Soroush Dalili
HomeBlogBug Bounty InvitesAdvisoriesContact

Notes & research

Blog

Application security, curious findings, and lessons from the details.

October 7, 2013

Catch-up on Flash XSS exploitation – bypassing the guardians! – Part 1

Read article
September 28, 2013

Simple Security Tip: window.location = window.location.pathname can cause Open-Redirect issue!

Read article
April 26, 2013

Microsoft XMLDOM in IE can divulge information of local drive/network in error messages – XXE

Read article
March 19, 2013

IE/Firefox Redirection Issue – FB Oauth2 Bypass – BugCrowd

Read article
November 28, 2012

File in the hole! – HackPra slides

Read article
November 12, 2012

XSS by uploading/including a SWF file

Read article
October 18, 2012

Don’t trust a string based on TryParse or IsNumeric result! (.Net/VBScript)

Read article
August 14, 2012

IE9 Self-XSS Blackbox Protection bypass

Read article
June 30, 2012

Microsoft IIS tilde character “~” Vulnerability/Feature – Short File/Folder Name Disclosure

Read article
June 20, 2012

Browsers Anti-XSS methods in ASP (classic) have been defeated!

Read article
Prev1…345678Next