56,966 blogs · [ { "id": "01a08748-7428-7199-8ee3-16eaf9e489c5", "title": "From Bug Bounty Hunter to Offensive Security Engineer Adventure (Short story and reflection)", "url": "http://blog.evanricafort.com/2025/03/from-bug-bounty-hunter-to-offensive.html", "published_at": "2025-03-27T17:09:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafa30eea3", "title": "pWning resources.gcash.com using HTTP PUT method enabled vulnerability (Write Up)", "url": "http://blog.evanricafort.com/2025/01/http-put-method-enabled-gcash.html", "published_at": "2025-01-30T16:57:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafa8bb4e3", "title": "WordPress TotalPoll Plugin Race Condition vulnerability (Write Up + AI generated blog)", "url": "http://blog.evanricafort.com/2023/05/i-asked-google-bard-ai-to-make-blog.html", "published_at": "2023-05-21T17:06:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafaabdc4a", "title": "IPv6 DNS Takeover via mitm6 (Write Up)", "url": "http://blog.evanricafort.com/2023/05/ipv6-dns-takeover-via-mitm6-write-up.html", "published_at": "2023-05-08T08:28:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafb0072af", "title": "Generate online votes using Race Condition Vulnerability in Woobox Web Application (Write Up)", "url": "http://blog.evanricafort.com/2021/06/generate-online-votes-using-race.html", "published_at": "2021-06-22T18:14:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafb47b916", "title": "HTML Injection and a dream in Google Chrome for Linux (Write Up)", "url": "http://blog.evanricafort.com/2021/06/html-injection-and-a-dream.html", "published_at": "2021-06-16T21:03:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafc392001", "title": "Unexpected IDOR Vulnerability in [REDACTED] - [redacted].net (Write Up)", "url": "http://blog.evanricafort.com/2021/06/2usd-idor-bug-in-redacted.html", "published_at": "2021-06-10T12:33:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafcaa236e", "title": "2FA Verification Bypass in Shapeshift [shapeshift.com] (Write Up)", "url": "http://blog.evanricafort.com/2021/05/2fa-verification-bypass-in-shapeshift.html", "published_at": "2021-05-10T08:40:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafd1b5b62", "title": "Hijacking Reset Password Link in https://www.niteflirt.com/ via Host Header Poisoning (Write Up)", "url": "http://blog.evanricafort.com/2021/02/hijacking-reset-password-link-in.html", "published_at": "2021-02-24T22:58:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafdc78b29", "title": "Changing other users Episode title & description - IDOR Vulnerability in [REDACTED] (Write Up)", "url": "http://blog.evanricafort.com/2021/02/idor-in-redacted.html", "published_at": "2021-02-12T20:01:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafe91dd7d", "title": "[CVE-2019-17674 & CVE-2020-11025] Stored XSS through navigation menu item edited in Customizer in Wordpress (Write Up)", "url": "http://blog.evanricafort.com/2020/12/cve-2019-17674-wordpress-stored-xss.html", "published_at": "2020-12-06T09:20:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafefb0253", "title": "XSS in Peerio 2 Windows Application (Write Up)", "url": "http://blog.evanricafort.com/2020/04/xss-in-peerio-2-windows-application.html", "published_at": "2020-04-23T18:39:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eaff97ac5e", "title": "Data Tampering Issue in Spot.im Application (Write Up)", "url": "http://blog.evanricafort.com/2020/02/data-tampering-issue-in-spotim.html", "published_at": "2020-02-18T18:36:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eafffb50b5", "title": "Popping Alerts in Mixmax Chrome Extension (Write Up)", "url": "http://blog.evanricafort.com/2020/02/popping-alerts-in-mixmax-chrome.html", "published_at": "2020-02-06T12:46:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eb00d4f75d", "title": "[Tutorial] Huawei Devices latest EMUI downgrade to bypass Google FRP", "url": "http://blog.evanricafort.com/2019/12/tutorial-huawei-devices-latest-emui.html", "published_at": "2019-12-08T20:42:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eb011ca1a1", "title": "HTML Injection to XSS bypass in [REDACTED.com]", "url": "http://blog.evanricafort.com/2019/12/html-injection-to-xss-bypass-in.html", "published_at": "2019-12-07T12:55:00+00:00" }, { "id": "01a08748-7428-7199-8ee3-16eb012a9be9", "title": "SSRF Vulnerability in https://app.[REDACTED].com", "url": "http://blog.evanricafort.com/2019/08/ssrf-vulnerability-in.html", "published_at": "2019-08-12T18:03:00+00:00" }, { "id": "01a08748-7429-7167-a63a-69b9015c225f", "title": "Application Level Denial of Service [DoS] using SVG file in https://[REDACTED].com (Write Up)", "url": "http://blog.evanricafort.com/2019/08/application-level-denial-of-service-dos.html", "published_at": "2019-08-10T10:45:00+00:00" }, { "id": "01a08748-7429-7167-a63a-69b902166da0", "title": "Read other user support tickets in https://support..com (Write Up)", "url": "http://blog.evanricafort.com/2019/08/read-other-user-support-tickets-in.html", "published_at": "2019-08-09T09:21:00+00:00" }, { "id": "01a08748-7429-7167-a63a-69b9030d7f2f", "title": "Disclose any main and 3rd party contributors email address and movie local path thru XML file in Plex TV - plex.tv (Write Up)", "url": "http://blog.evanricafort.com/2019/07/business-logic-plex-tv.html", "published_at": "2019-07-24T02:46:00+00:00" }, { "id": "01a08748-7429-7167-a63a-69b90349abca", "title": "Not a fancy bug, just HTML Injection in Clause - clause.io (Write Up)", "url": "http://blog.evanricafort.com/2019/07/html-injection-in-clause-email.html", "published_at": "2019-07-21T07:10:00+00:00" }, { "id": "01a08748-7429-7167-a63a-69b903fc3075", "title": "Blind-XSS in Chrome Experiments - Google (Write Up)", "url": "http://blog.evanricafort.com/2018/08/blind-xss-in-chrome-experiments-google.html", "published_at": "2018-08-03T04:40:00+00:00" }, { "id": "01a08748-7429-7167-a63a-69b90495803d", "title": "[RCE] Remote Code Execution in Wordpress iOS Application (version 9.3)", "url": "http://blog.evanricafort.com/2018/02/rce-remote-code-execution-in-wordpress.html", "published_at": "2018-02-21T15:52:00+00:00" }, { "id": "01a08748-7429-7167-a63a-69b90501a454", "title": "2016 Year in Review", "url": "http://blog.evanricafort.com/2016/12/2016-year-in-review.html", "published_at": "2016-12-04T18:35:00+00:00" }, { "id": "01a08748-7429-7167-a63a-69b905174431", "title": "XSS Vulnerability in Twitter [https://twitter.com] (Write Up)", "url": "http://blog.evanricafort.com/2016/09/xss-vulnerability-in-twitter.html", "published_at": "2016-09-26T00:06:00+00:00" } ] posts Claim your blog
Back to blog.evanricafort.com
Blog · corpus.blog/blogs/blog.evanricafort.com/posts

blog.evanricafort.com

blog.evanricafort.com

2025

2023

2021

2020

2019

2018

2016