<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://zhero-web-sec.github.io/thoughts/bugbounty-feedback-strategy-and-alchemy</loc>
<lastmod>2025-06-30T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/thoughts/draft-of-a-night-walk-the-diagnosis-of-a-researchers-quest-for-success</loc>
<lastmod>2026-01-24T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/dos-via-cache-poisoning/</loc>
<lastmod>2023-05-17T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/xss-intigriti-challenge-0523/</loc>
<lastmod>2023-05-30T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/cache-deception-to-csrf/</loc>
<lastmod>2023-10-25T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/ctf-intigriti-0825/</loc>
<lastmod>2025-08-26T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/waf-as-a-weapon-and-dos-as-a-bullet</loc>
<lastmod>2024-05-28T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/nextjs-and-cache-poisoning-a-quest-for-the-black-hole</loc>
<lastmod>2024-06-24T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir</loc>
<lastmod>2025-01-21T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/nuxt-show-me-your-payload</loc>
<lastmod>2025-03-03T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware</loc>
<lastmod>2025-03-18T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/react-router-and-the-remixed-path</loc>
<lastmod>2025-04-01T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/pre-render-data-spoofing-and-cpdos-on-react-router</loc>
<lastmod>2025-04-25T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/eclipse-on-nextjs-conditioned-exploitation-of-an-intended-race-condition</loc>
<lastmod>2025-05-06T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/nextjs-cache-poisoning-to-dos-via-a-204-response</loc>
<lastmod>2025-07-04T00:00:00-07:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/astro-framework-and-standards-weaponization</loc>
<lastmod>2025-11-05T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/unlocking-reflected-xss-in-the-astro-framework</loc>
<lastmod>2025-11-18T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/avoiding-the-paradox-a-native-full-read-ssrf-and-oneshot-dos-in-sveltekit</loc>
<lastmod>2026-01-16T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/talks/2012-03-01-talk-1</loc>
<lastmod>2012-03-01T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/talks/2013-03-01-tutorial-1</loc>
<lastmod>2013-03-01T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/talks/2014-02-01-talk-2</loc>
<lastmod>2014-02-01T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/talks/2014-03-01-talk-3</loc>
<lastmod>2014-03-01T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/teaching/2014-spring-teaching-1</loc>
<lastmod>2014-01-01T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/teaching/2015-spring-teaching-1</loc>
<lastmod>2015-01-01T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/teaching/2015-spring-teaching-1</loc>
<lastmod>2015-01-01T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/teaching/2015-spring-teaching-1</loc>
<lastmod>2015-01-01T00:00:00-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/archive-layout-with-content/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/categories/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/collection-archive/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/cv/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/zhero/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/non-menu-page/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/page-archive/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/thoughts/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/research-and-things/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/sitemap/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/tags/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/talkmap.html</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/talks/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/teaching/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/terms/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/writeups/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/markdown_generator/</loc>
</url>
<url>
<loc>https://zhero-web-sec.github.io/files/paper1.pdf</loc>
<lastmod>2026-02-11T13:37:01-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/files/paper2.pdf</loc>
<lastmod>2026-02-11T13:37:01-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/files/paper3.pdf</loc>
<lastmod>2026-02-11T13:37:01-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/files/slides1.pdf</loc>
<lastmod>2026-02-11T13:37:01-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/files/slides2.pdf</loc>
<lastmod>2026-02-11T13:37:01-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/files/slides3.pdf</loc>
<lastmod>2026-02-11T13:37:01-08:00</lastmod>
</url>
<url>
<loc>https://zhero-web-sec.github.io/talkmap/map.html</loc>
<lastmod>2026-02-11T13:37:01-08:00</lastmod>
</url>
</urlset>
