Corben Leo

gh/lc
/
x/hacker_
/
h1/cdl
/
in/corben-leo

I enjoy hacking, building, and analyzing things.

I'm a co-founder of Boring Mattress Co.[EXT]↗see what we've built

Since 2016, I've been hacking organizations like the DoD, PayPal, Facebook, Google, Microsoft, Apple, etc. through bug bounties.

Writing & Research

#
Title
Published
01

A $1,000,000 bounty? The KuCoin User Information Leak

※2023-05-18
02

Adapting to Endure – A Summary.

※2022-11-29
03

A Simple SQL Injection in an Air Force Website

※2022-11-19
04

A Fun SSRF through a Headless Browser

※2022-05-06
05

Learn to Hack Web Apps

※2022-04-24
06

Exposed Jenkins to RCE on 8 Adobe Experience Managers

※2019-09-04
07

Analysis of an Atlassian Crowd RCE - CVE-2019-11580

※2019-07-14
08

CI Knew There Would Be Bugs Here

※2019-04-26
09

XSS to XXE in Prince v10 and below (CVE-2018-19858)

※2018-12-05
10

Advanced CORS Exploitation Techniques

※2018-06-16
11

Chaining Bugs to Steal Yahoo Contacts!

※2018-01-11
12

Hacking the Hackers: Leveraging an SSRF in HackerTarget

※2017-12-17
13

SQL Injection in rog.asus.com

※2017-11-30
14

Tricky CORS Bypass in Yahoo! View

※2017-11-27
15

H1-212 CTF Solution.pdf

※2017-11-24
16

PHP Code Injection in X-Cart

※2017-10-05
17

Stored XSS in Bandcamp

※2017-06-30
18

Multiple XSS & CSRF in Pulse Connect Secure v8.3R1

※2017-05-28
19

Reflected & Stored XSS in Invision Power Board

※2017-05-09
20

Remote Code Execution in AT&T

※2017-03-10
21

XSS in mail.aol.com

※2017-01-09
22

Leveraging LFI to RCE using zip://.

※2017-01-01
REF.01
Navigation
→Home→Blog
REF.02
Contact
§Twitter§GitHub§Email§LinkedIn
REF.03
Legal

©2025 Corben Leo. All rights reserved.

※Built with Next.js and TailwindCSS.