<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0xGaphy</title><description>Cybersecurity writeups, CTF guides, and offensive security notes.</description><link>https://abdulgaphy.vercel.app/</link><item><title>Change Somebody Else&apos;s Password, Why Don&apos;t You</title><link>https://abdulgaphy.vercel.app/posts/pentest/change-somebody-elses-password/</link><guid isPermaLink="true">https://abdulgaphy.vercel.app/posts/pentest/change-somebody-elses-password/</guid><description>A password-change endpoint that trusted the email in the request body instead of the session that sent it.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item><item><title>None of Your Business — Bypassing JWT Signature Validation</title><link>https://abdulgaphy.vercel.app/posts/pentest/none-of-your-business/</link><guid isPermaLink="true">https://abdulgaphy.vercel.app/posts/pentest/none-of-your-business/</guid><description>How a forgotten &apos;alg: none&apos; code path turned a read-only audit token into full admin access.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>