Chaining file upload bypass and stored XSS to create admin accounts
Two medium-severity findings. No critical vulnerabilities anywhere in the report. And we created an admin account in the client’s application without anyone noticing. That’s the problem with scoring vulnerabilities in isolation. The target We were brought in to test a SaaS platform used by businesses for internal operations. Standard web app pen test, authenticated testing across multiple user roles, looking at the usual suspects: access controls, input validation, session management, business logic. ...
Fixing the Burp Suite clipboard crash on Hyprland
If you run Burp Suite on Hyprland, you might know this one already. Copy a request from Repeater, switch to Chromium to paste it into your notes, and Chrome just dies. No warning. No error dialog. Just gone. You end up running pkill -9 chromium, reopening it, restoring your tabs, and getting back to work. Then you copy from Burp again and it happens again. I put up with this for about three months before I sat down and actually fixed it. ...
AI Isn't Replacing Pentesters
I came across this thread on Reddit where someone was asking what they should be doing to survive the next few years in pen testing, given everything happening with AI. The replies were a mix of genuine advice and total doom-scrolling. It prompted me to write this because I keep hearing the same conversation. At conferences. On LinkedIn. In DMs. “Is AI going to replace us?” Short answer: no. But it is going to kill off a certain type of pentester, and honestly, good riddance. ...