Skip to content

The N45HT Blog

  • HOME
  • LEARNING
  • TOOLS
  • NEWS
  • RESEARCH
  • Reflected DOM-based XSS on DomaiNesia

    Reflected DOM-based XSS on DomaiNesia

    Choirur Rizal

    •

    April 30, 2021

    In this article, I’ll walk you through how I discovered a Reflected DOM-based Cross-site Scripting (XSS) vulnerability on…

  • Exploiting XSS via Markdown on Xiaomi

    Exploiting XSS via Markdown on Xiaomi

    Choirur Rizal

    •

    April 27, 2021

    Markdown is a popular text-to-HTML conversion tool, commonly used in forums and web platforms to create web content.…

  • N45HT Vulnerability Disclosure Program

    N45HT Vulnerability Disclosure Program

    XAdmin

    •

    April 25, 2021

    No technology is perfect, and N45HT believes that working with skilled security researchers across the globe is crucial…

  • Reflected XSS on Microsoft

    Reflected XSS on Microsoft

    Choirur Rizal

    •

    April 25, 2021

    During my recent bug bounty hunting, I started by gathering information on the Microsoft domain using a simple…

  • XSSR: An automatic XSS scanner

    XSSR: An automatic XSS scanner

    XAdmin

    •

    March 31, 2021

    Is an automatic Cross-site Scripting scanner application with Website, Chrome Extensions, and Windows Desktop platforms. Get in touch:

  • $300 Bounty for Exploiting DOM-based XSS

    $300 Bounty for Exploiting DOM-based XSS

    /dev/null

    •

    January 29, 2021

    While analyzing XING’s event management platform, I identified a reflected XSS vulnerability in the way event IDs are…

  • Reflected XSS on AT&T

    Reflected XSS on AT&T

    Choirur Rizal

    •

    July 17, 2020

    While performing a Google Dork search for potential vulnerabilities, I used the following query to target AT&T’s website:…

  • API: Subdomain Enumeration

    API: Subdomain Enumeration

    XAdmin

    •

    March 25, 2020

    Subdomain Enumeration is the process of finding sub-domains of a domain, this is an important phase in a…


←Previous Next→

Recent Posts

  • The CSS Backdoor Nobody Talks About
    Webmail clients like Gmail, Outlook, and Fastmail sanitize untrusted HTML/CSS… Read more: The CSS Backdoor Nobody Talks About
  • Critical Analysis of CVE-2026-50522: Microsoft SharePoint Remote Code Execution Vulnerability
    Microsoft SharePoint is one of the most widely used enterprise… Read more: Critical Analysis of CVE-2026-50522: Microsoft SharePoint Remote Code Execution Vulnerability
  • We’re Hiring: Python Cybersecurity Expert
    Hiring Status: Closed Applications for this position are no longer… Read more: We’re Hiring: Python Cybersecurity Expert
  • XSSR Pro is Now Available for Free
    We’re excited to announce that XSSR Pro is now available… Read more: XSSR Pro is Now Available for Free
  • Drupal CVE-2026-9082 Checker
    We recently created a small Python tool to detect CVE-2026-9082,… Read more: Drupal CVE-2026-9082 Checker

Social Media

  • Twitter
  • Instagram
  • LinkedIn
  • Facebook

Advertisement

Tags

API Bug Bounty Capture The Flag Command Injection Cross-site Scripting CSS CTF CVE-2026-9082 CVE-2026-50522 Drupal ExifTool HTML Information Disclosure JavaScript Markdown Microsoft SharePoint Open Redirection PHP SQL Injection VDP WAF Web Application Firewall XSS XSSR XSSRush

Connect With Us

  • Bali, Indonesia
  • [email protected]
  • Twitter
  • Instagram
  • Facebook

Categories

  • Learning
  • Tools
  • News
  • Research

N45HT

  • About
  • Contact
  • Products
  • Security

Search

Looking for something specific? Try a search below!

Copyright © 2023 | Made with love by SuperbThemes