Bypassing a WAF with parser differentials
2026-02How inconsistent request parsing between a CDN and origin let a blocked payload slip through.
Chaining IDOR and a race condition for account takeover
2025-11A timing window in a password-reset flow turned a low-severity IDOR into full ATO.
Story of SQL Injections on One Program (Bugcrowd)
2021-04A bug bounty story of finding multiple SQL injections across Informix and IBM DB2 databases, and bypassing the WAF with sqlmap tamper scripts.