Lautaro Colombo

    • About
  • One-Click Account Takeover: From XSS to Session Token Exfiltration

    Sep 18, 2025

    —

    by

    lcolombo
    in bug bounty

    On a recent pentest I was able to chain an Open Redirect + XSS to exfiltrate session tokens, only needing for a user to click on a link. Open Redirect on redirectUrl While browsing the site, I noticed that the…

  • Week in Review – #24

    Jun 25, 2025

    —

    by

    lcolombo
    in bug bounty, week in review

    To revive the blog I will begin a Week in Review series, where I write some notes about my previous week doing bug bounty work, with some ideas, notes and reflections of the process and what I’ve done.  I used to do…

lcolombo Avatar

About the author

Pentester and Security Researcher interested in all things offensive security.

Popular Categories

  • bug bounty (2)
  • week in review (1)


Search the website

Blog at WordPress.com.

  • Subscribe Subscribed
    • Lautaro Colombo
    • Already have a WordPress.com account? Log in now.
    • Lautaro Colombo
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar