Open in app

Sign in

Write

Sign in

Cristi Vlad
Cristi Vlad

1.3K Followers

Home

About

Cristi Vlad

Cristi Vlad

AIO Web App Pentesting Checklist

I’m testing the capabilities of NotebookLM for extracting valuable information from sources and I believe it can often do a much better job…

Oct 26
AIO Web App Pentesting Checklist
AIO Web App Pentesting Checklist
Oct 26
Cristi Vlad

Cristi Vlad

11 Pro Tips for OAuth 2.0 Pentesting

To build on the AI podcast based on RFC 6819 I recently posted, here are 11 specific tips for pentesters when dealing with OAuth 2.0:

Oct 7
11 Pro Tips for OAuth 2.0 Pentesting
11 Pro Tips for OAuth 2.0 Pentesting
Oct 7
Cristi Vlad

Cristi Vlad

Uncovering Critical Financial Bugs in a High-Profile Target - [A Pentester’s Diary]

In a recent pentest, I found multiple bugs that, if exploited by threat actors, could have caused significant financial damage.

Sep 11
Uncovering Critical Financial Bugs in a High-Profile Target - [A Pentester’s Diary]
Uncovering Critical Financial Bugs in a High-Profile Target - [A Pentester’s Diary]
Sep 11
Cristi Vlad

Cristi Vlad

Privilege Escalation to Admin through an Import Feature

I usually skip the introduction when posting a writeup because I don’t need to teach you what privesc or BOLA are, you can google that…

Apr 25
1
Privilege Escalation to Admin through an Import Feature
Privilege Escalation to Admin through an Import Feature
Apr 25
1
Cristi Vlad

Cristi Vlad

Account Takeover [It Looked Secure at First]

In a recent pentest for a client, I was going through the password reset flow. You know…

Feb 15
2
Account Takeover [It Looked Secure at First]
Account Takeover [It Looked Secure at First]
Feb 15
2
Cristi Vlad

Cristi Vlad

Account Takeover via Weak OTP

I seem to keep writing ATO posts here. I don’t mind. These are cool. Some are so easily discovered that it baffles me how persistent…

Nov 2, 2023
Created with AI technology.
Created with AI technology.
Nov 2, 2023
Cristi Vlad

Cristi Vlad

The Domino Effect: How Multiple Bugs Lead to Account Takeover

If you’ve spent sufficient time on a cybersecurity assignment so that the bigger picture falls into place, you know that some issues will…

Oct 13, 2023
The Domino Effect: How Multiple Bugs Lead to Account Takeover
The Domino Effect: How Multiple Bugs Lead to Account Takeover
Oct 13, 2023
Cristi Vlad

Cristi Vlad

Unauthenticated Massive PII Leak

This is probably the report that I’m most proud of. On top of that, it was the lengthiest I’ve ever written.

Sep 13, 2023
4
Unauthenticated Massive PII Leak
Unauthenticated Massive PII Leak
Sep 13, 2023
4
Cristi Vlad

Cristi Vlad

Account Takeover via Email Confirmation

It’s the second account takeover I’m finding on a client pentest in the span of a few days. I’m not sure wth is going on…

Jul 25, 2023
3
Account Takeover via Email Confirmation
Account Takeover via Email Confirmation
Jul 25, 2023
3
Cristi Vlad

Cristi Vlad

Account (of the CEO) Takeover via Password Reset

In a web app pentest for a client, I found this interesting account takeover and I thought of sharing my findings with the infosec…

Jul 10, 2023
1
Account (of the CEO) Takeover via Password Reset
Account (of the CEO) Takeover via Password Reset
Jul 10, 2023
1
Cristi Vlad

Cristi Vlad

1.3K Followers

Help

Status

About

Careers

Press

Blog

Privacy

Terms

Text to speech

Teams