Open in app

Sign In

Write

Sign In

Bend Theory
Bend Theory

247 Followers

Home

About

Nov 18, 2022

Remediation Archeology — Finding and Decoding an Ancient XSS

One of my favorite pastimes in Bug Bounty is reviewing my ancient (read: 2 or 3 years old) vulnerability reports. I feel like I’ve come a long way since then and can review old problems with a fresh perspective. One of these reports — an open redirect from June 2020…

Xss Attack

4 min read

Remediation Archeology — Finding and Decoding an Ancient XSS
Remediation Archeology — Finding and Decoding an Ancient XSS
Xss Attack

4 min read


May 21, 2021

Finding and Exploiting Unintended Functionality in Main Web App APIs

While hunting for bugs on Main Web Apps, I encounter tons of interesting APIs. Some are well secured, obscurely documented, and keep you in your lane despite attempts to poke and prod. Others are surprisingly open and fully exposed via JavaScript files — making them much more interesting targets! …

Bug Bounty

10 min read

Finding and Exploiting Unintended Functionality in Main Web App APIs
Finding and Exploiting Unintended Functionality in Main Web App APIs
Bug Bounty

10 min read


Apr 4, 2021

Journeys in Quoteless and Multi Reflection XSS

Cross Site Scripting is a tricky bug to fix and bypasses for these fixes can be even trickier. While there are several ways to remediate or prevent XSS, I want to focus on HTML Entity Encoding and the contextual pitfalls that can occur with this method. 9 times out of…

Bug Bounty

3 min read

Journeys in Quoteless and Multi Reflection XSS
Journeys in Quoteless and Multi Reflection XSS
Bug Bounty

3 min read

Bend Theory

Bend Theory

247 Followers

Hi! I'm Ben, a Web App Hacker, Bug Bounty Hunter, and Self-Taught Techno Entomologist

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech