r0rshark Blog

Computer Security thoughts and Bug Hunting advises

Stealing OAuth tokens in Microsoft Web applications

Wide redirect_uri parameter in the OAuth process allows an attacker to leak the Facebook OAuth token and steal user private information

Written By
Lorenzo Fontana

Getting a shell on a Google Acquisition

Forgotten Wordpress blog could be exploited to get remote command execution on Adometry by Google server

Written By
Lorenzo Fontana

Making you sell what I want: Story of an Ebay XSS

Reflected XSS vulnerability could be leveraged to make the victim sell unwanted items

Written By
Lorenzo Fontana