Soroush Dalili
HomeBlogBug Bounty InvitesAdvisoriesContact

Notes & research

Blog

Application security, curious findings, and lessons from the details.

February 23, 2015

Non-Root-Relative Path Overwrite (RPO) in IIS and .Net applications

Read article
February 22, 2015

Analysis of setting cookies for third party websites in different browsers

Read article
August 9, 2014

IIS Short File Name Disclosure is back! Is your server vulnerable?

Read article
July 27, 2014

Upload a web.config File for Fun & Profit

Read article
July 23, 2014

File Upload and PHP on IIS: >=? and <=* and "=.

Read article
May 21, 2014

Even uploading a JPG file can lead to Cross-Site Content Hijacking (client-side attack)!

Read article
April 14, 2014

How did I bypass everything in modsecurity evasion challenge?

Read article
January 13, 2014

Catch-up on Flash XSS exploitation Part 3 – XSS by embedding a flash file

Read article
October 21, 2013

Yahoo bug bounty program – LFI reported and patched!

Read article
October 16, 2013

Catch-up on Flash XSS exploitation Part 2 – “navigateToURL” and “jar:” protocol!

Read article
Prev123456…8Next