11 Writeups Logged · Web Security & CTFsGodson's
Godson's
BlogSource-Code Reviews & Web Security, One CTF At A Time
Hey there ๐ โ I'm Godson, a dude who loves doing source-code reviews and web security. I'm passionate about ensuring web applications are secure, uncovering vulnerabilities, and keeping them safe.
Latest Writeups
CTF & Bug Bounty WriteupsClient-Side / XSS
๐ Pinned
Client-Side / DOM
๐ PinnedResearch
An Art of DOM Clobbering ๐ญ
Client-Side / XSS
March 2023 - Intigriti's XSS Challenge - Author Writeup
Client-Side / XSS
Intigriti's Nov XSS Challenge Writeup
Chained Exploit
CTF Writeup
B-XSS -> ZipSlip -> Local File Read
Client-Side / XSS
CTF Writeup
May 2022 - Intigriti XSS Challenge Writeup - Prototype Pollution to Overwrite XSS filters!!!
Application Security
CTF Writeup
Order By Blind SQL Injection
Application Security
CTF Writeup
Exploiting Path Traversal in Python Application via os.path.join
Client-Side / XSS
CTF Writeup
Abusing URL Parser for XSS
Client-Side / DOM
CTF Writeup
DOM Clobbering - Clobber Undefined Variables!
Account Takeover in Fastmail
Bug Bounty
Account Takeover via User-Agent Spoofing in Fastmail's Password Reset
About This Blog
Hey there ๐, I'm Godson, a dude who loves doing source-code reviews and web security. I'm passionate about ensuring web applications are secure, uncovering vulnerabilities, and keeping applications safe. Most of what lands here comes out of CTFs and community XSS challenges โ browse by tag below to find a specific technique.
Find Me Elsewhere
Twitter, GitHub, LinkedIn, and the original posts on Hashnode.










