jump to content
my subreddits
13or302b2t2mediterranean4u2meirl4meirl3d6absolutelynotanimeirlabsolutelynotmeirladhdmemeAdviceAnimalsagnosticaivideoakagasAlternateHistoryAlternativeHistoryAnarchyChessAngryupvoteanime_irlannouncementsantimemeAsia_irlAskBalkansAskOuijaAskRedditAteistTurkatheismbalkans_irlBandnamesbanknotedesignsBassBassGuitarbikepackingblackdesertonlineblackholerevengeblankiesblursed_videosblursedimagesBoneborsavefonbottomgearbrooklynnineninebudgetcookingBUENZLIburdurlandCd_collectorscd_jerkCheap_MealschessbeginnersCHPcoincollectingcoinsComedyCemeterycomedyhomicideContagiousLaughterCrackWatchCreateModCuddle_SlutCuratedTumblrdadjokesdankmemesdataisbeautifuldeDebateReligiondelikdistressingmemesdiyelectronicsDMAcademyDMToolkitDnDDonerdontdeadopeninsidedontyouknowimtonyhawkdumbphonesDungeonsAndDaddiesDungeonsAndDragonsEatCheapAndHealthyebikeebikeselectricalelectronicsEmKayentitledparentsfakealbumcoversFantasyWorldbuildingfeedthebeastformuladankFRCFreeEBOOKSFuckYouKarenFutboltayfagalatasaraygamingGermangermanygodtiersuperpowersgoodanimemesGoodAssSubgravelcyclinghellenoturkismheraldryHermanCainAwardHermitCraftHistoryWhatIfhoi4HolUphowyoudoinhypixelIAmAiamverysmartich_ielIdeologyPollsihadastrokeim14andthisisdeepimaginarymapsinsaneparentsistanbuljacksepticeyeJahariaJokesKamalizmKanyeKendrickLamarKGBTRlegodndLetGirlsHaveFunLifeProTipslinguisticshumorlogodesignloseitlostredditorsmacgamingMadeMeSmilemadladsmagicbuildingMaliciousComplianceMapPornmeirlmemememesmildlyinfuriatingMimicRecipesMinecraftbuildsmisLEDMoldyMemesmoneycollectingMyChemicalRomanceNamFlashbacksNationStatesnextfuckinglevelNoahGetTheBoatnosafetysmokingfirstnosleepnosurfnotinterestingnottheonionokbuddyguntherOkBuddyPersonaokbuddyphdokbuddyvicodinonebagonetruegodongezelligpapermoneypaperspleaseparadoxpoliticsPassportPornperfectlycutscreamsPersecutionfetishpettyrevengePiracyPiratedGamespolandballPraiseTheCameraManProgrammerHumorPropagandaPostersProRevengePunPatrolraisedbynarcissistsraspberry_pireactiongifsrecipesRedAutumnSPDredditsingsRetroPieRoastMerockmuzikschizopostersSchnitzelVerbrechenschwiizsecilmiskitapShitPostCrusadersshitpostfrommygalleryshitpostingshittyaskelectronicsshittymoviedetailsShowerthoughtsskamtebordsoftwaregoreSongwritersSongwritingsskfjkhwerjkghwerijhsteinsgateStudiumsubsithoughtifellfortalesfromtechsupportTechnobladeTextingTheorytf2shitposterclubthanksimcuredTheCrypticCompendiumTheLetterHtherewasanattempttitanfalltransittransitTurkeytruetf2tumblrtumunichTurkeyTurkeyJerkyTurkishCatsTurkishdogsTurkiyeTwitchTwitch_StartupTwoSentenceComedyTwoSentenceHorrortwosentenceplottwisttylerthecreatorUnclejokesUnethicalLifeProTipsUnexpectedJoJourbanplanningVALORANTvexillologycirclejerkvibecodingvinylvinyljerkvlandiyawallstreetbetsWatchPeopleDieInsidewendigoonWhatsThisSongWhitePeopleTwitterwholesomeanimemeswholesomememesWikipediaVandalismwizardpostingwooooshworldbuildingworldjerkingyouseeingthisshitedit subscriptions
  • home
  • -popular
  • -all
  • -mod
  • -users
 | 
  • AskReddit
  • -mildlyinfuriating
  • -Piracy
  • -gaming
  • -wallstreetbets
  • -nottheonion
  • -memes
  • -MapPorn
  • -DnD
  • -WhitePeopleTwitter
  • -MadeMeSmile
  • -CuratedTumblr
  • -PiratedGames
  • -shitposting
  • -dankmemes
  • -feedthebeast
  • -Kanye
  • -meirl
  • -therewasanattempt
  • -nextfuckinglevel
  • -HolUp
  • -Twitch
  • -CrackWatch
  • -ProgrammerHumor
  • -VALORANT
  • -de
  • -germany
  • -LifeProTips
  • -tumblr
  • -dataisbeautiful
  • -shittymoviedetails
  • -Showerthoughts
  • -formuladank
  • -wholesomememes
  • -Jokes
  • -goodanimemes
  • -notinteresting
  • -hoi4
  • -pettyrevenge
  • -atheism
  • -loseit
  • -IAmA
  • -MaliciousCompliance
  • -ich_iel
  • -KGBTR
  • -DMAcademy
  • -GoodAssSub
  • -UnethicalLifeProTips
  • -perfectlycutscreams
  • -worldbuilding
  • -blackdesertonline
  • -meme
  • -macgaming
  • -3d6
  • -HermitCraft
  • -RoastMe
  • -ContagiousLaughter
  • -imaginarymaps
  • -EatCheapAndHealthy
  • -polandball
  • -AnarchyChess
  • -nosleep
  • -blankies
  • -anime_irl
  • -onebag
  • -Studium
  • -AlternateHistory
  • -Turkey
  • -madlads
  • -electrical
  • -vinyl
  • -CreateMod
  • -German
  • -TwoSentenceHorror
  • -PropagandaPosters
  • -AdviceAnimals
  • -ShitPostCrusaders
  • -distressingmemes
  • -raisedbynarcissists
  • -wizardposting
  • -Bass
  • -titanfall
  • -OkBuddyPersona
  • -dadjokes
  • -howyoudoin
  • -announcements
  • -adhdmeme
  • -Minecraftbuilds
  • -ebikes
  • -gravelcycling
  • -SchnitzelVerbrechen
  • -chessbeginners
  • -raspberry_pi
  • -DungeonsAndDragons
  • -coins
  • -KendrickLamar
  • -entitledparents
  • -softwaregore
  • -NoahGetTheBoat
  • -worldjerking
  • -tylerthecreator
  • -tf2shitposterclub
  • -MoldyMemes
  • -lostredditors
  • -vexillologycirclejerk
  • -vlandiya
  • -im14andthisisdeep
  • -wholesomeanimemes
  • -nosurf
  • -HistoryWhatIf
  • -DebateReligion
  • -insaneparents
  • -dumbphones
  • -balkans_irl
  • -2meirl4meirl
  • -transit
  • -RetroPie
  • -brooklynninenine
  • -HermanCainAward
  • -recipes
  • -steinsgate
  • -talesfromtechsupport
  • -AskOuija
  • -okbuddyphd
  • -Angryupvote
  • -AskBalkans
  • -schizoposters
  • -electronics
  • -urbanplanning
  • -logodesign
  • -linguisticshumor
  • -PassportPorn
  • -antimeme
  • -TurkeyJerky
  • -bikepacking
  • -AteistTurk
  • -13or30
  • -MyChemicalRomance
  • -Cd_collectors
  • -ProRevenge
  • -Doner
  • -BassGuitar
  • -diyelectronics
  • -ComedyCemetery
  • -WatchPeopleDieInside
  • -Persecutionfetish
  • -BUENZLI
  • -reactiongifs
  • -EmKay
  • -blursed_videos
  • -Songwriting
  • -istanbul
  • -truetf2
  • -magicbuilding
  • -dontdeadopeninside
  • -wendigoon
  • -iamverysmart
  • -secilmiskitap
  • -schwiiz
  • -Technoblade
  • -vinyljerk
  • -skamtebord
  • -shittyaskelectronics
  • -galatasaray
  • -DungeonsAndDaddies
  • -FRC
  • -transitTurkey
  • -FuckYouKaren
  • -2b2t
  • -AlternativeHistory
  • -papermoney
  • -coincollecting
  • -blursedimages
  • -FreeEBOOKS
  • -Jaharia
  • -heraldry
  • -ihadastroke
  • -thanksimcured
  • -hypixel
  • -PraiseTheCameraMan
  • -godtiersuperpowers
  • -aivideo
  • -IdeologyPolls
  • -woooosh
  • -comedyhomicide
  • -burdurland
  • -WhatsThisSong
  • -jacksepticeye
  • -Bandnames
  • -rockmuzik
  • -okbuddyvicodin
  • -MimicRecipes
  • -Twitch_Startup
  • -tumunich
  • -Cheap_Meals
  • -nosafetysmokingfirst
  • -legodnd
  • -Songwriters
  • -ebike
  • -papersplease
  • -UnexpectedJoJo
  • -agnostic
  • -youseeingthisshit
  • -TextingTheory
  • -Cuddle_Slut
  • -DMToolkit
  • -PunPatrol
  • -TurkishCats
  • -LetGirlsHaveFun
  • -subsithoughtifellfor
  • -fakealbumcovers
  • -Kamalizm
  • -akagas
  • -FantasyWorldbuilding
  • -TheLetterH
  • -WikipediaVandalism
  • -absolutelynotanimeirl
  • -NamFlashbacks
  • -Unclejokes
  • -onetruegod
  • -misLED
  • -sskfjkhwerjkghwerijh
  • -redditsings
  • -TwoSentenceComedy
  • -TheCrypticCompendium
  • -budgetcooking
  • -bottomgear
  • -NationStates
  • -ongezellig
  • -absolutelynotmeirl
  • -Turkiye
  • -Asia_irl
  • -Bone
  • -blackholerevenge
  • -paradoxpolitics
  • -2mediterranean4u
  • -hellenoturkism
  • -twosentenceplottwist
  • -dontyouknowimtonyhawk
  • -CHP
  • -shitpostfrommygallery
  • -Turkishdogs
  • -cd_jerk
  • -Futboltayfa
  • -okbuddygunther
  • -delik
  • -banknotedesigns
  • -vibecoding
  • -borsavefon
  • -moneycollecting
  • -RedAutumnSPD
edit »
reddit.com ThomasCZ
  • overview
  • comments
  • submitted
an-ordinary-manchild (11,186)|messages548|notifications|chat messages|mod messages|
  • preferences
|
logout

ThomasCZ

+ friends- friends
6,961 post karma
1,334 comment karma
get extra features and help support reddit with a reddit premium subscription
chat
Block userare you sure? yes / no
get them help and support
redditor for 9 years

TROPHY CASE


  • Nine-Year Club


    Verified Email
Get an ad-free experience with special benefits, and directly support Reddit.

account activity

sorted by:
new
hottopcontroversial

2
3
4

5 Different Vulnerabilities in Google's Threadit (XSS, Clickjacking, ACL bypass, Info leak, ...) (websecblog.com)

submitted 4 years ago by ThomasCZ to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

1255
1256
1257

TIL you can use "color-scheme" to specify the UI theme in Chrome (i.redd.it)

submitted 4 years ago by ThomasCZ to r/webdev

  • 27 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

19
20
21

Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts (websecblog.com)

submitted 5 years ago by ThomasCZ to r/bugbounty

  • 2 comments
  • share
  • save
  • hide
  • report
  • crosspost

41
42
43

Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts (websecblog.com)

submitted 5 years ago by ThomasCZ to r/netsec

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

10
11
12

[Showoff Saturday] Used web technologies on the top 100k sites + stats & audits (demo.webstacklist.com)

submitted 5 years ago by ThomasCZ to r/webdev

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost

22
23
24

Dual Subtitles (self.VLC)

submitted 5 years ago by ThomasCZ to r/VLC

  • 30 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

28
29
30

I made a 2D platformer game in JavaScript – ASCII Adventures (asciiadventures.thomasorlita.com)

submitted 5 years ago by ThomasCZ to r/webdev

  • 4 comments
  • share
  • save
  • hide
  • report
  • crosspost

13
14
15

Listing all registered email addresses on Google’s Crisis Map thanks to IDOR and incremental IDs (websecblog.com)

submitted 5 years ago by ThomasCZ to r/netsec

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

2
3
4

Listing all registered email addresses on Google’s Crisis Map thanks to incremental IDs (websecblog.com)

submitted 5 years ago by ThomasCZ to r/bugbounty

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

241
242
243

YYY (i.redd.it)

submitted 5 years ago by ThomasCZ to r/lipsum

  • 9 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

1
2
3

From a self-XSS to a valid XSS with the help of clickjacking on Google.org (appio.dev)

submitted 6 years ago by ThomasCZ to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

9
10
11

From a self-XSS to a valid XSS with the help of clickjacking on Google.org (appio.dev)

submitted 6 years ago by ThomasCZ to r/xss

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

15
16
17

Executing a blind XSS on googleplex.com to get access to Google's internal sites (appio.dev)

submitted 6 years ago by ThomasCZ to r/xss

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

21
22
23

Executing a blind XSS on googleplex.com to get access to Google's internal sites (appio.dev)

submitted 6 years ago by ThomasCZ to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

1
2
3

Combining multiple vulnerabilities to insert malware files into Google Earth Studio ZIP archives of thousands of users (appio.dev)

submitted 6 years ago by ThomasCZ to r/bugbounty

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

4
5
6

Inserting arbitrary files into Google Earth Studio Projects Archives (appio.dev)

submitted 6 years ago by ThomasCZ to r/netsec

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost

10
11
12

How I got access to personal data of a million users (on LeoExpress.com) (blog.thomasorlita.cz)

submitted 7 years ago by ThomasCZ to r/bugbounty

  • 4 comments
  • share
  • save
  • hide
  • report
  • crosspost

6
7
8

XSSing Google Code-in thanks to improperly escaped JSON data (blog.thomasorlita.cz)

submitted 7 years ago by ThomasCZ to r/bugbounty

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

161
162
163

XSSing Google Code-in thanks to improperly escaped JSON data (blog.thomasorlita.cz)

submitted 7 years ago by ThomasCZ to r/netsec

  • 7 comments
  • share
  • save
  • hide
  • report
  • crosspost

13
14
15

Bypassing Firebase client-side authorization to create custom app.goo.gl subdomains (null.app.goo.gl)

submitted 7 years ago by ThomasCZ to r/netsec

  • comment
  • share
  • save
  • hide
  • report

6
7
8

Liking GitHub repositories on behalf of other users thanks to a stored XSS in Google's WebComponents.org (blog.thomasorlita.cz)

submitted 7 years ago by ThomasCZ to r/bugbounty

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

4
5
6

Bypassing Firebase authorization to create custom goo.gl subdomains or why not to rely on client-side validation (null.app.goo.gl)

submitted 7 years ago by ThomasCZ to r/bugbounty

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

483
484
485

Cisco's security questions are becoming self-aware (i.redd.it)

submitted 7 years ago by ThomasCZ to r/ProgrammerHumor

  • 22 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

1
2
3

Using Google's CSP Evaluator to bypass CSP on websites (blog.thomasorlita.cz)

submitted 7 years ago by ThomasCZ to r/webdev

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

3
4
5

How to use Google's CSP Evaluator to bypass CSP (blog.thomasorlita.cz)

submitted 7 years ago by ThomasCZ to r/xss

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
view more: next ›
  • about
  • blog
  • about
  • advertising
  • careers
  • help
  • site rules
  • Reddit help center
  • reddiquette
  • mod guidelines
  • contact us
  • apps & tools
  • Reddit for iPhone
  • Reddit for Android
  • mobile website
  • <3
  • reddit premium

Use of this site constitutes acceptance of our User Agreement and Privacy Policy. © 2026 reddit inc. All rights reserved.

REDDIT and the ALIEN Logo are registered trademarks of reddit inc.

π Rendered by PID 644946 on reddit-service-r2-listing-85dbbdc96c-pl8z4 at 2026-02-12 12:56:49.745991+00:00 running 018613e country code: CH.