Soroush Dalili
HomeBlogBug Bounty InvitesAdvisoriesContact

Notes & research

Blog

Application security, curious findings, and lessons from the details.

June 12, 2012

“ASPXErrorPath in URL” Technique in Scanning a .Net Web Application

Read article
June 11, 2012

SecProject Web AppSec Challenge Series 1 Results

Read article
April 30, 2012

SecProject Web AppSec Challenge – Series 1

Read article
April 10, 2012

Sometimes no Ninja skill is required to receive money from security bug bounty programs!

Read article
December 31, 2011

Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames)

Read article
March 9, 2011

Flash ExternalInterface.call() JavaScript Injection – can make the websites vulnerable to XSS

Read article
January 23, 2011

Unrestricted File Download V1.0 – Windows Server

Read article
December 19, 2010

Facebook Redirect Link – New Bypass Method – “:/” after the domain name

Read article
December 19, 2010

JSReg Bypasses – OLD

Read article
December 18, 2010

A Dotty Salty Directory: A Secret Place in NTFS for Secret Files!

Read article
Prev1…45678Next