PinnedPublished inInfoSec Write-upsRiding the Waves of API Versioning: Unmasking a Stored XSS Vulnerability, CSP Bypass Using YouTube…Hello, as some of you already know me, I’m Syed Mushfik Hasan Tahsin aka SMHTahsin33. And for those who doesn’t, I’m a 19 Y/O Cyber…Nov 14, 20231Nov 14, 20231
Published inInfoSec Write-upsBypassing Character Limit — XSS Using Spanned PayloadHello, I am Syed Mushfik Hasan Tahsin aka SMHTahsin33, an 18 Y/O Cyber Security Enthusiast from Bangladesh. I am into Infosec due to…Mar 15, 20231Mar 15, 20231
Published inInfoSec Write-upsStored XSS to Account Takeover : Going beyond document.cookie (Dumping IndexedDB)Stealing Session Information From IndexedDBAug 2, 20224Aug 2, 20224
My Experience With BugBountyHunt3r — Hands on Bug Bounty Hunting Learning PlatformHello, I’m Syed Mushfik Hasan Tahsin (@SMHTahsin33) , a Cyber Security Enthusiast from Bangladesh :)Apr 24, 2021Apr 24, 2021