Pinnedd0nut·Jan 29, 2022Eliminating Authorization Vulnerabilities with DacquiriDacquiri identifies and eliminates authorization vulnerabilities by turning them into compiler errors.
Ind0nut readsbyd0nut·Jun 10, 2020Week 3 — Real Talk on Real Number SystemsIn continuation of the philosophical and foundational nature of the book thus far, Chapter 3 opens with a discussion on kinds of numbers…
Ind0nut readsbyd0nut·May 27, 2020Week 1: The Road to RealityI love watching educational Youtube channels. It’s a great way to constantly expose myself to science and technology as I’ve always been…
d0nut·Apr 27, 2020Piercing the Veal: Short Stories to Read with FriendsIt’s been over a year and a half since I’ve started my bug bounty journey as a hacker. With years of experience triaging reports and…A response icon4A response icon4
d0nut·Aug 20, 2019Attacks on Applications of K-Anonymity — For the Rest of UsThree weeks ago I saw a blog post by fellow bug hunter, Jack Cable. The post both inspired and challenged me. The attack vector presented…
d0nut·Apr 11, 2019Better Exfiltration via HTML InjectionThis is a story about how I (re)discovered an exploitation technique and took a bug with fairly limited impact to a 5 digit bounty by…A response icon5A response icon5
d0nut·Sep 25, 20185 Tips Bug Bounty Programs *Want* You to Know AboutIf you’re not aware, I joined Dropbox’s security team last September. Since then, I’ve become very involved in the bug bounty community on…
InInfoSec Write-upsbyd0nut·Jul 25, 2018Exfiltration via CSS InjectionToday’s topic is something that’s already pretty well covered: CSS injections. I wanted to talk about my experience implementing this…A response icon2A response icon2