_ Remmy9
LIVE
home writing about

Writing

>_
Bypassing WAF, 403, and OTP to Exploit SQL Injection Bypassing WAF, 403 Forbidden, and OTP restrictions to exploit a blind SQL injection on a VDP program.
sql-injectionwaf-bypass May 25, 2025 5 min
>_
My Therapist Said Tiny Problems Don’t Matter. These Vulnerability Chains Proved Me Wrong. Chaining multiple low-severity IDORs, broken access control, and token exhaustion into a data exfiltration chain.
chainingidor May 25, 2025 7 min
>_
From alert(origin) to ATO, an XSS Story How a simple XSS discovery escalated to full account takeover through response manipulation and creative payload crafting.
xssato Feb 4, 2025 6 min
>_
403 Forbidden? No Problem, Here’s a POST XSS Bypassing 403 forbidden restrictions to deliver a POST-based XSS payload that led to a Bugcrowd bounty.
xssbypass Oct 5, 2023 4 min

Remmy — offensive security specialist, exploit writer, cat person. 4+ years breaking web, AD, cloud, and mobile. 15+ crit/high findings. #opsec

© 2026 Remmy9

RemmyNine @NineRemmy rss