
Stealing OAuth tokens of connected Microsoft accounts via open redirect in Harvest App
Oct 21, 2023Reported an OAuth token leak via open redirect in Harvest.
Security Researcher and Software Developer
Welcome to eval.blog! Here I publish my research, technical papers, projects, and insights on systems programming, security, and artificial intelligence.

Reported an OAuth token leak via open redirect in Harvest.

AppSec Village DEF CON 31 CTF^2 (developer) winning entry. Bypassed the encryption and mutation techniques of the Mutant …

Reported CVE-2021-27902 (XSS) and CVE-2021-27903 (SSTI) that can be chained together to gain Remote Code Execution in …

Exploring prompt injection techniques to extract hidden system prompts from popular AI wrappers and chatbots.

How to use unit testing frameworks like xUnit for automated vulnerability scanning and exploit development.

Why data URLs are a powerful alternative to hosted JavaScript files for XSS testing and payload delivery.