<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>cat ~/footstep.ninja/blog.txt</title><link>https://footstep.ninja/</link><description>Recent content on cat ~/footstep.ninja/blog.txt</description><generator>Hugo -- gohugo.io</generator><copyright>Copyright &amp;copy; 2020 - Shuaib Oladigbolu</copyright><lastBuildDate>Sat, 29 Dec 2018 00:00:00 +0000</lastBuildDate><atom:link href="https://footstep.ninja/index.xml" rel="self" type="application/rss+xml"/><item><title>About Me</title><link>https://footstep.ninja/about/</link><pubDate>Sat, 29 Dec 2018 00:00:00 +0000</pubDate><guid>https://footstep.ninja/about/</guid><description>Shuaib Oladigbolu is a CS student at Ladoke Akintola University of Technology and also a bug bounty hunter who helps companies secure their online assets.</description></item><item><title>Hall of Fame</title><link>https://footstep.ninja/hof/</link><pubDate>Sat, 29 Dec 2018 00:00:00 +0000</pubDate><guid>https://footstep.ninja/hof/</guid><description> HackerOne</description></item><item><title>Exploiting HTML Injection in Email</title><link>https://footstep.ninja/posts/html-injection-in-email/</link><pubDate>Tue, 31 Dec 2019 22:21:09 +0100</pubDate><guid>https://footstep.ninja/posts/html-injection-in-email/</guid><description>Sequel to my last post, I’ll be discussing about HTML injection on the same target. HTMLi is a vulnerability that can be exploited in any application that renders HTML code; email happens to be one.</description></item><item><title>Story of an IDOR via HTTP</title><link>https://footstep.ninja/posts/idor-via-http/</link><pubDate>Tue, 31 Dec 2019 19:44:37 +0100</pubDate><guid>https://footstep.ninja/posts/idor-via-http/</guid><description>Oh! Yea, HTTP is the most common channel you could find an Insecure Direct Object Reference (IDOR) Vulnerability (IMO). I should call this an IDOR series, hahah!</description></item><item><title>Exploiting a Self Stored XSS with an IDOR</title><link>https://footstep.ninja/posts/exploiting-self-xss/</link><pubDate>Tue, 31 Dec 2019 18:47:43 +0100</pubDate><guid>https://footstep.ninja/posts/exploiting-self-xss/</guid><description>In this post, I’ll be talking about an interesting bug chain I discovered a few months ago; Stored XSS + IDOR (Cross Site Scripting and Insecure Direct Object Reference respectively).</description></item><item><title>IDOR via Websockets</title><link>https://footstep.ninja/posts/idor-via-websockets/</link><pubDate>Sat, 23 Nov 2019 09:23:23 +0100</pubDate><guid>https://footstep.ninja/posts/idor-via-websockets/</guid><description>In my previous post, I shared my love for testing Insecure Direct Object Reference (IDOR) vulnerability. This time I’ll be sharing the situation where I found an IDOR in Websockets.</description></item><item><title>My Struggle with Websockets Testing</title><link>https://footstep.ninja/posts/websockets-testing/</link><pubDate>Sat, 23 Nov 2019 08:47:02 +0100</pubDate><guid>https://footstep.ninja/posts/websockets-testing/</guid><description>Until a few months ago, I have only dealt with HTTP(S) endpoints. Then there was an application I was testing which I couldn’t figure out how it communicated to the server even though I am always logging every request with Burp Suite.</description></item><item><title>Story of an IDOR via Email</title><link>https://footstep.ninja/posts/idor-via-email/</link><pubDate>Mon, 29 Jul 2019 07:08:31 +0100</pubDate><guid>https://footstep.ninja/posts/idor-via-email/</guid><description>A year ago, I discovered an Insecure Direct Object Reference (IDOR) vulnerability which allowed anyone to reply to messages on behalf of other users on a website.</description></item><item><title>How I built my blog from scratch with Hugo, Github, and Netlify</title><link>https://footstep.ninja/posts/blog-documentation/</link><pubDate>Thu, 25 Jul 2019 10:48:39 +0100</pubDate><guid>https://footstep.ninja/posts/blog-documentation/</guid><description>Hello everyone! I&amp;rsquo;m going to document the steps involved in setting up this blog so anyone can also pick it up as a guide when they want to do the same.</description></item><item><title>Tale of a Misconfiguration in Password Reset</title><link>https://footstep.ninja/posts/password-reset/</link><pubDate>Sun, 30 Dec 2018 07:46:08 +0100</pubDate><guid>https://footstep.ninja/posts/password-reset/</guid><description>This post is about a misconfiguration in password reset I found on a popular help desk software sometimes ago where they were leaking the reset token.</description></item><item><title>Hacken Cup 2018 CTF Walkthrough</title><link>https://footstep.ninja/posts/hacken-cup/</link><pubDate>Sat, 29 Dec 2018 19:57:19 +0100</pubDate><guid>https://footstep.ninja/posts/hacken-cup/</guid><description>I&amp;rsquo;ve got this down since the CTF and saw a few writeups on the same. Then I thought why not share my approach too :D</description></item><item><title>Hello World</title><link>https://footstep.ninja/posts/hello-world/</link><pubDate>Sat, 29 Dec 2018 19:47:31 +0100</pubDate><guid>https://footstep.ninja/posts/hello-world/</guid><description>Hello World!
Yay! Finally, I made a blog.
So, exactly a year ago today, I made a list of goals for this year, 2018.</description></item></channel></rss>