<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>/articles/2018-10/blind-xss-tokopedia-internal-panel-bahasa</loc>
<lastmod>2018-10-04T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2019-01/how-i-hack-antihack-me</loc>
<lastmod>2019-01-11T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2019-06/reflected-xss-on-error-page</loc>
<lastmod>2019-06-11T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2019-08/aws-metadata-disclosure-via-hardcoded-host-download</loc>
<lastmod>2019-08-21T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2019-09/exploiting-cookie-based-xss-by-finding-rce</loc>
<lastmod>2019-09-22T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2019-10/xss-to-account-takeover</loc>
<lastmod>2019-10-29T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2020-01/how-i-found-bug-google-search-console</loc>
<lastmod>2020-01-18T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2020-06/unvalidated-redirect-parameter-tampering-acc-takeover</loc>
<lastmod>2020-06-14T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2020-12/from-git-disclosure-to-remote-code-execution</loc>
<lastmod>2020-12-04T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2021-05/ssrf-in-pdf-renderer-using-svg</loc>
<lastmod>2021-05-19T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2021-06/local-file-read-via-error-based-xxe</loc>
<lastmod>2021-06-19T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/articles/2025-01/cegah-website-tampilkan-konten-judol-dengan-cloudflare-worker</loc>
<lastmod>2025-01-15T00:00:00+07:00</lastmod>
</url>
<url>
<loc>/categories/</loc>
<lastmod>2025-01-16T09:21:27+07:00</lastmod>
</url>
<url>
<loc>/tags/</loc>
<lastmod>2025-01-16T09:21:27+07:00</lastmod>
</url>
<url>
<loc>/archives/</loc>
<lastmod>2025-01-16T09:21:27+07:00</lastmod>
</url>
<url>
<loc>/term-of-use/</loc>
<lastmod>2025-01-16T09:21:27+07:00</lastmod>
</url>
<url>
<loc>/</loc>
</url>
<url>
<loc>/tags/bug-hunting/</loc>
</url>
<url>
<loc>/tags/hacking/</loc>
</url>
<url>
<loc>/tags/xss/</loc>
</url>
<url>
<loc>/tags/bahasa/</loc>
</url>
<url>
<loc>/tags/local-file-disclosure/</loc>
</url>
<url>
<loc>/tags/aws/</loc>
</url>
<url>
<loc>/tags/sql-injection/</loc>
</url>
<url>
<loc>/tags/rce/</loc>
</url>
<url>
<loc>/tags/csrf/</loc>
</url>
<url>
<loc>/tags/account-takeover/</loc>
</url>
<url>
<loc>/tags/google/</loc>
</url>
<url>
<loc>/tags/broken-access-control/</loc>
</url>
<url>
<loc>/tags/unvalidated-redirect/</loc>
</url>
<url>
<loc>/tags/parameter-tampering/</loc>
</url>
<url>
<loc>/tags/git-folder-disclosure/</loc>
</url>
<url>
<loc>/tags/file-upload/</loc>
</url>
<url>
<loc>/tags/php/</loc>
</url>
<url>
<loc>/tags/ssrf/</loc>
</url>
<url>
<loc>/tags/svg/</loc>
</url>
<url>
<loc>/tags/xxe/</loc>
</url>
<url>
<loc>/tags/java/</loc>
</url>
<url>
<loc>/tags/xliff/</loc>
</url>
<url>
<loc>/tags/cybersecurity/</loc>
</url>
<url>
<loc>/categories/bug-hunting/</loc>
</url>
<url>
<loc>/categories/cybersecurity/</loc>
</url>
<url>
<loc>/page2/</loc>
</url>
</urlset>
