Luck: When Blind Payloads Strike Gold

▶ Watch (2:36)

Landry spray-prayed blind XSS payloads into a cloud compliance app. One payload popped in a CSV file viewed via QuickLook CSV, a 16-year-old Mac plugin. The file contained org IDs, AWS account IDs, and partial credit card data. The program rewarded it as a P1. Another blind XSS payload fired inside an internal email after a user filed a complaint. That complaint contained Landry’s payload, triggering a four-digit bounty. The user later messaged him on Twitter, upset but then helpful.

WTF: Ansible Server-Side Template Injection

▶ Watch (10:47)

Landry registered an account with an SSTI payload (double curly brackets 7*7) in his email. The email rendered to 49 in phpMyAdmin, confirming template evaluation. He asked the program and learned the API passed data through a Python serverless function, then Ansible. Ansible uses Jinja2, which evaluates double curly brackets. Landry used Ansible’s playbook_dir magic variable to confirm the engine, then abused the pipe lookup plugin to run arbitrary commands. The payload encoded parentheses as hex to bypass input restrictions. The command ran as root.

LOL: Password Filter Creates Thousands of Unprotected Leagues

▶ Watch (23:03)

A fantasy sports app filtered XSS payloads from the password field by stripping HTML-like tags. This also stripped the ‘<’ character from any password containing it. A password like “I love dogs” became “I”. Random passwords could become single characters or empty. Admins did not know, and invites sent passwords in clear text. Landry brute-forced the first two characters to join over a thousand private leagues. 56 leagues had no password at all, allowing free entry.

Notable Quotes

even though this isn’t a vulnerability in our application per se, we are cons considering this a P1 Jasmin “JR0ch17” Landry · ▶ Watch (5:51)

you and your friends ruined a fine experiment. You should be ashamed of yourself Jasmin “JR0ch17” Landry · ▶ Watch (9:12)

Man, you got you ruined my day. I waste a lot of time on what you did. Jasmin “JR0ch17” Landry · ▶ Watch (9:56)

by the way, that email, I don’t own it. It was just like to show that it was possible. Jasmin “JR0ch17” Landry · ▶ Watch (22:02)

Key Takeaways

  • Spray-and-pray blind XSS can expose production data through third-party plugins.
  • Email address fields are a common injection point for SSTI across backend stacks.
  • Input sanitization that strips HTML-like characters can accidentally weaken passwords.

About the Speaker(s)

Jasmin Landry is a seasoned ethical hacker and full-time bug bounty hunter who has reported hundreds of security vulnerabilities to some of the world’s largest tech companies. After years leading cybersecurity efforts as Senior Director of Information Security at Nasdaq, Jasmin returned to his roots in hacking — now focusing exclusively on uncovering critical bugs through bug bounty platforms. Recognized at multiple live hacking events for top findings, he brings a sharp eye for unexpected issues and a deep understanding of modern attack surfaces. He’s also a co-leader of OWASP Montréal and an active voice in the security research community.