Articles | Papers

How I Made an AI Steal Session Tokens for Me | Zero-Click Cross-Tenant ATO via LLM Output Rendering + IDOR

Paper

How I Made an AI Steal Session Tokens for Me | Zero-Click Cross-Tenant ATO via LLM Output Rendering + IDOR image
How I made a company’s own AI assistant steal its users’ session tokens, zero-click I want to tell you about the moment I realized I could make a company’s own AI assistant hand me its users’ sess...

The exploitation of a $$$$ SQL Injection Path Based

Paper

The exploitation of a $$$$ SQL Injection Path Based image
Here is how I exploited a unusual SQL Injection Path Based and got rewarded with bounty First of all, here are some sections that will be covered in this article, ┌───────────────Summary─────────...

How I g0t 4000$ for AWS Metadata Leak and Takeover $$

Paper

How I g0t 4000$ for AWS Metadata Leak and Takeover $$ image
Here is how I g0t $$ pwning AWS cloud of a bug bounty program at HackerOne First of all, we have some sections that will be covered in this article, ┌───────────────Summary────────────────┐ │ ...