<?xml version="1.0" encoding="utf-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">

  
  
    <url>
      <loc>https://herish.me/blog/starting-to-write-blogs-cybersecurity-journey/</loc>
      <lastmod>2025-08-28T18:01:19.317Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/privacy-policy/</loc>
      <lastmod>2025-09-05T00:00:00.000Z</lastmod>

      
        <changefreq>yearly</changefreq>
        <priority>0.4</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/terms-of-service/</loc>
      <lastmod>2025-09-05T00:00:00.000Z</lastmod>

      
        <changefreq>yearly</changefreq>
        <priority>0.4</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/0cl-request-smuggling/</loc>
      <lastmod>2025-09-09T15:47:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-where-clause-hidden-data/</loc>
      <lastmod>2025-09-23T22:06:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/the-ultimate-guide-to-sql-injection-sqli/</loc>
      <lastmod>2025-10-05T16:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-login-bypass/</loc>
      <lastmod>2025-10-06T18:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-union-column-count/</loc>
      <lastmod>2025-10-07T16:31:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-union-find-text-column/</loc>
      <lastmod>2025-10-08T17:05:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-union-retrieve-data/</loc>
      <lastmod>2025-10-09T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-union-multi-values-single-column/</loc>
      <lastmod>2025-10-10T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-database-type-version/</loc>
      <lastmod>2025-10-11T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-list-database-contents/</loc>
      <lastmod>2025-10-12T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-blind-conditional-responses/</loc>
      <lastmod>2025-10-13T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-blind-conditional-errors/</loc>
      <lastmod>2025-10-14T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-visible-error-based/</loc>
      <lastmod>2025-10-15T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-blind-time-delays/</loc>
      <lastmod>2025-10-16T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-blind-oob-interaction/</loc>
      <lastmod>2025-10-17T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-blind-oob-exfiltration/</loc>
      <lastmod>2025-10-18T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-filter-bypass-xml-encoding/</loc>
      <lastmod>2025-10-19T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-oracle-db-version/</loc>
      <lastmod>2025-10-20T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-oracle-listing-database-contents/</loc>
      <lastmod>2025-10-21T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/sqli-blind-time-delays-basic/</loc>
      <lastmod>2025-10-22T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/bounty-xss-sidefx-messaging/</loc>
      <lastmod>2025-10-23T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/idor-bug-bounty-burp-suite/</loc>
      <lastmod>2025-10-24T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/bac-unauthorized-pension-removal/</loc>
      <lastmod>2025-10-25T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/0click-account-takeover-punycode/</loc>
      <lastmod>2025-10-26T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/race-condition-double-signup/</loc>
      <lastmod>2025-10-27T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/earn-1k-month-info-disclosure/</loc>
      <lastmod>2025-10-28T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/xss-bug-hope-250/</loc>
      <lastmod>2025-10-29T16:59:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/bac-easy-130-user-to-admin/</loc>
      <lastmod>2025-10-30T05:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/ai-defend-vs-hackers-pentesters-reality/</loc>
      <lastmod>2025-10-31T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/otp-bypass-500-duplicate-lesson/</loc>
      <lastmod>2025-11-01T17:01:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/403-bypass-1000-bounty/</loc>
      <lastmod>2025-11-02T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/lfi-to-rce-5000-bounty/</loc>
      <lastmod>2025-11-03T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/authbypass-password-reset-4000-bounty/</loc>
      <lastmod>2025-11-04T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/authbypass-null-role-admin-takeover/</loc>
      <lastmod>2025-11-05T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/parameter-tampering-zero-eur-bug/</loc>
      <lastmod>2025-11-06T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/xss-url-waf-bypass/</loc>
      <lastmod>2025-11-07T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/auth-reset-flow-broken-validation/</loc>
      <lastmod>2025-11-08T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/local-api-rebinding-mcp/</loc>
      <lastmod>2025-11-09T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/xss-unsafe-eval-dom/</loc>
      <lastmod>2025-11-10T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/idor-master-key/</loc>
      <lastmod>2025-11-11T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/ai-model-extraction-training-data-heist/</loc>
      <lastmod>2025-11-12T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/access-control-apocalypse-broken-permissions/</loc>
      <lastmod>2025-11-13T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/vision-api-privacy-leakage/</loc>
      <lastmod>2025-11-14T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/prompt-injection-pandemonium/</loc>
      <lastmod>2025-11-15T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/voice-assistant-eavesdropper/</loc>
      <lastmod>2025-11-16T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/access-control-403-bypass/</loc>
      <lastmod>2025-11-17T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/privilege-escalation-token-forgery/</loc>
      <lastmod>2025-11-18T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/cloud-azure-speech-api-key-exposure/</loc>
      <lastmod>2025-11-19T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/dom-xss-nasa-hacking-story/</loc>
      <lastmod>2025-11-20T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/ssrf-gitlab-import-url-internal-network-probing/</loc>
      <lastmod>2025-11-21T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/auth-bypass-hardcoded-otp-government-app/</loc>
      <lastmod>2025-11-22T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/stripe-subscription-escalation-default-payment-behavior/</loc>
      <lastmod>2025-11-23T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/cache-poisoning-case-studies-part-1-foundational-attacks/</loc>
      <lastmod>2025-11-24T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/cache-poisoning-case-studies-part-2-advanced-cloud-framework-attacks/</loc>
      <lastmod>2025-11-25T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/cache-poisoning-case-studies-part-3-oauth-api-gateway-supply-chain/</loc>
      <lastmod>2025-11-26T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/spark-ar-rce-package-postinstall/</loc>
      <lastmod>2025-11-27T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/idor-pii-exposure-6-million-users/</loc>
      <lastmod>2025-11-28T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/cloudflare-origin-ip-bypass-misconfiguration/</loc>
      <lastmod>2025-11-29T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/reflected-xss-account-takeover-analysis/</loc>
      <lastmod>2025-11-30T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/idor-400-bad-request-document-name-disclosure/</loc>
      <lastmod>2025-12-01T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/modern-recon-ai-hunting/</loc>
      <lastmod>2025-12-02T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/oauth-authentication-bypass-pii-exposure-analysis/</loc>
      <lastmod>2025-12-03T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/ssrf-chatgpt-custom-actions-azure-metadata/</loc>
      <lastmod>2025-12-04T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/bugbounty-program-wins-researcher-loses/</loc>
      <lastmod>2025-12-05T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/identity-hijacking-email-schema-validation-bug/</loc>
      <lastmod>2025-12-06T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/401-error-information-disclosure/</loc>
      <lastmod>2025-12-07T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/cloud-storage-misconfiguration-ctf-storage-showdown-remastered/</loc>
      <lastmod>2025-12-08T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/ctf-sql-truncation-account-duplication/</loc>
      <lastmod>2025-12-09T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/react2shell-cve-2025-55182-cve-2025-66478-explained/</loc>
      <lastmod>2025-12-10T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/slowloris-dos-nodejs-cve-2018-12122-cve-2019-5739/</loc>
      <lastmod>2025-12-11T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/lfi-cloud-single-parameter-catastrophe/</loc>
      <lastmod>2025-12-12T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/reflected-xss-global-gaming-platform-case-study/</loc>
      <lastmod>2025-12-13T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/idor-enumeration-image-download-filename-prediction/</loc>
      <lastmod>2025-12-14T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/business-logic-account-entrapment-team-name-bypass/</loc>
      <lastmod>2025-12-15T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/bug-bounty-mistakes-before-first-bounty/</loc>
      <lastmod>2025-12-16T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/how-to-get-your-first-cve-as-a-beginner/</loc>
      <lastmod>2025-12-17T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/broken-auth-email-preferences-business-logic/</loc>
      <lastmod>2025-12-18T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/idor-predictable-filenames-image-download/</loc>
      <lastmod>2025-12-19T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/graphql-privilege-escalation-editor-to-owner/</loc>
      <lastmod>2025-12-20T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/websec-content-security-policy-complete-guide/</loc>
      <lastmod>2025-12-21T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/yelp-xss-cookie-smuggling-account-takeover/</loc>
      <lastmod>2025-12-22T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/how-to-test-for-idor-practical-methodology/</loc>
      <lastmod>2025-12-23T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/response-manipulation-business-logic-flaws/</loc>
      <lastmod>2025-12-24T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/blind-xss-rockstar-games-admin-panel/</loc>
      <lastmod>2025-12-25T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/five-bounties-one-ssrf-multiple-bypass-techniques/</loc>
      <lastmod>2025-12-26T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/file-inclusion-vulnerabilities-bug-bounty/</loc>
      <lastmod>2025-12-27T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/cve-2025-64446-fortiweb-rce-analysis/</loc>
      <lastmod>2025-12-28T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/reset-password-poisoning-host-header/</loc>
      <lastmod>2025-12-29T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/csrf-vulnerability-high-bounty-full-breakdown/</loc>
      <lastmod>2025-12-30T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/idor-unauthorized-access-user-pii/</loc>
      <lastmod>2025-12-31T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/nasa-appreciation-letter-cve-2025-0133-xss/</loc>
      <lastmod>2026-01-01T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/header-based-idor-client-controlled-account-id/</loc>
      <lastmod>2026-01-02T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/critical-idor-university-student-data-exposure/</loc>
      <lastmod>2026-01-03T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/email-verification-bypass-full-organization-takeover/</loc>
      <lastmod>2026-01-04T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/info-disclosure-revive-adserver-verbose-errors/</loc>
      <lastmod>2026-01-11T17:00:00.000Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.5</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/about/</loc>
      <lastmod>2026-01-11T17:03:17.509Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.7</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/blog/</loc>
      <lastmod>2026-01-11T17:03:17.517Z</lastmod>

      
        <changefreq>daily</changefreq>
        <priority>0.9</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/contact/</loc>
      <lastmod>2026-01-11T17:03:17.517Z</lastmod>

      
        <changefreq>monthly</changefreq>
        <priority>0.7</priority>
      
    </url>
  

  
  
    <url>
      <loc>https://herish.me/</loc>
      <lastmod>2026-01-11T17:03:17.517Z</lastmod>

      
        <changefreq>weekly</changefreq>
        <priority>1.0</priority>
      
    </url>
  

</urlset>
