home
|
feeds
|
donate
Log in / sign up
Sam Curry
White hat hacker
follow
hacking the world poker tour: inside clubwpt gold’s back office
Sam Curry
-
Oct 12
hide
hacking subaru: tracking and controlling cars via the starlink admin panel
Sam Curry
-
Jan 23
hide
hacking kia: remotely controlling cars with just a license plate
Sam Curry
-
Sep 20 2024
hide
hacking millions of modems (and investigating who hacked my modem)
Sam Curry
-
Jun 03 2024
hide
leaked secrets and unlimited miles: hacking the largest airline and hotel rewards platform
Sam Curry
-
Aug 03 2023
hide
web hackers vs. the auto industry: critical vulnerabilities in ferrari, bmw, rolls royce, porsche, and more
Sam Curry
-
Jan 03 2023
hide
exploiting web3's hidden attack surface: universal xss on netlify's next.js library
Sam Curry
-
Sep 21 2022
hide
hacking chess.com and accessing 50 million customer records
Sam Curry
-
Dec 16 2020
hide
we hacked apple for 3 months: here’s what we found
Sam Curry
-
Oct 07 2020
hide
hacking starbucks and accessing nearly 100 million customer records
Sam Curry
-
Jun 20 2020
hide
don't force yourself to become a bug bounty hunter
Sam Curry
-
May 11 2020
hide
abusing http path normalization and cache poisoning to steal rocket league accounts
Sam Curry
-
Apr 19 2020
hide
filling in the blanks: exploiting null byte buffer overflow for a $40,000 bounty
Sam Curry
-
Nov 01 2019
hide
analysis of cve-2019-14994 - jira service desk path traversal leads to massive information disclosure
Sam Curry
-
Sep 26 2019
hide
cracking my windshield and earning $10,000 on the tesla bug bounty program
Sam Curry
-
Jul 14 2019
hide
reading asp secrets for $17,000
Sam Curry
-
Dec 17 2018
hide
the $12,000 intersection between clickjacking, xss, and denial of service
Sam Curry
-
Jul 04 2018
hide
hacking a massive steam scamming and phishing operation for fun and profit
Sam Curry
-
May 09 2018
hide
exploiting directory traversal to view customer credit card information on yahoo's small business platform
Sam Curry
-
Nov 10 2017
hide
how i gained access to chef, docker, aws, and mongodb instances in a single request
Sam Curry
-
Aug 03 2017
hide
permanent account takeover on yahoo's small business platform
Sam Curry
-
Jun 25 2017
hide
how i could've taken over the production server of a yahoo acquisition through command injection
Sam Curry
-
Jun 04 2017
hide
eradicating image authentication injection from the entire internet
Sam Curry
-
May 10 2017
hide
how i stole the identity of every yahoo user
Sam Curry
-
May 09 2017
hide