← Back to list

RXSS — My First Official Vulnerability: A Significant Step in My Cybersecurity Journey

[Repost]

t1lt45 · 2026-05-29 19:12 · 0 claps · 2.6 min read
#xs #vulnerability
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

RXSS — My First Official Vulnerability: A Significant Step in My Cybersecurity Journey

[Repost]

Today, I want to share a milestone in my career in CyberSecurity: I identified my first official vulnerability, a Reflected Cross-Site Scripting (RXSS). 🚀

What is RXSS?

  • Explaining in a simple and direct way what RXSS is. — The Reflected Cross-Site Scripting (RXSS) vulnerability happens when a website “reflects” something you type or click on, without verifying that it is safe. This can allow someone malicious to send you a special link. When you click, the site runs hidden code that can, for example, steal your information or do something on the site as if it were you.
  • Simple example — Imagine you are on a search engine. You type in “pizza” and the site responds with “Results for pizza”. If the site doesn’t verify what you’ve typed, someone could create a malicious link that, instead of searching for “pizza”, sends a code to steal your information. And because the site shows it back without checking, the code ends up being executed in your browser.
  • How to avoid this? — Websites can fix this by checking everything they receive before showing it back. That way, they ensure that they only display safe things.

The moment I joined the project

— When I joined the project, I was very excited, but in a way scared and anxious, because it was my first time as a Pentester benginner in the REAL CORPORATE WORLD. We were presented with the scope of the project:

  • Black Box: This physical test, attempting to gain access to the building of which one of the branches is a part.
  • Gray Box: Process of analysis, investigation and attempts to access or collect data that we should not have access to.

Based on the scope presented and without much idea of where to go, I had a lot of guidance and instructions from the Pentester responsible for the project, which basically showed me the way.

What were your initial analysis and what sparked your curiosity/insight to discover the vulnerability? And when the pop-up came, what was the reaction?

Starting with my initial analysis: I started with the site even though I’m just “curious” (we need to be curious), as I’m currently looking at some content and studies on Web Attack, I started there, what I already had so far, I started to analyze the behavior of the site, going through all the tabs, buttons, forms, searches, until… On one of these screens I started to put payloads in <html> even without forcing the page too much, until I changed it by the payload used (print below).

“Entrei em choque quando apareceu o pop-up 🤣” (I was desperate when the pop-up appeared🤣) — I’ll leave you with a small piece of evidence: a screenshot with my T1LT4S tag, symbolizing this special moment.

  • Then… BOOM the pop-up on my screen, I froze at first 😅 I couldn’t believe what I was seeing because it was my first discovery, I tested it again to make sure in another browser (still incredulous) and BOOM, pop-up on the screen again.
  • Afraid I’d done something wrong, not least because it’s a private project, I went to talk to the person in charge of the project to inform him of the discovery I’d just made.
  • And that was basically the process from the moment the project was presented to me and I was included in it.

I will continue to evolve and contribute to meeting the challenges of security in the digital world.

I will continue to evolve and contribute to meeting the challenges of security in the digital world.

I hope I’ve contributed in some way. See you!


메타데이터
post_id
5dfe41a23fa3
slug
rxss-my-first-official-vulnerability-a-significant-step-in-my-cybersecurity-journey-5dfe41a23fa3
url
https://medium.com/@0xtiltas/rxss-my-first-official-vulnerability-a-significant-step-in-my-cybersecurity-journey-5dfe41a23fa3
canonical_url
https://medium.com/@0xtiltas/rxss-my-first-official-vulnerability-a-significant-step-in-my-cybersecurity-journey-5dfe41a23fa3
author_url
https://medium.com/@0xtiltas
status
ok
fetched_at
2026-06-10 08:17:25