<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://blog.veysel-xan.com/</id><title>cyb3rlynx</title><subtitle>Vulnerability research, bug bounty writeups, and CVE disclosures by cyb3rlynx — web application exploitation, recon workflows, and the security tools I build along the way</subtitle> <updated>2026-06-20T18:04:25+00:00</updated> <author> <name>cyb3rlynx</name> <uri>https://blog.veysel-xan.com/</uri> </author><link rel="self" type="application/atom+xml" href="https://blog.veysel-xan.com/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://blog.veysel-xan.com/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 cyb3rlynx </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>That Time a Bank Blocked My Account and Still Handed Me a Token</title><link href="https://blog.veysel-xan.com/posts/bank-otp-bypass/" rel="alternate" type="text/html" title="That Time a Bank Blocked My Account and Still Handed Me a Token" /><published>2026-06-20T00:00:00+00:00</published> <updated>2026-06-20T00:00:00+00:00</updated> <id>https://blog.veysel-xan.com/posts/bank-otp-bypass/</id> <content type="text/html" src="https://blog.veysel-xan.com/posts/bank-otp-bypass/" /> <author> <name>cyb3rlynx</name> </author> <category term="Bug Bounty" /> <category term="Web Security" /> <summary>A four digit OTP, a ten minute lockout, and a backend that never got the memo. The story of the laziest brute force I ever ran turning into an auth bypass.</summary> </entry> <entry><title>I Came for RFI, I Left with SSRF + XSS</title><link href="https://blog.veysel-xan.com/posts/i-came-for-rfi-i-left-with-ssrf-xss/" rel="alternate" type="text/html" title="I Came for RFI, I Left with SSRF + XSS" /><published>2026-06-17T00:00:00+00:00</published> <updated>2026-06-17T00:00:00+00:00</updated> <id>https://blog.veysel-xan.com/posts/i-came-for-rfi-i-left-with-ssrf-xss/</id> <content type="text/html" src="https://blog.veysel-xan.com/posts/i-came-for-rfi-i-left-with-ssrf-xss/" /> <author> <name>cyb3rlynx</name> </author> <category term="Bug Bounty" /> <category term="Web Security" /> <summary>A messy little bug where a URL inside a URL made the server phone a stranger, then reflect whatever it said straight into the page.</summary> </entry> </feed>
