Chaining Bugs to Steal Yahoo Contacts!

👨🏻‍💻 Introduction & Background:

This is a write-up of how I chained two vulnerabilities (an XSS and a CORS misconfiguration) that allowed me to steal contacts from a victim’s contact book. This data included: names,...

SQL Injection in

🔎 Introduction & Background

        To get started, I’ll give a bit of backstory behind this. I found this bug back in January of 2017 and was one of the first reports I made to...

Tricky CORS Bypass in Yahoo! View

Recently, HackerOne hosted their second Hack The World competition. During this time I decided to take a look at Yahoo’s bug bounty program because I have heard good things about them and also due to...

