JSEC1065 - Coindrawer Non-persistent XSS disclosure (Buy/sell orders feature, cancel_order param)

Read more

JSEC1053 - Coindrawer Provide Arbitrary Exchange Rate disclosure

Read more

NotSoSecure's 2nd SQLiLab CTF writeup

This year’s Easter weekend featured NotSoSecure’s 2nd SQLiLab CTF event. The contest promised two flags to capture, and lasted about 72 hours (it ended up being extended due to some muppet’s DNS DoS attack against the game). Let’s capture some flags.
Read more

JSEC1051 - Coindrawer Payment Replay Disclosure, Create Multiple Merchant Orders

Read more

JSEC1046 - Coindrawer Persistent DOM XSS disclosure (Paycoin feature)

Read more

Coindrawer Bug Bounty Experience

Read more

Heartbleed by proxy

Read more