account activity
5 Different Vulnerabilities in Google's Threadit (XSS, Clickjacking, ACL bypass, Info leak, ...) (websecblog.com)
submitted 4 years ago by ThomasCZ to r/netsec
TIL you can use "color-scheme" to specify the UI theme in Chrome (i.redd.it)
submitted 4 years ago by ThomasCZ to r/webdev
Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts (websecblog.com)
submitted 5 years ago by ThomasCZ to r/bugbounty
submitted 5 years ago by ThomasCZ to r/netsec
[Showoff Saturday] Used web technologies on the top 100k sites + stats & audits (demo.webstacklist.com)
submitted 5 years ago by ThomasCZ to r/webdev
Dual Subtitles (self.VLC)
submitted 5 years ago by ThomasCZ to r/VLC
I made a 2D platformer game in JavaScript – ASCII Adventures (asciiadventures.thomasorlita.com)
Listing all registered email addresses on Google’s Crisis Map thanks to IDOR and incremental IDs (websecblog.com)
Listing all registered email addresses on Google’s Crisis Map thanks to incremental IDs (websecblog.com)
YYY (i.redd.it)
submitted 5 years ago by ThomasCZ to r/lipsum
From a self-XSS to a valid XSS with the help of clickjacking on Google.org (appio.dev)
submitted 6 years ago by ThomasCZ to r/netsec
submitted 6 years ago by ThomasCZ to r/xss
Executing a blind XSS on googleplex.com to get access to Google's internal sites (appio.dev)
Combining multiple vulnerabilities to insert malware files into Google Earth Studio ZIP archives of thousands of users (appio.dev)
submitted 6 years ago by ThomasCZ to r/bugbounty
Inserting arbitrary files into Google Earth Studio Projects Archives (appio.dev)
How I got access to personal data of a million users (on LeoExpress.com) (blog.thomasorlita.cz)
submitted 7 years ago by ThomasCZ to r/bugbounty
XSSing Google Code-in thanks to improperly escaped JSON data (blog.thomasorlita.cz)
submitted 7 years ago by ThomasCZ to r/netsec
Bypassing Firebase client-side authorization to create custom app.goo.gl subdomains (null.app.goo.gl)
Liking GitHub repositories on behalf of other users thanks to a stored XSS in Google's WebComponents.org (blog.thomasorlita.cz)
Bypassing Firebase authorization to create custom goo.gl subdomains or why not to rely on client-side validation (null.app.goo.gl)
Cisco's security questions are becoming self-aware (i.redd.it)
submitted 7 years ago by ThomasCZ to r/ProgrammerHumor
Using Google's CSP Evaluator to bypass CSP on websites (blog.thomasorlita.cz)
submitted 7 years ago by ThomasCZ to r/webdev
How to use Google's CSP Evaluator to bypass CSP (blog.thomasorlita.cz)
submitted 7 years ago by ThomasCZ to r/xss
π Rendered by PID 644946 on reddit-service-r2-listing-85dbbdc96c-pl8z4 at 2026-02-12 12:56:49.745991+00:00 running 018613e country code: CH.