<?xml version="1.0" encoding="utf-8" standalone="yes"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml"><url><loc>https://mazinahmed.net/blog/publishing-malicious-vscode-extensions/</loc><lastmod>2025-12-06T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/</loc><lastmod>2025-12-06T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/posts/</loc><lastmod>2025-12-06T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/preventing-prompt-injection-attacks-at-scale/</loc><lastmod>2025-06-09T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/llmquery-project/</loc><lastmod>2025-01-13T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/crowdstrike-incident-engineering-learnings/</loc><lastmod>2024-07-26T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/secrets-patterns-db/</loc><lastmod>2023-02-07T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/speaking-at-blackhat-mea-2022/</loc><lastmod>2022-12-05T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/demystfying-practical-dos-attacks-talk/</loc><lastmod>2022-12-04T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/shennina-exploitation-framework/</loc><lastmod>2022-11-08T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/tfplan-release/</loc><lastmod>2022-10-27T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/indepth-analysis-twitch-security-tools/</loc><lastmod>2022-06-01T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/attacking-terraform-environments/</loc><lastmod>2022-01-29T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/interview-with-appsec-podcast-terraform-security/</loc><lastmod>2021-10-17T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/tfquery-project-release/</loc><lastmod>2021-04-28T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/stressful-ddos-framework/</loc><lastmod>2021-04-13T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/interview-with-sectastic-podcast/</loc><lastmod>2021-03-22T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/hacking-zoom/</loc><lastmod>2020-08-09T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/covid19-and-cybersecurity/</loc><lastmod>2020-04-14T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/testing-for-path-traversal-with-python/</loc><lastmod>2020-04-12T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/ohmyzsh-dotenv-rce/</loc><lastmod>2020-04-08T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/wasec-book-review/</loc><lastmod>2020-03-29T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/breaking-jwt/</loc><lastmod>2019-10-25T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/search-engine-abuse-in-popular-social-networks/</loc><lastmod>2019-05-17T12:03:11+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/swiss-evoting-system-security/</loc><lastmod>2019-04-16T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/backchannel-leaks-on-strict-csp-policy/</loc><lastmod>2019-01-18T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/practical-protection-against-dns-rebinding-attacks/</loc><lastmod>2018-07-31T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/creating-emojis-php-webshell/</loc><lastmod>2018-07-23T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/html-attribute-separators/</loc><lastmod>2018-07-17T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/bypassing-csp-by-abusing-jsonp-endpoints/</loc><lastmod>2018-01-16T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/modsecurity-handbook-2nd-edition-review/</loc><lastmod>2017-10-03T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/starting-in-infosec-101/</loc><lastmod>2017-08-11T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/using-ubuntu-desktop-as-malware-vector/</loc><lastmod>2017-04-08T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/exploiting-misconfigured-apache-server-status-instances/</loc><lastmod>2017-01-13T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/bug-bounty-hunting-swiss-cyber-storm/</loc><lastmod>2016-10-23T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/backup-file-artifacts/</loc><lastmod>2016-08-18T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/google-ui-redressing-bug-that-discloses-email-addresses/</loc><lastmod>2016-04-08T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/bypassing-noscript-security-suite/</loc><lastmod>2016-03-17T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/firefox-security-toolkit/</loc><lastmod>2015-11-03T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/evading-all-web-application-firewalls/</loc><lastmod>2015-09-09T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/bypassing-google-password-alert/</loc><lastmod>2015-07-25T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/facebook-messenger-multiple-csrf/</loc><lastmod>2015-06-09T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/summary-of-hsts-support-in-modern-browsers/</loc><lastmod>2015-05-29T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/my-experience-with-ebay-bug-bounty/</loc><lastmod>2015-04-24T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/w3-total-fail/</loc><lastmod>2014-12-11T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/session-hijacking-in-instagram-mobile/</loc><lastmod>2014-07-26T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/my-story-with-onavo/</loc><lastmod>2014-06-09T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/cross-site-scripting-on-wikileaks/</loc><lastmod>2014-02-19T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/code-execution-on-bugcrowd/</loc><lastmod>2014-02-13T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/acknowledged-by-oracle/</loc><lastmod>2014-02-06T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/open-redirector-on-google/</loc><lastmod>2014-02-06T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/blog/university-of-calgary/</loc><lastmod>2014-02-06T00:00:00+00:00</lastmod></url><url><loc>https://mazinahmed.net/about/</loc></url><url><loc>https://mazinahmed.net/blog/</loc></url><url><loc>https://mazinahmed.net/cv/</loc></url><url><loc>https://mazinahmed.net/hire-me/</loc></url><url><loc>https://mazinahmed.net/awards/</loc></url><url><loc>https://mazinahmed.net/press/</loc></url><url><loc>https://mazinahmed.net/projects/</loc></url></urlset>