0xAzoz@ubuntu:~$

/0xAzoz

Bug Bounty Hunter • Web Security Researcher

Latest Write-ups

💉 Command Injection in Move File Function Allows Reading Server Files (HTB) cover

💉 Command Injection in Move File Function Allows Reading Server Files (HTB)

A bypass technique that abuses third-party OAuth misconfigurations to disable 2FA protection.

OAuth2FAAuthentication
2025-05-07 3 min read
Read More
🛡️ Remote Code Execution via File Upload (HTB) cover

🛡️ Remote Code Execution via File Upload (HTB)

A Remote Code Execution (RCE) vulnerability was discovered on the file upload feature

File upload attackRCE
2025-05-08 3 min read
Read More
 🍬 HTB CTF: CandyVault – NoSQL Login Bypass cover

🍬 HTB CTF: CandyVault – NoSQL Login Bypass

A fun MongoDB NoSQL login bypass on a Flask app from Hack The Box's CandyVault challenge.

NoSQLAuthenticationWebHTB
2025-05-14 2 min read
Read More
View All Write-ups