Report a Vulnerability
Submit, help fixing, get kudos.
Start a Bug Bounty
Run your bounty program for free.
748,133 coordinated disclosures
438,261 fixed vulnerabilities
1148 bug bounties with 2,200 websites
20,689 researchers, 1257 honor badges

0xrocky Top VIP Security Researcher of the Month | Security Researcher Profile

Security researcher 0xrocky has already helped fix 1797 vulnerabilities.

Researcher reputation:  100

Real name:
Michele Corrias

About me:
I'm completing my M.Sc. degree in Computer Science at University of Milan (UniMi), Italy. More, I work for an ICT company in Milan.

How to contact me:
- e-mail: mhl dot crr at gmail dot com

Alternative Contacts:
- LinkedIn
- Twitter

Certifications & Diplomas:
- B.Sc. degree in Computer Science (UniMi)
- High school diploma

Experience in Application Security
< 1 year

Award / Bug Bounty I prefer:
A thanksgiving and a brief recommendation in my researcher profile will be really appreciated, but if you would like I'm open to:

- donations
- swag
- kudos
- hall of fame

Follow me on:

Recommendations and Acknowledgements

@fabriziopandol5     4 November, 2019
    Twitter fabriziopandol5 fabrizio pandolfi from Minsait (Indra Company):
Thanks 0xrocky for identifying an XSS vulnerability and for letting us know and helping solve it. His collaboration was fundamental to solving our problems. Great security researcher to work with. Keep up the good work!
@Cineca1969     18 October, 2019
    Twitter Cineca1969 Press Office from Cineca:
Thank you 0xrocky for identifying a vulnerability and making us aware of it. Great security researcher to work with. Keep up the good work!
@CosimoGdM     17 October, 2019
    Twitter CosimoGdM CGdM from I1G:
A kudos to 0xrocky for his professional work in not using the identified vulnerabilities and alerting us
@nickinckin     17 October, 2019
    Twitter nickinckin Nicola Inchingolo from Arpa Puglia:
Thanks to 0xrocky for identifying the vulnerability. Now we patched the vulnerability.
@DiEsse     13 September, 2019
    Twitter DiEsse DiEsse from Jobbydoo:
Big thanks to 0xrocky for identifying and responsibly disclosing a vulnerability on our site!

Please login via Twitter to add a recommendation

Honor Badges

Number of Secured Websites

10+ Secured Websites Badge
50+ Secured Websites Badge
500+ Secured Websites Badge
Web Security Veteran Badge
10+ Websites
50+ Websites
500+ Websites
1000+ Websites

Advanced Security Research

WAF Bypasser Badge
CSRF Master Badge
AppSec Logic Master Badge
Fastest Fix Badge
WAF Bypasser
CSRF Master
30+ Reports
AppSec Logic Master
30+ Reports
Fastest Fix
Fix in 24 hours

Outstanding Achievements

Secured OBB Badge
OBB Advocate Badge
Improved OBB Badge
Secured OBB
OBB Advocate
Improved OBB

Commitment to Remediate and Patch

Patch Master Badge
Patch Guru Badge
Patch Lord Badge
Patch Master
55% Patched
Patch Guru
65% Patched
Patch Lord
75% Patched

Recommendations and Recognition

10+ Recommends
25+ Recommends
50+ Recommends

Distinguished Blog Author

Distinguished Blog Author Badge
Distinguished Blog Author Badge
Distinguished Blog Author Badge
1 Post
3 Posts
5+ Posts

Research Statistics

Total reports:2090
Total reports on VIP sites:44
Total patched vulnerabilities:1797
Recommendations received:5
Active since:19.07.2019
Top Security Researcher Awards:Gold Star Top Security Researcher of the Month

Open Bug Bounty Certificate

Researcher Certificate

10.02.2020  Stored XSS on

17.10.2019  Stored XSS

I navigated this website:, an Italian web portal on construction. I found out that it was vulnerable to reflected XSS, as seen in the image.

Reflected XSS

Reported Vulnerabilities

All Submissions VIP SubmissionsFeatured Submissions

  Latest Patched


  Latest Blog Posts

25.12.2020 by _Y000_
How to bypass mod_security (WAF)
10.12.2020 by _Y000_
sql injection to bypass Mod_Security
10.12.2020 by _Y000_
Create encoded sql payloads
26.10.2020 by _r00t1ng_
Bypass Addslashes using Multibyte Character
26.10.2020 by _r00t1ng_
One Payload to Inject them all - MultiQuery Injection

  Recent Recommendations

@KodiMaster1     23 January, 2021
    Twitter KodiMaster1:
Good and professional report. I was a pleasure working with him!
@igucci     23 January, 2021
    Twitter igucci:
Thank you for the notification and quick & polite response.
Keep up the great work!
@randomthing4ev1     22 January, 2021
    Twitter randomthing4ev1:
Thank you for pointing out the vulnerability on our website! Very responsive.
@dtestitall     22 January, 2021
    Twitter dtestitall:
Thank you for finding the information disclosure vulnerability! Praveen was very responsive!
@hoshitabeman     21 January, 2021
    Twitter hoshitabeman:
It was very helpful for me to point out that I forgot to delete!