<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>tpaidakis</title><link>https://tpaidakis.com/</link><description>Recent content on tpaidakis</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 00:00:00 +0300</lastBuildDate><atom:link href="https://tpaidakis.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Your login failed. The attack didn't. Stored XSS in OpenClaw Dashboard</title><link>https://tpaidakis.com/writeups/openclaw-dashboard-stored-xss/</link><pubDate>Mon, 03 Aug 2026 00:00:00 +0300</pubDate><guid>https://tpaidakis.com/writeups/openclaw-dashboard-stored-xss/</guid><description>Two stored XSS bugs in OpenClaw Dashboard, both the same missing encode on the way to innerHTML. One is reachable by an unauthenticated visitor through the login form, the other fires on a background timer with no admin click at all.</description></item><item><title>Who owns this secret? Nobody. Great, that's me: deleting secrets in Password Pusher</title><link>https://tpaidakis.com/writeups/passwordpusher-nil-authorization/</link><pubDate>Sun, 02 Aug 2026 00:00:00 +0300</pubDate><guid>https://tpaidakis.com/writeups/passwordpusher-nil-authorization/</guid><description>An unauthenticated visitor holding only a Password Pusher link could permanently destroy the secret behind it, even with deletable_by_viewer turned off, because the ownership check compared two nils and Ruby said they matched.</description></item><item><title>When Zero Minus One Is Four Billion: Three Unauthenticated DoS Bugs in facil.io</title><link>https://tpaidakis.com/writeups/facilio-parser-dos/</link><pubDate>Thu, 30 Jul 2026 00:00:00 +0300</pubDate><guid>https://tpaidakis.com/writeups/facilio-parser-dos/</guid><description>Three unauthenticated denial-of-service bugs in facil.io&amp;rsquo;s hand-written HTTP and multipart parsers, all the same shape: a value that is correct where it is computed and wrong by the time someone uses it.</description></item><item><title>CVE-2026-66748: Sir, Your Dropdown Is Running Bash: Finding RCE in Camaleon CMS</title><link>https://tpaidakis.com/writeups/camaleon-cms-rce-select-eval/</link><pubDate>Wed, 29 Jul 2026 00:00:00 +0300</pubDate><guid>https://tpaidakis.com/writeups/camaleon-cms-rce-select-eval/</guid><description>A select field with Ruby eval support and no sanitization becomes a remote code execution vector in Camaleon CMS, exploitable by any editor-level account.</description></item><item><title>About</title><link>https://tpaidakis.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://tpaidakis.com/about/</guid><description>&lt;p&gt;I&amp;rsquo;m a penetration tester in the payments sector - most of my time is in PCI DSS scope. Before offensive security I spent several years as a software engineer.&lt;/p&gt;
&lt;p&gt;I hold a BSc in Software Engineering and an MSc in Cybersecurity. Growing up I was running scripts I barely understood and poking at things I probably should not have been. The interest was always there, it just took a while to become a job.&lt;/p&gt;</description></item></channel></rss>