Sitemap
A list of all the posts and pages found on the site. For you robots out there is an XML version available for digesting as well.
Pages
Posts
A web cache deception chained to a CSRF, the recipe
Published:
Recently, I received a bounty for a vulnerability discovered on an e-commerce site allowing the personal information — including the delivery address — of a user to be changed. Let’s talk about it!
XSS Intigriti challenge 0523
Published:
Let me explain how did I overcome this XSS challenge set up by the bug bounty platform Intigriti. It may be a source of inspiration for some of you during your research.
DOS via cache poisoning on Mozilla
Published:
Let’s take a closer look at how cache poisoning works and how I was able to exploit this vulnerability to get a DOS on the home page of a large company.
A successful prototype pollution chained to a DOM XSS
Published:
Today I decided to share with you my last little discovery and to explain a little more in detail how prototype pollution work.
portfolio
Bug bounty, feedback, strategy and alchemy
Published:
Honey attracts bees, and like many others who occasionally share moments of success, I often get asked recurring questions about bug bounty hunting: how I got started, what advice I’d give, what roadmap to follow, and so on. I figured it might be worthwhile to put some of my thoughts, experiences, and perspectives into writing for anyone curious about the subject.
publications
WAF as a weapon and DOS as a bullet
Published in zhero_web_security, 2024
Next.js and cache poisoning: a quest for the black hole
Published in zhero_web_security, 2024
CVE-2024-XXXX
Next.js, cache, and chains: the stale elixir
Published in zhero_web_security, 2025
CVE-2024-46982
Nuxt, show me your payload - a basic CP DoS
Published in zhero_web_security, 2025
CVE-2025-27415
Next.js and the corrupt middleware: the authorizing artifact
Published in zhero_web_security, 2025
CVE-2025-29927
React Router and the Remix’ed path
Published in zhero_web_security, 2025
CVE-2025-31137
React-Router : Pre-render data spoofing + CPDoS (no research paper)
Published in zhero_web_security, 2025
CVE-2025-43865 + CVE-2025-43864
Eclipse on Next.js: Conditioned exploitation of an intended race-condition
Published in zhero_web_security, 2025
CVE-2025-32421
Next.js : Cache Poisoning to DoS via a 204 response (no research paper)
Published in zhero_web_security, 2025
CVE-2025-49826
talks
Talk 1 on Relevant Topic in Your Field
Published:
This is a description of your talk, which is a markdown files that can be all markdown-ified like any other post. Yay markdown!
Conference Proceeding talk 3 on Relevant Topic in Your Field
Published:
This is a description of your conference proceedings talk, note the different field in type. You can put anything in this field.
teaching
Teaching experience 1
Undergraduate course, University 1, Department, 2014
This is a description of a teaching experience. You can use markdown like any other post.
Teaching experience 2
Workshop, University 1, Department, 2015
This is a description of a teaching experience. You can use markdown like any other post.
Teaching experience 2
Workshop, University 1, Department, 2015
This is a description of a teaching experience. You can use markdown like any other post.
Teaching experience 2
Workshop, University 1, Department, 2015
This is a description of a teaching experience. You can use markdown like any other post.