Open in app

Sign in

Write

Sign in

Cristi Vlad
Cristi Vlad

1.5K followers

Home

About

RCE through Zip Unarchiving

In a recent pentest I found an interesting way to obtain remote code execution and eventually a reverse shell on the underlying system.

Mar 22
1
RCE through Zip Unarchiving
RCE through Zip Unarchiving
Mar 22
1

AIO Web App Pentesting Checklist

I’m testing the capabilities of NotebookLM for extracting valuable information from sources and I believe it can often do a much better job…

Oct 26, 2024
1
AIO Web App Pentesting Checklist
AIO Web App Pentesting Checklist
Oct 26, 2024
1

11 Pro Tips for OAuth 2.0 Pentesting

To build on the AI podcast based on RFC 6819 I recently posted, here are 11 specific tips for pentesters when dealing with OAuth 2.0:

Oct 7, 2024
11 Pro Tips for OAuth 2.0 Pentesting
11 Pro Tips for OAuth 2.0 Pentesting
Oct 7, 2024

Uncovering Critical Financial Bugs in a High-Profile Target - [A Pentester’s Diary]

In a recent pentest, I found multiple bugs that, if exploited by threat actors, could have caused significant financial damage.

Sep 11, 2024
Uncovering Critical Financial Bugs in a High-Profile Target - [A Pentester’s Diary]
Uncovering Critical Financial Bugs in a High-Profile Target - [A Pentester’s Diary]
Sep 11, 2024

Privilege Escalation to Admin through an Import Feature

I usually skip the introduction when posting a writeup because I don’t need to teach you what privesc or BOLA are, you can google that…

Apr 25, 2024
1
Privilege Escalation to Admin through an Import Feature
Privilege Escalation to Admin through an Import Feature
Apr 25, 2024
1

Account Takeover [It Looked Secure at First]

In a recent pentest for a client, I was going through the password reset flow. You know…

Feb 15, 2024
2
Account Takeover [It Looked Secure at First]
Account Takeover [It Looked Secure at First]
Feb 15, 2024
2

Account Takeover via Weak OTP

I seem to keep writing ATO posts here. I don’t mind. These are cool. Some are so easily discovered that it baffles me how persistent…

Nov 2, 2023
Created with AI technology.
Created with AI technology.
Nov 2, 2023

The Domino Effect: How Multiple Bugs Lead to Account Takeover

If you’ve spent sufficient time on a cybersecurity assignment so that the bigger picture falls into place, you know that some issues will…

Oct 13, 2023
The Domino Effect: How Multiple Bugs Lead to Account Takeover
The Domino Effect: How Multiple Bugs Lead to Account Takeover
Oct 13, 2023

Unauthenticated Massive PII Leak

This is probably the report that I’m most proud of. On top of that, it was the lengthiest I’ve ever written.

Sep 13, 2023
4
Unauthenticated Massive PII Leak
Unauthenticated Massive PII Leak
Sep 13, 2023
4

Account Takeover via Email Confirmation

It’s the second account takeover I’m finding on a client pentest in the span of a few days. I’m not sure wth is going on…

Jul 25, 2023
3
Account Takeover via Email Confirmation
Account Takeover via Email Confirmation
Jul 25, 2023
3
Cristi Vlad

Cristi Vlad

1.5K followers

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech