<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://00xmora.github.io/posts/Privilege-Escalation-via-Chat-Permissions-Bypass/</loc>
<lastmod>2025-07-06T23:44:51+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Auth-Token-Theft-via-CORS-Misconfiguration/</loc>
<lastmod>2025-08-03T12:43:38+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Path-Traversal-in-File-Upload-via-GraphQL-API/</loc>
<lastmod>2025-08-03T12:43:38+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/How-I-Tricked-the-System-with-Type-Confusion-and-Became-a-System-Admin-(Briefly)/</loc>
<lastmod>2025-08-03T12:43:38+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Exploiting-Flag26Service-Android-Messenger-Based-Service-(Hextree-CTF)/</loc>
<lastmod>2025-06-09T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Hextree-Labs-Flag27Service-Messenger-Vulnerability-(Solution)/</loc>
<lastmod>2025-08-03T12:43:38+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Flag28Service-AIDL-Binding-Walkthrough-(Hextree-Lab)/</loc>
<lastmod>2025-08-03T12:43:38+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Race-Condition-A-Detailed-Exploration/</loc>
<lastmod>2025-08-03T12:43:38+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Exploiting-SSTI-in-Node.js-Template-Rendering/</loc>
<lastmod>2025-07-28T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Pickle-RCE-Exfiltrating-Secrets-via-Unsafe-Deserialization/</loc>
<lastmod>2025-07-31T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/SpEL-Injection-Exploit-AppSec-Master-Challenge-Writeup/</loc>
<lastmod>2025-07-31T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/posts/Node.js-Arbitrary-File-Upload-to-RCE-AppSec-Master-Challenge-Writeup/</loc>
<lastmod>2025-08-03T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/categories/</loc>
<lastmod>2025-08-03T12:46:44+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/tags/</loc>
<lastmod>2025-08-03T12:46:44+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/archives/</loc>
<lastmod>2025-08-03T12:46:44+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/about/</loc>
<lastmod>2025-08-03T12:46:44+00:00</lastmod>
</url>
<url>
<loc>https://00xmora.github.io/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/privilege-escalation/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/access-control/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/api-security/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/bug-bounty/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/cors/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/auth-token-theft/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/web-security/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/path-traversal/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/file-upload/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/graphql/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/gcp/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/type/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/confusion/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/privilege/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/escalation/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/security/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/bug/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/bounty/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/ctf/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/vulnerabilities/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/real-world/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/stories/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/android/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/ipc/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/messenger/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/hextree/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/services/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/app/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/android/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/ctf/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/labs/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/messenger/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/ipc/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/vulnerability/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/writeup/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/reverse/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/engineering/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/android/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/aidl/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/binder/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/reverse-engineering/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/inter-process-communication/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/hextree/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/penetration-testing/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/android-security/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/race-condition/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/security/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/multithreading/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/synchronization/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/ssti/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/nodejs/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/vm/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/appsecmaster/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/rce/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/pickle/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/deserialization/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/flask/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/webhook/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/appsecmaster/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/spel/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/java/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/injection/</loc>
</url>
<url>
<loc>https://00xmora.github.io/tags/challenge/</loc>
</url>
<url>
<loc>https://00xmora.github.io/categories/web/</loc>
</url>
<url>
<loc>https://00xmora.github.io/categories/android/</loc>
</url>
<url>
<loc>https://00xmora.github.io/categories/research/</loc>
</url>
<url>
<loc>https://00xmora.github.io/categories/code-review/</loc>
</url>
<url>
<loc>https://00xmora.github.io/page2/</loc>
</url>
<url>
<loc>https://00xmora.github.io/googlefb1f3b853a05bcd1.html</loc>
<lastmod>2025-08-03T12:46:16+00:00</lastmod>
</url>
</urlset>
