<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://ayoubsafa.com/posts/Old-but-Gold-Exploiting-ASP.NET-Padding-Oracle-MS10-070/</loc>
<lastmod>2018-06-15T18:00:00+01:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/posts/Think-Outside-the-Scope-Advanced-CORS-Exploitation-Techniques/</loc>
<lastmod>2019-05-14T18:00:00+01:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/posts/The-Bad-Twin-a-peculiar-case-of-JWT-exploitation-scenario/</loc>
<lastmod>2020-05-07T18:00:00+01:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/posts/Story-of-Command_injection_worth_$7500/</loc>
<lastmod>2021-10-15T18:00:00+01:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/posts/Bsides-Leeds-Talk-2023/</loc>
<lastmod>2023-07-08T16:00:00+01:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/posts/SteelCon-Talk-2023/</loc>
<lastmod>2023-07-08T16:00:00+01:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/posts/Neo4j_injection_(Cypher-Injection)/</loc>
<lastmod>2025-01-30T17:00:00+00:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/about/</loc>
<lastmod>2026-02-11T12:58:12+00:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/archives/</loc>
<lastmod>2026-02-11T12:58:12+00:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/categories/</loc>
<lastmod>2026-02-11T12:58:12+00:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/tags/</loc>
<lastmod>2026-02-11T12:58:12+00:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/padding-oracle/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/path-traversal/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/asp-net/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/cors/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/xss/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/csrf/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/javascript/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/jwt/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/ato/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/acoount-takeover/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/command-injection/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/rce/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/out-of-band/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/oob/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/uuid/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/account-takeover/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/password-reset/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/idor/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/sqli/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/neo4j/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/cypher/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/burp/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/time-based-payload/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/tags/out-of-band-payload/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/padding-oracle/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/path-traversal/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/asp-net/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/cors/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/xss/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/csrf/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/javascript/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/jwt/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/ato/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/acoount-takeover/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/command-injection/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/rce/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/out-of-band/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/oob/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/uuid/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/account-takeover/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/password-reset/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/idor/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/sqli/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/neo4j/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/cypher/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/burp/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/time-based-payload/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/categories/out-of-band-payload/</loc>
</url>
<url>
<loc>https://ayoubsafa.com/assets/pdf/bsides_leeds_ayoubsafa.pdf</loc>
<lastmod>2026-02-11T12:57:46+00:00</lastmod>
</url>
<url>
<loc>https://ayoubsafa.com/assets/pdf/steelcon_ayoubsafa.pdf</loc>
<lastmod>2026-02-11T12:57:46+00:00</lastmod>
</url>
</urlset>
