41554 blogs · [ { "id": "01a0bb91-dedd-71d0-966c-b25cfd247c58", "title": "Attacking GraphQL APIs (OWASP PNW 2024)", "url": "https://mazinahmed.net/blog/attacking-graphql-apis-owasp-pnw-2024/", "published_at": "2026-09-16T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ea387763", "title": "Backlog: A Local-First Task and Context Manager for Humans and AI", "url": "https://mazinahmed.net/blog/backlog-project/", "published_at": "2026-07-07T11:28:35+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9eadf36de", "title": "The GitHub Breach Through VS Code Is the One I Warned About", "url": "https://mazinahmed.net/blog/github-vscode-breach/", "published_at": "2026-05-22T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9eb95a6cc", "title": "Compromising Developers with Malicious Extensions - VS Code, Cursor AI, and the Backdoor You Didn't See Coming", "url": "https://mazinahmed.net/blog/publishing-malicious-vscode-extensions/", "published_at": "2025-12-06T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ec8ccaf2", "title": "Preventing Prompt Injection Attacks at Scale", "url": "https://mazinahmed.net/blog/preventing-prompt-injection-attacks-at-scale/", "published_at": "2025-06-09T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9eca4dbc8", "title": "Introducing LLMQuery Framework: Scaling GenAI Automation with Prompt Templates", "url": "https://mazinahmed.net/blog/llmquery-project/", "published_at": "2025-01-13T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ed7f90dc", "title": "Engineering Learnings from the CrowdStrike Falcon Outage", "url": "https://mazinahmed.net/blog/crowdstrike-incident-engineering-learnings/", "published_at": "2024-07-26T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ee3e15a0", "title": "Secrets Patterns DB: Building Open-Source Regex Database for Secret Detection", "url": "https://mazinahmed.net/blog/secrets-patterns-db/", "published_at": "2023-02-07T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ee935302", "title": "Speaking at BlackHat MEA 2022", "url": "https://mazinahmed.net/blog/speaking-at-blackhat-mea-2022/", "published_at": "2022-12-05T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ef09ed56", "title": "DoS Attacks are Dead: Demystifying Practical DoS Attacks", "url": "https://mazinahmed.net/blog/demystfying-practical-dos-attacks-talk/", "published_at": "2022-12-04T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ef40c41b", "title": "Shennina Framework - Automating Host Exploitation with AI", "url": "https://mazinahmed.net/blog/shennina-exploitation-framework/", "published_at": "2022-11-08T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ef5c0863", "title": "Scan Terraform plans and changes with tfquery, an SQL-powered framework", "url": "https://mazinahmed.net/blog/tfplan-release/", "published_at": "2022-10-27T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ef9d9077", "title": "Twitch Internal Security Tools: In-depth Analysis of the Leaked Twitch Security Tools", "url": "https://mazinahmed.net/blog/indepth-analysis-twitch-security-tools/", "published_at": "2022-06-01T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f060f6ae", "title": "Attacking Modern Environments Series: Attack Vectors on Terraform Environments", "url": "https://mazinahmed.net/blog/attacking-terraform-environments/", "published_at": "2022-01-29T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f14e18ac", "title": "Interview With the AppSec Podcast: Terraform Security", "url": "https://mazinahmed.net/blog/interview-with-appsec-podcast-terraform-security/", "published_at": "2021-10-17T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f1a59891", "title": "tfquery: Run SQL queries on your Terraform infrastructure", "url": "https://mazinahmed.net/blog/tfquery-project-release/", "published_at": "2021-04-28T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f2077be0", "title": "DDoS is not Dead: Building a Scalable DDoS Framework", "url": "https://mazinahmed.net/blog/stressful-ddos-framework/", "published_at": "2021-04-13T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f214f12c", "title": "Interview with Sectastic Podcast: How I started, What is FullHunt, and How are Security Startups in the GCC Region", "url": "https://mazinahmed.net/blog/interview-with-sectastic-podcast/", "published_at": "2021-03-22T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f2542351", "title": "Hacking Zoom: Uncovering Tales of Security Vulnerabilities in Zoom", "url": "https://mazinahmed.net/blog/hacking-zoom/", "published_at": "2020-08-09T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f340d164", "title": "Bad Marketing: COVID-19 and Cyber Security", "url": "https://mazinahmed.net/blog/covid19-and-cybersecurity/", "published_at": "2020-04-14T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f352054f", "title": "The Path for Testing Path Traversal Vulnerabilities with Python", "url": "https://mazinahmed.net/blog/testing-for-path-traversal-with-python/", "published_at": "2020-04-12T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f3a45178", "title": "OhMyZsh dotenv Remote Code Execution", "url": "https://mazinahmed.net/blog/ohmyzsh-dotenv-rce/", "published_at": "2020-04-08T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f3fc1406", "title": "Book Review: WASEC by Alessandro Nadalin", "url": "https://mazinahmed.net/blog/wasec-book-review/", "published_at": "2020-03-29T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f4bc733a", "title": "Practical Approaches for Testing and Breaking JWT Authentication", "url": "https://mazinahmed.net/blog/breaking-jwt/", "published_at": "2019-10-25T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f4f1189b", "title": "Search Engine Abuse in Popular Social Networks", "url": "https://mazinahmed.net/blog/search-engine-abuse-in-popular-social-networks/", "published_at": "2019-05-17T12:03:11+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f4f79d34", "title": "[Research] Overview of the Application-Level Security of the Swiss E-voting System", "url": "https://mazinahmed.net/blog/swiss-evoting-system-security/", "published_at": "2019-04-16T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f55b4634", "title": "Backchannel Leaks on Strict Content-Security Policy", "url": "https://mazinahmed.net/blog/backchannel-leaks-on-strict-csp-policy/", "published_at": "2019-01-18T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f613cab2", "title": "Practical Protection Against DNS Rebinding Attacks", "url": "https://mazinahmed.net/blog/practical-protection-against-dns-rebinding-attacks/", "published_at": "2018-07-31T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f6190ca8", "title": "Creating an Emojis PHP Webshell", "url": "https://mazinahmed.net/blog/creating-emojis-php-webshell/", "published_at": "2018-07-23T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f6ff3639", "title": "Using HTML Attribute Separators for Bypassing WAF XSS Filters", "url": "https://mazinahmed.net/blog/html-attribute-separators/", "published_at": "2018-07-17T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f7aa8a35", "title": "Bypassing CSP by Abusing JSONP Endpoints", "url": "https://mazinahmed.net/blog/bypassing-csp-by-abusing-jsonp-endpoints/", "published_at": "2018-01-16T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f8005963", "title": "[Book Review] ModSecurity Handbook - 2nd Edition", "url": "https://mazinahmed.net/blog/modsecurity-handbook-2nd-edition-review/", "published_at": "2017-10-03T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f8327f12", "title": "Starting in InfoSec - 101", "url": "https://mazinahmed.net/blog/starting-in-infosec-101/", "published_at": "2017-08-11T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f865f103", "title": "Using Ubuntu .DESKTOP as a Malware Vector", "url": "https://mazinahmed.net/blog/using-ubuntu-desktop-as-malware-vector/", "published_at": "2017-04-08T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f8a46d50", "title": "Exploiting Misconfigured Apache server-status Instances with server-status_PWN", "url": "https://mazinahmed.net/blog/exploiting-misconfigured-apache-server-status-instances/", "published_at": "2017-01-13T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f8f2d86f", "title": "Bug Bounty Hunting - Swiss Cyber Storm 2016", "url": "https://mazinahmed.net/blog/bug-bounty-hunting-swiss-cyber-storm/", "published_at": "2016-10-23T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9f9cde0ca", "title": "Backup-File Artifacts: The Underrated Web-Danger", "url": "https://mazinahmed.net/blog/backup-file-artifacts/", "published_at": "2016-08-18T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fa5362e3", "title": "Google UI-Redressing Bug That Discloses the User's Email Address", "url": "https://mazinahmed.net/blog/google-ui-redressing-bug-that-discloses-email-addresses/", "published_at": "2016-04-08T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fb52111c", "title": "Bypassing NoScript Security Suite Using Cross-Site Scripting and MITM Attacks", "url": "https://mazinahmed.net/blog/bypassing-noscript-security-suite/", "published_at": "2016-03-17T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fb7ac51a", "title": "Why Prebuilt Security Browsers are Bad: Introducing Firefox Security Toolkit", "url": "https://mazinahmed.net/blog/firefox-security-toolkit/", "published_at": "2015-11-03T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fba23ce3", "title": "Evading All Web-Application Firewalls XSS Filters", "url": "https://mazinahmed.net/blog/evading-all-web-application-firewalls/", "published_at": "2015-09-09T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fc469bf4", "title": "Bypassing Google Password Alert with One Line of Code", "url": "https://mazinahmed.net/blog/bypassing-google-password-alert/", "published_at": "2015-07-25T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fd44d94e", "title": "Facebook Messenger Multiple CSRF Vulnerabilities", "url": "https://mazinahmed.net/blog/facebook-messenger-multiple-csrf/", "published_at": "2015-06-09T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fdc42474", "title": "Summary of HSTS Support in Modern Browsers", "url": "https://mazinahmed.net/blog/summary-of-hsts-support-in-modern-browsers/", "published_at": "2015-05-29T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fe1a03e5", "title": "My Experience with eBay Bug Bounty Program", "url": "https://mazinahmed.net/blog/my-experience-with-ebay-bug-bounty/", "published_at": "2015-04-24T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9fee5f279", "title": "W3 Total Cache's W3TotalFail Vulnerability That Leads to Full Defacement (CVE-2014-9414)", "url": "https://mazinahmed.net/blog/w3-total-fail/", "published_at": "2014-12-11T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25a9ffc0557a", "title": "Session Hijacking in Instagram Mobile App via MITM Attack [0-DAY]", "url": "https://mazinahmed.net/blog/session-hijacking-in-instagram-mobile/", "published_at": "2014-07-26T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25aa005d913c", "title": "My Story with Onavo (Acquired by Facebook)", "url": "https://mazinahmed.net/blog/my-story-with-onavo/", "published_at": "2014-06-09T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25aa00c20736", "title": "Cross-Site Scripting on WikiLeaks", "url": "https://mazinahmed.net/blog/cross-site-scripting-on-wikileaks/", "published_at": "2014-02-19T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25aa01448c36", "title": "PHP Code Execution on Bugcrowd", "url": "https://mazinahmed.net/blog/code-execution-on-bugcrowd/", "published_at": "2014-02-13T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25aa018a3df0", "title": "Acknowledged By Oracle", "url": "https://mazinahmed.net/blog/acknowledged-by-oracle/", "published_at": "2014-02-06T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25aa01e2ded0", "title": "Open Redirector on Google.com", "url": "https://mazinahmed.net/blog/open-redirector-on-google/", "published_at": "2014-02-06T00:00:00+00:00" }, { "id": "01a087a3-062b-71ed-b503-25aa02d7e936", "title": "SQL Injection and Cross-site Scripting at the website of the University of Calgary", "url": "https://mazinahmed.net/blog/university-of-calgary/", "published_at": "2014-02-06T00:00:00+00:00" } ] posts Claim your blog
Back to mazinahmed.net
Blog · corpus.blog/blogs/mazinahmed.net/posts

mazinahmed.net

mazinahmed.net

2026

2025

2024

2023

2022

2021

2020

2019

2018

2017

2016

2015

2014