<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1"><url><loc>https://blog.securitybreached.org/</loc></url><url><loc>https://blog.securitybreached.org/2017/</loc></url><url><loc>https://blog.securitybreached.org/2017/10/10/bugcrowds-domain-subdomain-takeover-vulnerability/</loc></url><url><loc>https://blog.securitybreached.org/2017/10/10/exploiting-insecure-cross-origin-resource-sharing-cors-api-artsy-net/</loc></url><url><loc>https://blog.securitybreached.org/2017/10/10/sqli-xss-vulnerabilities-in-a-popular-airlines-website/</loc></url><url><loc>https://blog.securitybreached.org/2017/10/10/subdomain-takeover-lamborghini-hacked/</loc></url><url><loc>https://blog.securitybreached.org/2017/10/11/what-is-subdomain-takeover-vulnerability/</loc></url><url><loc>https://blog.securitybreached.org/2017/11/04/access-localhost-via-virtual-host-virtual-host-enumeration/</loc></url><url><loc>https://blog.securitybreached.org/2017/11/20/uber-wildcard-subdomain-takeover/</loc></url><url><loc>https://blog.securitybreached.org/2017/11/25/guide-to-basic-recon-for-bugbounty/</loc></url><url><loc>https://blog.securitybreached.org/2017/12/10/how-i-was-able-to-takeover-facebook-account-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2017/12/19/security-researcher-saved-careem-from-a-data-breach/</loc></url><url><loc>https://blog.securitybreached.org/2017/12/19/unrestricted-file-upload-to-rce-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2018/</loc></url><url><loc>https://blog.securitybreached.org/2018/01/16/knoxss-for-dummies-a-new-detailed-guide-to-use-knoxss-pro-in-real-world/</loc></url><url><loc>https://blog.securitybreached.org/2018/01/27/how-i-was-able-to-download-any-file-from-web-server/</loc></url><url><loc>https://blog.securitybreached.org/2018/02/02/how-i-was-able-to-bypass-xss-protection-on-hackerones-private-program/</loc></url><url><loc>https://blog.securitybreached.org/2018/02/04/hunting-insecure-direct-object-reference-vulnerabilities-for-fun-and-profit-part-1/</loc></url><url><loc>https://blog.securitybreached.org/2018/02/05/how-i-found-idor-on-twitters-acquisition-mopub-com/</loc></url><url><loc>https://blog.securitybreached.org/2018/05/18/get-subscription-of-120-year-for-free-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2018/05/22/ios-11-4-authentication-bug-siri-cve-2018-4238/</loc></url><url><loc>https://blog.securitybreached.org/2018/05/23/edmodo-number-compromised/</loc></url><url><loc>https://blog.securitybreached.org/2018/09/07/rce-jenkins-instance-dosomething-org-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2018/09/08/sqli-bootcampnutanix-com-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2018/09/09/zol-zimbabwe-authbypass-sqli-xss/</loc></url><url><loc>https://blog.securitybreached.org/2018/09/10/sqli-login-bypass-autotraders/</loc></url><url><loc>https://blog.securitybreached.org/2018/09/16/idor-account-takeover-using-facebook/</loc></url><url><loc>https://blog.securitybreached.org/2018/09/24/subdomain-takeover-via-unsecured-s3-bucket/</loc></url><url><loc>https://blog.securitybreached.org/2018/10/27/privilege-escalation-like-a-boss/</loc></url><url><loc>https://blog.securitybreached.org/2018/11/03/p1-like-a-boss-information-disclosure-via-github-leads-to-employee-account-takeover/</loc></url><url><loc>https://blog.securitybreached.org/2018/11/05/hacking-a-company-through-help-desk-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2018/12/08/how-i-was-able-to-bypass-email-verification/</loc></url><url><loc>https://blog.securitybreached.org/2020/</loc></url><url><loc>https://blog.securitybreached.org/2020/01/22/user-account-takeover-via-signup-feature-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2020/01/26/improper-input-validation-add-custom-text-and-urls-in-sms-send-by-snapchat-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2020/02/04/exploiting-insecure-firebase-database-bugbounty/</loc></url><url><loc>https://blog.securitybreached.org/2020/02/19/hacking-sms-api-service-provider-of-a-company-android-app-static-security-analysis-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2020/03/17/getting-started-in-android-apps-pentesting/</loc></url><url><loc>https://blog.securitybreached.org/2020/03/31/microsoft-rce-bugbounty/</loc></url><url><loc>https://blog.securitybreached.org/2020/04/04/playing-with-json-web-tokens-for-fun-and-profit/</loc></url><url><loc>https://blog.securitybreached.org/2020/06/30/using-inspect-element-to-bypass-security-restrictions-bug-bounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/2022/</loc></url><url><loc>https://blog.securitybreached.org/2022/02/27/hacking-subscription-plans-for-free-service/</loc></url><url><loc>https://blog.securitybreached.org/2022/05/19/hacking-100k-loyalty-programs-for-fun-and-profit/</loc></url><url><loc>https://blog.securitybreached.org/2023/</loc></url><url><loc>https://blog.securitybreached.org/2023/04/19/how-i-manipulated-my-rank-on-the-bugcrowd-platform/</loc></url><url><loc>https://blog.securitybreached.org/2023/08/18/bug-bounty-blueprint-a-beginners-guide/</loc></url><url><loc>https://blog.securitybreached.org/2024/</loc></url><url><loc>https://blog.securitybreached.org/2024/06/28/finding-hidden-threats-how-i-found-leaked-aws-credentials-in-an-android-app-api-using-dast/</loc></url><url><loc>https://blog.securitybreached.org/2024/10/14/ai-hijack-how-i-took-control-of-an-ai-assistant/</loc></url><url><loc>https://blog.securitybreached.org/2024/10/22/from-staging-to-full-admin-control-in-prod-a-breakdown-of-critical-authentication-flaws/</loc></url><url><loc>https://blog.securitybreached.org/2025/</loc></url><url><loc>https://blog.securitybreached.org/2025/01/20/purple-teaming-what-not-to-do-in-ot-iot-testing-to-avoid-halting-the-factory-or-sinking-the-oil-rig/</loc></url><url><loc>https://blog.securitybreached.org/category/bug-bounty-guide/</loc></url><url><loc>https://blog.securitybreached.org/category/bugbounty-poc/</loc></url><url><loc>https://blog.securitybreached.org/category/news/</loc></url><url><loc>https://blog.securitybreached.org/category/purple-teaming/</loc></url><url><loc>https://blog.securitybreached.org/category/tutorials/</loc></url><url><loc>https://blog.securitybreached.org/category/uncategorized/</loc></url></urlset>