Cristi Vlad·Mar 22, 2025RCE through Zip UnarchivingIn a recent pentest I found an interesting way to obtain remote code execution and eventually a reverse shell on the underlying system.A response icon1A response icon1
Cristi Vlad·Oct 26, 2024AIO Web App Pentesting ChecklistI’m testing the capabilities of NotebookLM for extracting valuable information from sources and I believe it can often do a much better job…A response icon1A response icon1
Cristi Vlad·Oct 7, 202411 Pro Tips for OAuth 2.0 PentestingTo build on the AI podcast based on RFC 6819 I recently posted, here are 11 specific tips for pentesters when dealing with OAuth 2.0:
Cristi Vlad·Sep 11, 2024Uncovering Critical Financial Bugs in a High-Profile Target - [A Pentester’s Diary]In a recent pentest, I found multiple bugs that, if exploited by threat actors, could have caused significant financial damage.
Cristi Vlad·Apr 25, 2024Privilege Escalation to Admin through an Import FeatureI usually skip the introduction when posting a writeup because I don’t need to teach you what privesc or BOLA are, you can google that…A response icon1A response icon1
Cristi Vlad·Feb 15, 2024Account Takeover [It Looked Secure at First]In a recent pentest for a client, I was going through the password reset flow. You know…A response icon2A response icon2
Cristi Vlad·Nov 2, 2023Account Takeover via Weak OTPI seem to keep writing ATO posts here. I don’t mind. These are cool. Some are so easily discovered that it baffles me how persistent…
Cristi Vlad·Oct 13, 2023The Domino Effect: How Multiple Bugs Lead to Account TakeoverIf you’ve spent sufficient time on a cybersecurity assignment so that the bigger picture falls into place, you know that some issues will…
Cristi Vlad·Sep 13, 2023Unauthenticated Massive PII LeakThis is probably the report that I’m most proud of. On top of that, it was the lengthiest I’ve ever written.A response icon4A response icon4
Cristi Vlad·Jul 25, 2023Account Takeover via Email ConfirmationIt’s the second account takeover I’m finding on a client pentest in the span of a few days. I’m not sure wth is going on…A response icon3A response icon3