May 9, 2023, 6:39 p.m. | M7arm4n

InfoSec Write-ups - Medium infosecwriteups.com

Discovering XSS in large companies is one of my hobbies. Today I want to talk about Opera XSS which took 15 minutes. The power of finding XSS so fast is searching out-of-the-box endpoints. To do this, you first need to find a list of all subdomains, even the ones that don’t give you results (404, 403, etc.). And then find all old existing or recently added endpoints.

Choosing the domain I’m going to work on is usually graded based on …

bug bounty hunting infosec security xss-attack

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Open-Source Intelligence (OSINT) Policy Analyst (TS/SCI)

@ WWC Global | Reston, Virginia, United States

Security Architect (DevSecOps)

@ EUROPEAN DYNAMICS | Brussels, Brussels, Belgium

Infrastructure Security Architect

@ Ørsted | Kuala Lumpur, MY

Contract Penetration Tester

@ Evolve Security | United States - Remote

Senior Penetration Tester

@ DigitalOcean | Canada