<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title></title>
    <link>/</link>
    <description>Recent content on </description>
    <generator>Hugo -- gohugo.io</generator>
    <lastBuildDate>Mon, 01 Sep 2025 00:00:00 +0000</lastBuildDate>
    
	<atom:link href="/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>Apex-Hunting 101: How to Expand Attack Surface by Finding Hidden Company Domains (Case Study)</title>
      <link>/blog-posts/apex-hunting-101/</link>
      <pubDate>Mon, 01 Sep 2025 00:00:00 +0000</pubDate>
      
      <guid>/blog-posts/apex-hunting-101/</guid>
      <description>Goal: turn a single target into a wide, defensible attack surface by discovering apex domains owned by the company, its acquisitions, and its sub-organizations—using only open sources.
 Great bugs often live just outside the obvious example.com. If you can map acquired brands and subsidiaries, you’ll uncover older tech stacks, forgotten portals, and regional sites that are still very much in scope for “wide-scope” programs.
Below is the exact recon playbook I use.</description>
    </item>
    
    <item>
      <title>Hacking the Chatbot: Leaking PII Data and Cancel any Order Unauthorizedly</title>
      <link>/blog-posts/hacking-chatbot-pii-data-leak/</link>
      <pubDate>Tue, 19 Aug 2025 00:00:00 +0000</pubDate>
      
      <guid>/blog-posts/hacking-chatbot-pii-data-leak/</guid>
      <description>During recon on a large e-commerce target, I landed upon a domain with a pretty interesting chatbot functionality. It could manage orders, process cancellations, and hand you off to a live agent. Even better (or worse), when you were logged in, the bot “helpfully” pulled up your recent orders. Cool! This was all I needed to take a close look.
To keep things realistic, I bought an item as a guest with an email I control — call it victim-me.</description>
    </item>
    
  </channel>
</rss>