WRITEUPS

Writeups

Breakdowns of findings from bug bounty programs and private research. I publish after the vendor ships a fix and the program clears me to talk. Nothing here is live.

2026-07XSS
Reflected XSS and Account Takeover: How I Got Paid for a Duplicate in Bug Bounty

An encoding bypass on a redirect endpoint plus a non-HttpOnly session cookie let one crafted link hijack a victim's account, balance included.