How I stopped hunting on HackerOne after years because they stole my $50k. And so should you.You may have heard about Belarusian security researcher xnwup and the story of blocking his $25k on HackerOne. It was pretty resonant at…Jun 25, 202210Jun 25, 202210
Bug Bounty: Do You Need To Be A Programmer?Disclaimer: we are talking about the research of web applications only.Feb 23, 2022Feb 23, 2022
Published inSystem WeaknessWhat an injection into jQuery-selector can lead toI somehow came across a page with something like a user survey (the program is private, so I will speak abstractly).Feb 21, 20221Feb 21, 20221
I’ve made over $588k on Bug Bounty so farHow much one can earn on Bug Bounty?Feb 18, 20225Feb 18, 20225
Bug Bounty: Should You Go Full-Time?In the comments, I was asked what turned out to be more profitable in terms of money as a result — my previous job as a developer or…Feb 17, 20221Feb 17, 20221
How Did I Start Doing Bug Bounty?Since school, I have been reading Hacker (the Russian offensive security magazine) when I had the opportunity to buy it (then it was still…Feb 15, 2022Feb 15, 2022
Bug Bounty: Low Hanging FruitLow-hanging fruit are bugs that are very easy to find. I would divide them into 2 more types.Feb 15, 20221Feb 15, 20221
Неочевидное об XSS и HTML-энкодингеМногие знают о том, что перед тем, как получить значение атрибута тега, браузер декодирует HTML-сущности внутри. Скажем, если попытаться…Feb 15, 2022Feb 15, 2022
The Unobvious About XSS and HTML EncodingMany people know that before getting the value of a tag attribute, the browser decodes the HTML entities inside. Let’s say if you try to…Feb 14, 2022Feb 14, 2022
Improving the impact of a mouse-related XSS with styling and CSS-gadgetsI will write more about how I make PoCs in the future. But with special care, I work out scenarios for vulnerabilities that need user…Feb 12, 2022Feb 12, 2022
Bug Bounty: My First Five Figure PayoutThis is the post from my Telegram channel about Bug Bounty, where I share my experience and knowledge as well as just write about being…Feb 12, 20222Feb 12, 20222