Tag: Security
- M365 Internal Phish: Abusing the Power Platform for SharePoint/OneDrive Privilege Escalation (13 May 2022)
An internal phishing POC leveraging Microsoft 365 citizen development tools (Power Platform). Phish for access to a target user's OneDrive and all SharePoint sites they own. - Finding Vulnerabilities in an 18 Year Old MMO (12 Nov 2021)
Finding and abusing size constrained XSS and a payment gateway bypass in an 18 year old MMO.