<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://whitton.io/archive/my-experience-with-the-paypal-bug-bounty-programme/</loc>
<lastmod>2012-10-12T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/archive/redirects-relative-protocols/</loc>
<lastmod>2012-10-16T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/archive/vodafone-no-pasting-into-password-fields/</loc>
<lastmod>2012-10-30T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://whitton.io/archive/persistent-xss-on-myworld-ebay-com/</loc>
<lastmod>2013-01-27T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://whitton.io/archive/framing-part-1-click-jacking-etsy/</loc>
<lastmod>2013-02-05T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/stealing-facebook-access-tokens-with-a-double-submit/</loc>
<lastmod>2013-04-13T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/overwriting-banner-images-on-etsy/</loc>
<lastmod>2013-05-21T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/hijacking-a-facebook-account-with-sms/</loc>
<lastmod>2013-06-26T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/removing-covers-images-on-friendship-pages-on-facebook/</loc>
<lastmod>2013-09-25T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/content-types-and-xss-facebook-studio/</loc>
<lastmod>2013-10-21T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/instagrams-one-click-privacy-switch/</loc>
<lastmod>2013-10-31T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/cookie-stealing-on-customer-internet-connections/</loc>
<lastmod>2013-11-19T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/abusing-cors-for-an-xss-on-flickr/</loc>
<lastmod>2013-12-12T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/safecurl-ssrf-protection-and-a-capture-the-bitcoins/</loc>
<lastmod>2014-05-19T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/safecurl-capture-the-bitcoins-post-mortem/</loc>
<lastmod>2014-05-26T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/bug-bounties-101-getting-started/</loc>
<lastmod>2014-07-29T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/bypassing-google-authentication-on-periscopes-admin-panel/</loc>
<lastmod>2015-07-20T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/messenger-site-wide-csrf/</loc>
<lastmod>2015-07-26T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/xss-on-facebook-via-png-content-types/</loc>
<lastmod>2016-01-27T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/uber-turning-self-xss-into-good-xss/</loc>
<lastmod>2016-03-22T00:00:00+00:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/obtaining-tokens-outlook-office-azure-account/</loc>
<lastmod>2016-04-03T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/articles/from-researcher-to-engineer-and-beyond/</loc>
<lastmod>2020-04-19T00:00:00+01:00</lastmod>
</url>
<url>
<loc>https://whitton.io/posts/</loc>
</url>
<url>
<loc>https://whitton.io/tags/</loc>
</url>
<url>
<loc>https://whitton.io/</loc>
</url>
<url>
<loc>https://whitton.io/about/</loc>
</url>
<url>
<loc>https://whitton.io/page2/</loc>
</url>
<url>
<loc>https://whitton.io/page3/</loc>
</url>
<url>
<loc>https://whitton.io/page4/</loc>
</url>
<url>
<loc>https://whitton.io/page5/</loc>
</url>
</urlset>
