<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Web on Medusa0xf</title>
    <link>https://blog.medusa0xf.com/topics/web/</link>
    <description>Recent content in Web on Medusa0xf</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>© 2026 Medusa0xf</copyright>
    <lastBuildDate>Tue, 17 Mar 2026 21:53:25 +0100</lastBuildDate><atom:link href="https://blog.medusa0xf.com/topics/web/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>MCP Servers Explained: The New AI Attack Surface</title>
      <link>https://blog.medusa0xf.com/posts/mcp-servers-explained/</link>
      <pubDate>Tue, 17 Mar 2026 21:53:25 +0100</pubDate>
      
      <guid>https://blog.medusa0xf.com/posts/mcp-servers-explained/</guid>
      <description>MCP Servers Explained: The New AI Attack Surface # What is MCP?</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://blog.medusa0xf.com/posts/mcp-servers-explained/featured.png" />
    </item>
    
    <item>
      <title>IDOR Leads to Unauthorized Deletion: How I Earned $500 in Bug Bounty</title>
      <link>https://blog.medusa0xf.com/posts/idor-leads-to-unauthorized-deletion-how-i-earned-500-in-bug-bounty/</link>
      <pubDate>Sat, 08 Nov 2025 11:55:35 +0100</pubDate>
      
      <guid>https://blog.medusa0xf.com/posts/idor-leads-to-unauthorized-deletion-how-i-earned-500-in-bug-bounty/</guid>
      <description>During bug hunting, I discovered an IDOR vulnerability that allowed unauthorized deletion of resources across accounts within the same tenant.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://blog.medusa0xf.com/posts/idor-leads-to-unauthorized-deletion-how-i-earned-500-in-bug-bounty/feature.gif" />
    </item>
    
    <item>
      <title>How I Found an Account Takeover Bug in the Forgot Password Flow</title>
      <link>https://blog.medusa0xf.com/posts/how-i-found-an-account-takeover-bug-in-the-forgot-password-flow/</link>
      <pubDate>Tue, 23 Sep 2025 21:55:35 +0100</pubDate>
      
      <guid>https://blog.medusa0xf.com/posts/how-i-found-an-account-takeover-bug-in-the-forgot-password-flow/</guid>
      <description>While I was hunting on a target, I came across an acquisition related to it, so I decided to look around the new domain.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://blog.medusa0xf.com/posts/how-i-found-an-account-takeover-bug-in-the-forgot-password-flow/feature.jpg" />
    </item>
    
    <item>
      <title>How I Found a $3000 IDOR Vulnerability in a Delivery App</title>
      <link>https://blog.medusa0xf.com/posts/how-i-found-a-3000-idor-vulnerability-in-a-delivery-app/</link>
      <pubDate>Sat, 13 Sep 2025 20:57:35 +0100</pubDate>
      
      <guid>https://blog.medusa0xf.com/posts/how-i-found-a-3000-idor-vulnerability-in-a-delivery-app/</guid>
      <description>Recently, I was hunting on a target that I can’t disclose because of its responsible disclosure program, even though it’s public.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://blog.medusa0xf.com/posts/how-i-found-a-3000-idor-vulnerability-in-a-delivery-app/feature.png" />
    </item>
    
    <item>
      <title>Exploiting DOM for Open Redirect Attacks</title>
      <link>https://blog.medusa0xf.com/posts/exploiting-dom-for-open-redirect-attacks/</link>
      <pubDate>Fri, 22 Nov 2024 22:30:35 +0100</pubDate>
      
      <guid>https://blog.medusa0xf.com/posts/exploiting-dom-for-open-redirect-attacks/</guid>
      <description>What is Open Redirect Vulnerability?</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://blog.medusa0xf.com/posts/exploiting-dom-for-open-redirect-attacks/featured.png" />
    </item>
    
    <item>
      <title>HTTP Parameter Pollution vs Mass Assignment</title>
      <link>https://blog.medusa0xf.com/posts/http-parameter-pollution-vs-mass-assignment/</link>
      <pubDate>Tue, 04 Jun 2024 22:20:35 +0100</pubDate>
      
      <guid>https://blog.medusa0xf.com/posts/http-parameter-pollution-vs-mass-assignment/</guid>
      <description>In this blog, we are going to see the difference between HTTP parameter pollution and mass assignment.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://blog.medusa0xf.com/posts/http-parameter-pollution-vs-mass-assignment/featured.png" />
    </item>
    
  </channel>
</rss>
