<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Infosec on Medusa0xf</title>
    <link>https://medusa0xf.com/tags/infosec/</link>
    <description>Recent content in Infosec on Medusa0xf</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>© 2026 Medusa0xf</copyright>
    <lastBuildDate>Sat, 13 Sep 2025 20:57:35 +0100</lastBuildDate><atom:link href="https://medusa0xf.com/tags/infosec/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How I Found a $3000 IDOR Vulnerability in a Delivery App</title>
      <link>https://medusa0xf.com/posts/how-i-found-a-3000-idor-vulnerability-in-a-delivery-app/</link>
      <pubDate>Sat, 13 Sep 2025 20:57:35 +0100</pubDate>
      
      <guid>https://medusa0xf.com/posts/how-i-found-a-3000-idor-vulnerability-in-a-delivery-app/</guid>
      <description>Recently, I was hunting on a target that I can’t disclose because of its responsible disclosure program, even though it’s public.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://medusa0xf.com/posts/how-i-found-a-3000-idor-vulnerability-in-a-delivery-app/feature.png" />
    </item>
    
    <item>
      <title>API Basics: A Hacker&#39;s Starter Guide</title>
      <link>https://medusa0xf.com/posts/api-basics-hsg/</link>
      <pubDate>Thu, 21 Mar 2024 21:42:37 +0100</pubDate>
      
      <guid>https://medusa0xf.com/posts/api-basics-hsg/</guid>
      <description>What is an API?</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://medusa0xf.com/posts/api-basics-hsg/featured.gif" />
    </item>
    
    <item>
      <title>How to Discover API Subdomains? | API Hacking |</title>
      <link>https://medusa0xf.com/posts/api-subdomains/</link>
      <pubDate>Tue, 12 Mar 2024 22:05:37 +0100</pubDate>
      
      <guid>https://medusa0xf.com/posts/api-subdomains/</guid>
      <description>How to Discover API Subdomains?</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://medusa0xf.com/posts/api-subdomains/featured.png" />
    </item>
    
    <item>
      <title>Server Side Parameter Pollution in Rest API path parameter</title>
      <link>https://medusa0xf.com/posts/server-side-parameter-pollution/</link>
      <pubDate>Mon, 04 Mar 2024 11:50:00 +0001</pubDate>
      
      <guid>https://medusa0xf.com/posts/server-side-parameter-pollution/</guid>
      <description>What is Server Side Parameter Pollution?</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://medusa0xf.com/posts/server-side-parameter-pollution/feature.png" />
    </item>
    
    <item>
      <title>How to Perform CSRF Attack in GraphQL</title>
      <link>https://medusa0xf.com/posts/csrf-in-graphql/</link>
      <pubDate>Tue, 16 Jan 2024 22:05:37 +0100</pubDate>
      
      <guid>https://medusa0xf.com/posts/csrf-in-graphql/</guid>
      <description>What is a CSRF Attack?</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://medusa0xf.com/posts/csrf-in-graphql/featured.png" />
    </item>
    
    <item>
      <title>Broken Object Level Authorization Vs. Broken Functionality Level Authorization | API Hacking</title>
      <link>https://medusa0xf.com/posts/api-broken-auth/</link>
      <pubDate>Mon, 13 Jun 2022 20:55:37 +0100</pubDate>
      
      <guid>https://medusa0xf.com/posts/api-broken-auth/</guid>
      <description>In this blog, we will explore two significant security vulnerabilities: Broken Object Level Authorization (BOLA) and Broken Functionality Level Authorization (BFLA) in APIs.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://medusa0xf.com/posts/api-broken-auth/featured.png" />
    </item>
    
  </channel>
</rss>
