Tuesday, 17 December 2013

helpouts.google.com Reflected (XSS)

PoC


 and google security team  reward me $3133.7  :D

and got  listed in their HOF


thanks google security team  <3

Thursday, 12 December 2013

Third bug telekom.com "Reflected XSS"

PoC

the Bug valid by Telecom  security team  and fixed now , Their reply :


Wednesday, 11 December 2013

one from telekom.de highly sensitive services vulnerable to persistent xss

i've reported  critical bug to telekom.de , one from more  highly sensitive service

i got this reply




then i got listed in the their hall of fame


Ironically the vulnerability still not fixed , i don't know what happened , for this reason i didn't publish the POC

Saturday, 30 November 2013

Sunday, 24 November 2013

lanyrd.com (XSS)

i reported bug to heroku.com they say and they say that this vulnerable of "lanyrd.com" website


so i decide to reported to you . and their reply



 POC:
 the bug  fixed now :)

Thursday, 21 November 2013

spendbitcoins.com (XSS)

POC

i've already reported the bug and  got their  reply :/


the bug steel unfixed 

Tuesday, 19 November 2013