Marx Chryz Del Mundo·Sep 27, 2025Escalating an HTML Injection into 1-Click Account TakeoverHello everyone, I am Marx Chryz and I’m a HTB CWEE, CPTS, and CBBH passer. I will show you a write up about a vulnerability I found…A response icon7A response icon7
Marx Chryz Del Mundo·Dec 4, 2022URL Validation Bypass Using Browser URI NormalizationHello everyone, I am Marx Chryz and I do bug bounty hunting for about two years now. It’s also been three and a half years since I started…A response icon1A response icon1
Marx Chryz Del Mundo·Nov 29, 2021Price Manipulation Bypass Using Integer Overflow MethodHello everyone, I am Marx Chryz and I do bug bounty hunting for about a year now. It’s also been two and a half years since I started doing…A response icon3A response icon3
Marx Chryz Del Mundo·Sep 2, 2021How I Found Multiple XSS in Hidden Legacy PagesHello everyone, I am Marx Chryz and I do bug bounty hunting for about a year now. It’s also been two and a half years since I started…
Marx Chryz Del Mundo·Feb 6, 2021How I Gain Access to the Server Administration of a Million-Dollar CompanyHello everyone, I am Marx Chryz and I am new to bug bounty hunting even though I do web penetration testing for more than a year.A response icon1A response icon1
Marx Chryz Del Mundo·Dec 17, 2020My Bug Bounty Journey and My First Critical Bug — Time Based Blind SQL InjectionHello everyone, I am Marx Chryz and I am new to bug bounty hunting even though I do web penetration testing for more than a year.A response icon9A response icon9