↓ Skip to Main Content

Graham Bleaney

Main Navigation

  • Home
  • Work Experience
    • Application Security Engineer – Meta (formerly Facebook)
    • Software Developer – Bloomberg L.P.
    • Software Developer (Contract) – Bloomberg L.P.
    • Application Security Engineer Intern – Palantir
    • Forward Deployed Engineer Intern – Palantir
    • Product Manager Intern – Yelp
    • Software Developer Intern – Bloomberg L.P.
    • Developer Intern – Embium
    • Software Developer Intern – Desire2Learn
  • Software Projects
    • Distributed Computing WiFi Access Point
    • Route Optimizer
    • This Website
    • Appy
    • Balife Inc – Shad Valley Project
      • Original Business Plan
      • Shad Cup Business Plan
      • Source Code
      • Technical Specifications
      • User Manual
    • RFID Scanning Cart
      • Presentation
      • Report
    • Cannon Game
      • Disclaimer and Bugs
      • Game Source Code
      • Notes to Future Programmers
      • Program Overview and Intro
    • Graphing Program
  • Public Speaking
  • Research
    • Machine Learning to Detect Product Safety Issues
    • Runtime Performance of Memory Allocation Strategies in C++
  • Security
    • CTF
    • Blog
  • Hardware Projects
    • Remote Control
      • Remote Source Code
    • Tic Tac Toe
    • CHRP Robot
  • Artwork
    • Self Portrait
    • Magazine Cover
  • Resume
  • Info

Year: 2015

Breaking the Bank – Money and Credential Theft in Venmo (Paypal Product)

By user Posted on May 16, 2015 Posted in Blog Tagged with account-takeover, security, venmo, xss

Abstract I identified a reflected cross site scripting (XSS) vulnerability on the login page of Venmo’s website, and used it to develop a proof of concept exploit that could drain a user’s account and steal their credentials. The effects of this …

Breaking the Bank – Money and Credential Theft in Venmo (Paypal Product) Read more »

Developing an account takeover worm for Pixelapse (Dropbox product)

By user Posted on March 23, 2015 Posted in Blog Tagged with account-takeover, pixelapse, security, xss

Intro In this writeup, I go through the process of finding, and then weaponizing two simple bugs to develop a powerful exploit against Pixelapse. I tried to write this in as friendly a way as possible, to be understandable by people with …

Developing an account takeover worm for Pixelapse (Dropbox product) Read more »

Copyright © 2025 Graham Bleaney | Powered by Responsive Theme