid isPermaLink="true">https://patrik.re/bug-bounty-prezi-map-prezi-com-path-traversal/</guid>
      <pubDate>Wed, 21 May 2014 00:00:00 &#43;0000</pubDate>
      <description>A path traversal issue on Prezi&#39;s map.prezi.com subdomain, fixed within two days of reporting and rewarded with a $1,000 bounty.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Seven PayPal Bugs, Zero Bounties</title>
      <link>https://patrik.re/a-tale-of-7-vulnerabilities-paypal-bug-bounty/</link>
      <guid isPermaLink="true">https://patrik.re/a-tale-of-7-vulnerabilities-paypal-bug-bounty/</guid>
      <pubDate>Sun, 20 Apr 2014 00:00:00 &#43;0000</pubDate>
      <description>A 2014 run through PayPal&#39;s bug bounty scope: seven confirmed issues across paypal.com, financing.paypal.com, apps.paypal.com and the paypal-*.com family, all closed as duplicate or invalid.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
    <item>
      <title>160 German tax office sites vulnerable to XSS</title>
      <link>https://patrik.re/were-on-heise-german-found-160-sites-vulnerable-to-xss/</link>
      <guid isPermaLink="true">https://patrik.re/were-on-heise-german-found-160-sites-vulnerable-to-xss/</guid>
      <pubDate>Mon, 11 Nov 2013 00:00:00 &#43;0000</pubDate>
      <description>Reflected cross-site scripting across 160 German tax office websites, disclosed via heise.de and forwarded to CERT-Bund for coordinated remediation.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>PHP 5.3.3–5.3.6 socket_connect Bind Shell</title>
      <link>https://patrik.re/php-5-3-3-5-3-6-exploit-bind-shell/</link>
      <guid isPermaLink="true">https://patrik.re/php-5-3-3-5-3-6-exploit-bind-shell/</guid>
      <pubDate>Sat, 06 Jul 2013 00:00:00 &#43;0000</pubDate>
      <description>A public PHP 5.3.3-5.3.6 socket_connect exploit carrying a bind-TCP shell payload, dropped as an uploaded PHP file and located with an nmap sweep of ports 4000-4500.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
    <item>
      <title>SQL injection to root on a 2013 lab box</title>
      <link>https://patrik.re/from-nobody-to-root-advanced-sql-injection/</link>
      <guid isPermaLink="true">https://patrik.re/from-nobody-to-root-advanced-sql-injection/</guid>
      <pubDate>Tue, 07 May 2013 00:00:00 &#43;0000</pubDate>
      <description>Chaining a login-form SQL injection through sqlmap&#39;s --os-shell into a Linux 2.6.32 local root exploit to go from the &#39;nobody&#39; user to full control of the server.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Yahoo&#39;s /14 and an exposed phpinfo.php</title>
      <link>https://patrik.re/bugbounty-yahoo-phpinfo-php-disclosure/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-yahoo-phpinfo-php-disclosure/</guid>
      <pubDate>Sun, 20 Jan 2013 00:00:00 &#43;0000</pubDate>
      <description>Pivoting from Yahoo&#39;s main A record to its ARIN netblock and sweeping all 260,000 addresses in the /14 for an exposed phpinfo.php.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
  </channel>
</rss>
