Jon Bottarini
Just another security blog — bug bounty writeups and security research.
Writeups
Don’t Reply: A Clever Phishing Method In Apple’s Mail App
About four or five years ago, friend and fellow bug bounty hunter Sam Curry asked if I had “ever thought about what was possible to load inside an <img> tag, besides an image“.
Using Burp Suite match and replace settings to escalate your user privileges and find hidden features
On May 14th, Lew Cirne, the CEO of New Relic, announced a new platform called New Relic One.
Get as image function pulls any Insights/NRQL data from any New Relic account (IDOR)
This writeup walks you through the full process as to how I found a pretty bad Insecure Direct Object Reference (IDOR) in New Relic.
Abusing internal API to achieve IDOR in New Relic
I recently found a nice insecure direct object reference (IDOR) in New Relic which allowed me to pull data from other user accounts, and I thought it was worthy of writing up because it might make you think twice about the types (and the sheer number!)
Inspect Element leads to Stripe Account Lockout Authentication Bypass
A common thing I see happening with many popular applications is that a developer will disable an HTML element through the “class” attribute.
XSS vulns galore (plus a cool shirt!)
When PornHub launched their public bug bounty program, I was pretty sure that most of the low hanging fruits of vulnerabilities would be taken care of and already reported.
Discovering a stored XSS that affects over 900k websites (CVE-2016-9751)
In my free time when I’m not hunting for bugs in paid programs, I like to contribute a bit to the open-source community and check for vulnerabilities that might arise.
Bypassing Apple’s iOS 10 Restrictions Settings – Twice
By default, Apple has a feature that allows all of their iOS devices to be assigned restrictions, so that employees and mostly children cannot access naughty websites and other types of less-desirable content.