corpus.blog
Most cited
Talked about
Blogs
41554 blogs · [ { "id": "01a087bd-a16f-739e-9fce-f8730fc0541d", "title": "Where was Mythos when WordPress fell?", "url": "https://patrik.re/where-was-mythos-when-wordpress-fell/", "published_at": "2026-08-04T22:30:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f8730fe05263", "title": "Jolokia endpoints: JNDI RCE and heap dumps", "url": "https://patrik.re/how-i-made-more-than-30k-with-jolokia-cves/", "published_at": "2020-06-16T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f8730ff6b613", "title": "Visual recon with Aquatone and WebScreenshot", "url": "https://patrik.re/visual-recon-a-beginners-guide/", "published_at": "2018-05-05T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87310566e18", "title": "Android certificate pinning bypass with Frida", "url": "https://patrik.re/the-stony-path-of-android--f0-9f-a4-96-bug-bounty-bypassing-certificate-pinning/", "published_at": "2017-10-21T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87310f04fe9", "title": ".htpasswd exposed, DES hash cracked", "url": "https://patrik.re/bugbounty-decoding-a--f0-9f-98-b1-00000-htpasswd-bounty/", "published_at": "2016-09-08T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87311ac19c9", "title": "Google Cloud Console: dormant stored XSS", "url": "https://patrik.re/bugbounty-sleeping-stored-google-xss-awakens-a-5000-bounty/", "published_at": "2016-05-17T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87311cf2850", "title": "Shopify POS firmware: extracting a root hash", "url": "https://patrik.re/digging-into-the-shopify-pos-firmware-part-1/", "published_at": "2015-10-09T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87312080927", "title": "Stop OS X Spotlight Leaking Your Location", "url": "https://patrik.re/research-stop-osx-spotlight-from-sending-your-location/", "published_at": "2015-06-15T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87312b007f1", "title": "XSS via XML File Upload on PayPal", "url": "https://patrik.re/bugbounty-papyal-xml-upload-cross-site-scripting-vulnerability/", "published_at": "2015-01-07T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87312bfca0f", "title": "PayPal merchant directory reflected XSS", "url": "https://patrik.re/bugbounty-reflected-cross-site-scripting-at-paypal-com/", "published_at": "2014-12-15T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87313970470", "title": "Hijacking a Prezi Subdomain Redirect ($500)", "url": "https://patrik.re/bugbounty-malicious-redirect-on-mailroom-prezi-com/", "published_at": "2014-12-10T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87314351e0c", "title": "BillMeLater: XSS Through a Style Attribute", "url": "https://patrik.re/bugbounty-reflected-cross-site-scripting-billmelater/", "published_at": "2014-11-17T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f8731439f482", "title": "Two Weeks of a Kippo SSH Honeypot", "url": "https://patrik.re/research-ssh-honeypot-honey-wss-sh-com/", "published_at": "2014-11-17T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f8731455a239", "title": "PayPal Stored XSS via a Signup Flow Bypass", "url": "https://patrik.re/bugbounty-paypal-stored-xss-security-bypass/", "published_at": "2014-11-11T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f873145683c4", "title": "DOM XSS on PayPal's Main Domain", "url": "https://patrik.re/bugbounty-paypal-dom-xss-main-domain/", "published_at": "2014-11-05T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87314832d28", "title": "XSS in Google Tag Manager via JSON Import", "url": "https://patrik.re/bugbounty-the-5000-google-xss/", "published_at": "2014-10-31T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f873148e1545", "title": "Stored XSS in Three WordPress Chat Plugins", "url": "https://patrik.re/wordpress-3x-vulnerable-chat-plugins-3/", "published_at": "2014-10-02T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f873152fb502", "title": "Chrome backslash URLs and XSS filter bypass", "url": "https://patrik.re/google-chrome-security-multiple-leading-slashes-in-urls-may-confuse-some-server-side-xss-filters/", "published_at": "2014-06-17T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f873162852dd", "title": "Path Traversal on map.prezi.com ($1,000)", "url": "https://patrik.re/bug-bounty-prezi-map-prezi-com-path-traversal/", "published_at": "2014-05-21T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87316db4a30", "title": "Seven PayPal Bugs, Zero Bounties", "url": "https://patrik.re/a-tale-of-7-vulnerabilities-paypal-bug-bounty/", "published_at": "2014-04-20T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f8731786bebe", "title": "160 German tax office sites vulnerable to XSS", "url": "https://patrik.re/were-on-heise-german-found-160-sites-vulnerable-to-xss/", "published_at": "2013-11-11T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f8731793b801", "title": "PHP 5.3.3–5.3.6 socket_connect Bind Shell", "url": "https://patrik.re/php-5-3-3-5-3-6-exploit-bind-shell/", "published_at": "2013-07-06T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87318178e88", "title": "SQL injection to root on a 2013 lab box", "url": "https://patrik.re/from-nobody-to-root-advanced-sql-injection/", "published_at": "2013-05-07T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f873186012f3", "title": "iTunes anti-debugging bypass with GDB and LLDB", "url": "https://patrik.re/itunes-exploit-development/", "published_at": "2013-03-10T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f87318690e6b", "title": "About", "url": "https://patrik.re/about/", "published_at": "2013-03-09T00:00:00+00:00" }, { "id": "01a087bd-a16f-739e-9fce-f8731910802b", "title": "Yahoo's /14 and an exposed phpinfo.php", "url": "https://patrik.re/bugbounty-yahoo-phpinfo-php-disclosure/", "published_at": "2013-01-20T00:00:00+00:00" } ] posts
Claim your blog
Back to patrik.re
Blog · corpus.blog/blogs/patrik.re/posts
patrik.re
patrik.re
2026
Where was Mythos when WordPress fell?
original ↗
4 Aug 2026
2020
Jolokia endpoints: JNDI RCE and heap dumps
original ↗
16 Jun 2020
2018
Visual recon with Aquatone and WebScreenshot
original ↗
5 May 2018
2017
Android certificate pinning bypass with Frida
original ↗
21 Oct 2017
2016
.htpasswd exposed, DES hash cracked
original ↗
8 Sept 2016
Google Cloud Console: dormant stored XSS
original ↗
17 May 2016
2015
Shopify POS firmware: extracting a root hash
original ↗
9 Oct 2015
Stop OS X Spotlight Leaking Your Location
original ↗
15 Jun 2015
XSS via XML File Upload on PayPal
original ↗
7 Jan 2015
2014
PayPal merchant directory reflected XSS
original ↗
15 Dec 2014
Hijacking a Prezi Subdomain Redirect ($500)
original ↗
10 Dec 2014
BillMeLater: XSS Through a Style Attribute
original ↗
17 Nov 2014
Two Weeks of a Kippo SSH Honeypot
original ↗
17 Nov 2014
PayPal Stored XSS via a Signup Flow Bypass
original ↗
11 Nov 2014
DOM XSS on PayPal's Main Domain
original ↗
5 Nov 2014
XSS in Google Tag Manager via JSON Import
original ↗
31 Oct 2014
Stored XSS in Three WordPress Chat Plugins
original ↗
2 Oct 2014
Chrome backslash URLs and XSS filter bypass
original ↗
17 Jun 2014
Path Traversal on map.prezi.com ($1,000)
original ↗
21 May 2014
Seven PayPal Bugs, Zero Bounties
original ↗
20 Apr 2014
2013
160 German tax office sites vulnerable to XSS
original ↗
11 Nov 2013
PHP 5.3.3–5.3.6 socket_connect Bind Shell
original ↗
6 Jul 2013
SQL injection to root on a 2013 lab box
original ↗
7 May 2013
iTunes anti-debugging bypass with GDB and LLDB
original ↗
10 Mar 2013
About
original ↗
9 Mar 2013
Yahoo's /14 and an exposed phpinfo.php
original ↗
20 Jan 2013