<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>pizzaPower</title>
    <link>https://pizzapower.me</link>
    <description>a blog on security, homelabs, networking, etc.</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 07 Jul 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://pizzapower.me/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A New Build for pizzaPower</title>
      <link>https://pizzapower.me/posts/hello-new-blog</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/hello-new-blog</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
      <description>The blog moved off Jekyll and GitHub Pages onto Next.js stack on Vercel</description>
      <media:content url="https://pizzapower.me/posts/hello-new-blog/opengraph-image" medium="image" />
      <category>site</category>
      <category>meta</category>
    </item>
    <item>
      <title>UHF IPTV Review</title>
      <link>https://pizzapower.me/posts/uhf-iptv-review</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/uhf-iptv-review</guid>
      <pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate>
      <description>I recently posted about getting IPTV up and running in Plex. Admittedly, it&apos;s a bit of a pain to do so and there are some drawbacks to it. I eventually stumbled upon this UHF app…</description>
      <media:content url="https://pizzapower.me/posts/uhf-iptv-review/opengraph-image" medium="image" />
      <category>IPTV</category>
      <category>Plex</category>
      <category>streaming</category>
      <category>DVR</category>
      <category>EPG</category>
      <category>M3U</category>
      <category>Home Server</category>
    </item>
    <item>
      <title>Beware Burp Suite AI Explore Feature Using Malicious Commands</title>
      <link>https://pizzapower.me/posts/beware-burp-suite-ai-explore-feature-using-malicious-commands</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/beware-burp-suite-ai-explore-feature-using-malicious-commands</guid>
      <pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate>
      <description>I recently decided to try the explore with AI feature of Burp Suite after param miner discovered an issue I hadn&apos;t seen before. It proceeded through the process, then eventually…</description>
      <media:content url="https://pizzapower.me/posts/beware-burp-suite-ai-explore-feature-using-malicious-commands/opengraph-image" medium="image" />
      <category>burp suite</category>
      <category>web application penetration testing</category>
      <category>AI</category>
      <category>LLM</category>
      <category>artifical intelligence</category>
    </item>
    <item>
      <title>Using 3 Monitors with MacBook Pro M3 Max and a Dock</title>
      <link>https://pizzapower.me/posts/using-3-monitors-with-macbook-pro-m3-max-and-a-dock</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/using-3-monitors-with-macbook-pro-m3-max-and-a-dock</guid>
      <pubDate>Tue, 02 Sep 2025 00:00:00 GMT</pubDate>
      <description>I was running my MacBook M3 Max connected to a Dell D6000 dock. After installing the DisplayLink software on the Mac, I was able to connect two monitors to the dock and one to the…</description>
      <media:content url="https://pizzapower.me/posts/using-3-monitors-with-macbook-pro-m3-max-and-a-dock/opengraph-image" medium="image" />
    </item>
    <item>
      <title>Setting up IPTV with Plex</title>
      <link>https://pizzapower.me/posts/iptv-plex-epg-streaming-setup</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/iptv-plex-epg-streaming-setup</guid>
      <pubDate>Mon, 01 Sep 2025 00:00:00 GMT</pubDate>
      <description>So, you want to stream IPTV in Plex. Here is how you can do it. Prerequisites At least a little bit of technical knowledge. You may want to use Docker or download and run a…</description>
      <media:content url="https://pizzapower.me/posts/iptv-plex-epg-streaming-setup/opengraph-image" medium="image" />
      <category>IPTV</category>
      <category>Plex</category>
      <category>streaming</category>
      <category>DVR</category>
      <category>EPG</category>
      <category>M3U</category>
      <category>Home Server</category>
    </item>
    <item>
      <title>Building a New Home Server</title>
      <link>https://pizzapower.me/posts/building-a-new-home-server</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/building-a-new-home-server</guid>
      <pubDate>Sat, 12 Jul 2025 00:00:00 GMT</pubDate>
      <description>I was bored, so I decided to build a new home server. I wasn&apos;t running into too many limitations with the previous incarnation, but the video card was a bit old (1080ti), and…</description>
      <media:content url="https://pizzapower.me/posts/building-a-new-home-server/opengraph-image" medium="image" />
      <category>server</category>
      <category>PC</category>
      <category>zfs</category>
      <category>home server</category>
    </item>
    <item>
      <title>Ubiquiti UniFi Dream Machine SE Power Supply Failure Fix</title>
      <link>https://pizzapower.me/posts/ubiquiti-udm-se-power-supply-fix</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/ubiquiti-udm-se-power-supply-fix</guid>
      <pubDate>Tue, 24 Jun 2025 00:00:00 GMT</pubDate>
      <description>The UDM SE died with a dead power supply Ubiquiti won&apos;t sell you. Here&apos;s the ~$80 Mean Well replacement that brought it back to life.</description>
      <media:content url="https://pizzapower.me/posts/ubiquiti-udm-se-power-supply-fix/opengraph-image" medium="image" />
      <category>unifi</category>
      <category>routers</category>
      <category>homelab</category>
      <category>repair</category>
    </item>
    <item>
      <title>iPad Pro vs. Supernote A5 X2 Manta vs reMarkable Paper Pro</title>
      <link>https://pizzapower.me/posts/ipad-pro-vs-manta-supernote-a5x2-vs-remarkable-paper-pro</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/ipad-pro-vs-manta-supernote-a5x2-vs-remarkable-paper-pro</guid>
      <pubDate>Fri, 16 May 2025 00:00:00 GMT</pubDate>
      <description>Now with early 2026 updates. Note, I may get comission from some of these links: I&apos;m a big paper note taker, and I go through a bunch of notebooks and pens a year. I mostly use it…</description>
      <media:content url="https://pizzapower.me/posts/ipad-pro-vs-manta-supernote-a5x2-vs-remarkable-paper-pro/opengraph-image" medium="image" />
      <category>eink</category>
      <category>tablets</category>
      <category>notes</category>
    </item>
    <item>
      <title>Building a Custom OOB Server</title>
      <link>https://pizzapower.me/posts/building-a-custom-oob-server</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/building-a-custom-oob-server</guid>
      <pubDate>Sat, 10 May 2025 00:00:00 GMT</pubDate>
      <description>If you&apos;re reading this, you&apos;ve probably used Burp, and you&apos;re probably aware of Burp Collaborator, the out of band detection feature. Basically, it gives you a (sub)domain name…</description>
      <media:content url="https://pizzapower.me/posts/building-a-custom-oob-server/opengraph-image" medium="image" />
      <category>bug bounty</category>
      <category>burp</category>
      <category>interactsh</category>
      <category>oob</category>
      <category>blind xss</category>
      <category>ssrf</category>
    </item>
    <item>
      <title>Please wait while Nessus is initializing</title>
      <link>https://pizzapower.me/posts/why-is-nessus-so-bad</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/why-is-nessus-so-bad</guid>
      <pubDate>Sat, 10 May 2025 00:00:00 GMT</pubDate>
      <description>Nessus is neverendingly annoying. 1. Takes way too long to install and &quot;initialize&quot;. 2. Can&apos;t open anything in a new tab. 3. Can&apos;t easily copy large lists of IPs (e.g. a…</description>
      <media:content url="https://pizzapower.me/posts/why-is-nessus-so-bad/opengraph-image" medium="image" />
      <category>nessus</category>
      <category>vulnerability scanning</category>
    </item>
    <item>
      <title>Escalating Self-XSS for Riches</title>
      <link>https://pizzapower.me/posts/escalating-self-xss-for-riches</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/escalating-self-xss-for-riches</guid>
      <pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate>
      <description>I have a bit of a love hate relationship with Self XSS. I find them somewhat regularly, and while I do think programs should pay a bounty for them (the lowest they offer), I’m…</description>
      <media:content url="https://pizzapower.me/posts/escalating-self-xss-for-riches/opengraph-image" medium="image" />
      <category>bug bounty</category>
      <category>xss</category>
      <category>hacking</category>
      <category>penetration testing</category>
    </item>
    <item>
      <title>A Very Brief Look at YesWiki</title>
      <link>https://pizzapower.me/posts/a-quick-look-at-yeswiki</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/a-quick-look-at-yeswiki</guid>
      <pubDate>Tue, 29 Apr 2025 00:00:00 GMT</pubDate>
      <description>After I created TemplateSearch.io, I was testing it out by searching for random things and I came across several templates for YesWiki. So I Googled it to see exactly what it is…</description>
      <media:content url="https://pizzapower.me/posts/a-quick-look-at-yeswiki/opengraph-image" medium="image" />
      <category>hacking</category>
      <category>bug bounty</category>
      <category>penetration testing</category>
      <category>web application</category>
      <category>cve</category>
      <category>pentesting</category>
      <category>research</category>
      <category>white box</category>
    </item>
    <item>
      <title>Funny Bug Bounty Reports #1</title>
      <link>https://pizzapower.me/posts/funny-bug-bounty-reports-1</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/funny-bug-bounty-reports-1</guid>
      <pubDate>Mon, 28 Apr 2025 00:00:00 GMT</pubDate>
      <description>This is the first part in my new series &quot;Funny Bug Bounty Reports&quot;. These are not judged on their merits, technical abilities, or anything other than if they make me laugh. Today,…</description>
      <media:content url="https://pizzapower.me/posts/funny-bug-bounty-reports-1/opengraph-image" medium="image" />
      <category>funnybbreports</category>
      <category>bug bounty</category>
      <category>penetration testing</category>
    </item>
    <item>
      <title>Behold! TemplateSearch.io</title>
      <link>https://pizzapower.me/posts/behold-templatesearch.io</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/behold-templatesearch.io</guid>
      <pubDate>Wed, 09 Apr 2025 00:00:00 GMT</pubDate>
      <description>I was tired of manually searching for the right Nuclei templates to use. The one existing site that lets you search them — while interestingly designed and certainly more stylish…</description>
      <media:content url="https://pizzapower.me/posts/behold-templatesearch.io/opengraph-image" medium="image" />
      <category>hacking</category>
      <category>nuclei</category>
      <category>nuclei templates</category>
      <category>bug bounty</category>
      <category>pentesting</category>
    </item>
    <item>
      <title>Installing Tailscale on a Wifi Pineapple</title>
      <link>https://pizzapower.me/posts/installing-tailscale-on-wifi-pineapple</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/installing-tailscale-on-wifi-pineapple</guid>
      <pubDate>Sat, 05 Apr 2025 00:00:00 GMT</pubDate>
      <description>I went to install Tailscale on a Wifi Pineapple, and the normal pipe to bash (lol) script didn&apos;t work. I had to do it manually like this. YMMV attempt at your own risk . I&apos;m…</description>
      <media:content url="https://pizzapower.me/posts/installing-tailscale-on-wifi-pineapple/opengraph-image" medium="image" />
      <category>hacking</category>
      <category>wifi</category>
      <category>wireless penetration test</category>
      <category>pentesting</category>
    </item>
    <item>
      <title>California Top 25 Researcher 2024</title>
      <link>https://pizzapower.me/posts/top-25-state-of-california-researcher</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/top-25-state-of-california-researcher</guid>
      <pubDate>Fri, 04 Apr 2025 00:00:00 GMT</pubDate>
      <description>I received an email saying I&apos;m a top 25 researcher in the California VDP from 2024. Not too bad from the thousands of reports they get, I&apos;m sure.</description>
      <media:content url="https://pizzapower.me/posts/top-25-state-of-california-researcher/opengraph-image" medium="image" />
      <category>california</category>
      <category>hacking</category>
      <category>bug bounty</category>
      <category>vdp</category>
      <category>vulnerability disclosure</category>
    </item>
    <item>
      <title>Pentesting a ClickHouse DB</title>
      <link>https://pizzapower.me/posts/clickhouse-db-security</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/clickhouse-db-security</guid>
      <pubDate>Tue, 01 Apr 2025 00:00:00 GMT</pubDate>
      <description>I recently ran across an application that allowed access to a ClickHouse DB for my user. The access was allowed, so that isn&apos;t an issue. However, when we as pentesters or bug…</description>
      <media:content url="https://pizzapower.me/posts/clickhouse-db-security/opengraph-image" medium="image" />
      <category>db</category>
      <category>clickhouse</category>
      <category>cybersecurity</category>
      <category>misconfigurations</category>
      <category>bug bounty</category>
      <category>clickhouse reverse shell</category>
      <category>penetration testing</category>
    </item>
    <item>
      <title>BugCrowd P1 Warrior Swag</title>
      <link>https://pizzapower.me/posts/bugcrowd-p1-warrior</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/bugcrowd-p1-warrior</guid>
      <pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate>
      <description>The other day I received an email saying I was eligible for some swag for getting my 25th valid P1 submission on BugCrowd. I don&apos;t do too much BB hunting these days, and also not…</description>
      <media:content url="https://pizzapower.me/posts/bugcrowd-p1-warrior/opengraph-image" medium="image" />
      <category>bugcrowd</category>
      <category>bug bounty</category>
    </item>
    <item>
      <title>reMarkable Paper Pro Sleep Screen Changing via &quot;HTML Injection&quot;</title>
      <link>https://pizzapower.me/posts/remarkable-paper-pro-html-injection</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/remarkable-paper-pro-html-injection</guid>
      <pubDate>Thu, 06 Feb 2025 00:00:00 GMT</pubDate>
      <description>That&apos;s in quotes, because this is seemingly a self HTML injection with little to no security impact, but it does allow for you to change your reMarkable&apos;s sleep screen in a…</description>
      <media:content url="https://pizzapower.me/posts/remarkable-paper-pro-html-injection/opengraph-image" medium="image" />
    </item>
    <item>
      <title>Mura/Masa CMS - SQL Injection CVE-2024-32640</title>
      <link>https://pizzapower.me/posts/mura-masa-cms-sql-injection-cve-2024-32640</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/mura-masa-cms-sql-injection-cve-2024-32640</guid>
      <pubDate>Wed, 13 Nov 2024 00:00:00 GMT</pubDate>
      <description>A while back the illustrious team over at Project Discovery wrote about the discovery of an SQLi in Masa/Mura CMS . It&apos;s a good writeup, so go check it out for the technical…</description>
      <media:content url="https://pizzapower.me/posts/mura-masa-cms-sql-injection-cve-2024-32640/opengraph-image" medium="image" />
      <category>CVE</category>
      <category>cyber</category>
      <category>cybersecurity</category>
      <category>hacking</category>
      <category>masa</category>
      <category>mura</category>
      <category>python</category>
      <category>sqli</category>
      <category>bug bounty</category>
      <category>bugbounty</category>
    </item>
    <item>
      <title>iOS 16.7.8 Jailbreak on iPhone X</title>
      <link>https://pizzapower.me/posts/ios-16-7-8-jailbreak-on-iphone-x</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/ios-16-7-8-jailbreak-on-iphone-x</guid>
      <pubDate>Thu, 25 Jul 2024 00:00:00 GMT</pubDate>
      <description>If you&apos;re a pentester or bug bounty hunter that is trying to do some iOS mobile application testing, half the battle is getting a phone properly jailbroken so you can proxy HTTP…</description>
      <media:content url="https://pizzapower.me/posts/ios-16-7-8-jailbreak-on-iphone-x/opengraph-image" medium="image" />
      <category>cybersecurity</category>
      <category>hacking</category>
      <category>infosec</category>
      <category>ios 16.7.8 jailbreak</category>
      <category>iphone jailbreak</category>
      <category>linux</category>
      <category>mobile</category>
      <category>mobile application penetration testing</category>
      <category>offsec</category>
      <category>bug bounty</category>
      <category>jailbreak</category>
    </item>
    <item>
      <title>Hacking RAMADDA, White Box Web Apps, and Bug Bounty Tips</title>
      <link>https://pizzapower.me/posts/hacking-ramadda-white-box-web-apps-and-bug-bounty-tips</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/hacking-ramadda-white-box-web-apps-and-bug-bounty-tips</guid>
      <pubDate>Fri, 20 Oct 2023 00:00:00 GMT</pubDate>
      <description>Note: disregard any layout/content/formatting errors as this post was migrated from wordpress to jekyll As mentioned in a previous post, I was the July RotM for the DoD VDP…</description>
      <media:content url="https://pizzapower.me/posts/hacking-ramadda-white-box-web-apps-and-bug-bounty-tips/opengraph-image" medium="image" />
      <category>appsec</category>
      <category>cybersecurity</category>
      <category>debugging</category>
      <category>hacking</category>
      <category>infosec</category>
      <category>java</category>
      <category>rce</category>
      <category>white box</category>
      <category>xss</category>
      <category>aws</category>
      <category>bug bounty</category>
      <category>bugbounty</category>
      <category>CVE</category>
    </item>
    <item>
      <title>Department of Defense Researcher of the Month (Year)</title>
      <link>https://pizzapower.me/posts/department-of-defense-researcher-of-the-month-and-more</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/department-of-defense-researcher-of-the-month-and-more</guid>
      <pubDate>Fri, 18 Aug 2023 00:00:00 GMT</pubDate>
      <description>I was recently awarded the DoD Researcher of the Month for July, 2023 . Between moving across the country and other hacking duties, I still had time to hammer away at a particular…</description>
      <media:content url="https://pizzapower.me/posts/department-of-defense-researcher-of-the-month-and-more/opengraph-image" medium="image" />
      <category>cyber</category>
      <category>cybersecurity</category>
      <category>hacking</category>
      <category>infosec</category>
      <category>bug bounty</category>
    </item>
    <item>
      <title>PyMedusa OS Command Injection</title>
      <link>https://pizzapower.me/posts/pymedusa-os-command-injection</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/pymedusa-os-command-injection</guid>
      <pubDate>Mon, 27 Mar 2023 00:00:00 GMT</pubDate>
      <description>PyMedusa is a well known video library manager that many of us self hosted types may use to organize our libraries. I decided to give it a spin one day and found a classic OS…</description>
      <media:content url="https://pizzapower.me/posts/pymedusa-os-command-injection/opengraph-image" medium="image" />
      <category>cybersecurity</category>
      <category>offsec</category>
      <category>OSCP</category>
      <category>OSWE</category>
      <category>self hosting</category>
      <category>certifications</category>
      <category>CVE</category>
      <category>offensive security</category>
      <category>python</category>
      <category>security</category>
    </item>
    <item>
      <title>SQL Injection in Eufy Security Application</title>
      <link>https://pizzapower.me/posts/sql-injection-in-eufy-security-application</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/sql-injection-in-eufy-security-application</guid>
      <pubDate>Mon, 20 Feb 2023 00:00:00 GMT</pubDate>
      <description>I found a textbook SQLi in the Eufy Security application. Don&apos;t mind the heavy use of red blocks to redact. The first, normal request. Everything looks fine. Notice the response…</description>
      <media:content url="https://pizzapower.me/posts/sql-injection-in-eufy-security-application/opengraph-image" medium="image" />
      <category>cybersecurity</category>
      <category>hacking</category>
      <category>iot</category>
      <category>sqli</category>
      <category>infosec</category>
      <category>security</category>
    </item>
    <item>
      <title>Self-Hosted Security Part ? - Poor Rate Limiting in Organizr</title>
      <link>https://pizzapower.me/posts/self-hosted-security-part-taking-over-organizr-accounts</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/self-hosted-security-part-taking-over-organizr-accounts</guid>
      <pubDate>Wed, 25 Jan 2023 00:00:00 GMT</pubDate>
      <description>Organizr is a self hosted application written in PHP that basically helps you self host other services at your home. It&apos;s nifty application with a surprisingly large amount of…</description>
      <media:content url="https://pizzapower.me/posts/self-hosted-security-part-taking-over-organizr-accounts/opengraph-image" medium="image" />
      <category>cybersecurity</category>
      <category>hacking</category>
      <category>infosec</category>
      <category>self hosting</category>
      <category>bug bounty</category>
      <category>CVE</category>
      <category>offensive security</category>
    </item>
    <item>
      <title>Docker Compose - Plex, Jackett, Sonarr, Radarr, Lidarr, Prowlarr, qBittorrent, and PIA</title>
      <link>https://pizzapower.me/posts/docker-compose-plex-jackett-sonarr-radarr-lidarr-prowlar-qbittorrent-and-pia</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/docker-compose-plex-jackett-sonarr-radarr-lidarr-prowlar-qbittorrent-and-pia</guid>
      <pubDate>Fri, 25 Nov 2022 00:00:00 GMT</pubDate>
      <description>I updated this post to add in prowlarr support. But here is the updated docker compose.yml. version: &apos;3.8&apos; services: pms docker: container name: plex network mode: host hostname:…</description>
      <media:content url="https://pizzapower.me/posts/docker-compose-plex-jackett-sonarr-radarr-lidarr-prowlar-qbittorrent-and-pia/opengraph-image" medium="image" />
      <category>docker</category>
      <category>lidarr</category>
      <category>linux</category>
      <category>pia</category>
      <category>prowlarr</category>
      <category>qbittorrent</category>
      <category>radarr</category>
      <category>self hosting</category>
      <category>sonarr</category>
      <category>torrents</category>
    </item>
    <item>
      <title>Webmin CVE-2022-0824 RCE in Golang</title>
      <link>https://pizzapower.me/posts/webmin-cve-2022-0824-rce-in-golang</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/webmin-cve-2022-0824-rce-in-golang</guid>
      <pubDate>Mon, 17 Oct 2022 00:00:00 GMT</pubDate>
      <description>I&apos;ve continued my quest to translate exploits into Golang. Here is an RCE in Webmin due to broken access controls. Please see the following links for more information.…</description>
      <media:content url="https://pizzapower.me/posts/webmin-cve-2022-0824-rce-in-golang/opengraph-image" medium="image" />
      <category>CVE</category>
      <category>GOLANG</category>
      <category>hacking</category>
      <category>POC</category>
      <category>coding</category>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>offensive security</category>
      <category>offsec</category>
    </item>
    <item>
      <title>Guitar Pro Directory Traversal and Filename XSS</title>
      <link>https://pizzapower.me/posts/guitar-pro-directory-traversal-and-filename-xss</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/guitar-pro-directory-traversal-and-filename-xss</guid>
      <pubDate>Tue, 11 Oct 2022 00:00:00 GMT</pubDate>
      <description>These were given CVE 2022 43263 and CVE 2022 43264. I found these vulnerabilities in the latest version of Guitar Pro (1.10.2) on the iPad and iPhone. Neither one is that great of…</description>
      <media:content url="https://pizzapower.me/posts/guitar-pro-directory-traversal-and-filename-xss/opengraph-image" medium="image" />
      <category>cybersecurity</category>
      <category>directory traversal</category>
      <category>guitar pro</category>
      <category>hacking</category>
      <category>infosec</category>
      <category>xss</category>
      <category>offensive security</category>
      <category>offsec</category>
    </item>
    <item>
      <title>CrushFTP DoS</title>
      <link>https://pizzapower.me/posts/crushftp-dos</link>
      <guid isPermaLink="true">https://pizzapower.me/posts/crushftp-dos</guid>
      <pubDate>Fri, 30 Sep 2022 00:00:00 GMT</pubDate>
      <description>I was doing a security review of CrushFTP , a multi platform FTP application, and I came across a DoS stemming from lack of validation of user input. Originally, I thought there…</description>
      <media:content url="https://pizzapower.me/posts/crushftp-dos/opengraph-image" medium="image" />
      <category>crushftp</category>
      <category>cyber</category>
      <category>dos</category>
      <category>hacking</category>
      <category>infosec</category>
      <category>offsec</category>
      <category>coding</category>
      <category>security</category>
    </item>
  </channel>
</rss>
