PinnedKreSec·Apr 29, 2024Hackerone got hacked! How can I steal your POC? 🥷🏻Story of my experience how to get critical bugs directly upstream (Hackerone) as a bug bounty platform.A response icon6A response icon6
KreSec·May 3IDOR Vulnerability Despite Non-Enumerable Object IdentifiersWhat happens when a SaaS page-builder platform allows anyone to delete pages from any user — even when it already uses random…A response icon1A response icon1
KreSec·Apr 25[$1K] From LFI to Full Cloud Takeover: How a Path Traversal Exposed an Entire Kubernetes ClusterTL;DR I discovered a Path Traversal (LFI) vulnerability on [REDACTED] (results by nuclei btw). This single bug allowed me to exfiltrate a…A response icon1A response icon1
KreSec·Sep 11, 2025Reducing the manual process of looking for XSS with dursgo/dalfox/nuclei.Let’s look at how the traditional (manual) method and the automated approach work for identifying vulnerabilities.
KreSec·Dec 22, 2024Reflected XSS bypass WAF & Page notfoundIt was hard for me to finally bypass this.A response icon3A response icon3
KreSec·Oct 6, 2023From exam to hackingThe story begins with an error message that inspires me to do some hacking (SQL-I, RCE, Source Code Exposed, Privilege escalation).
KreSec·Sep 18, 2023One-click Account Takeover & IDOR leaks all user informationThe story of how I took over someone's account by resetting their password.
KreSec·Sep 16, 2023Subdomain takeover via teamwork.comExploiting Subdomain Takeover Vulnerabilities via teamwork.com
KreSec·Sep 12, 2023Introduction & How to use vulnshot.com 🪲If you need to manage the Nuclei CLI output which was previously only limited to chat lines on Telegram, Discord, and others, with VulnShot…
KreSec·Sep 9, 2023Subdomain takeover via Frill.coExploiting subdomain takeover via Frill (A Customer feedback, Roadmap and Announcements tool).A response icon1A response icon1