<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xmlns:xhtml="http://www.w3.org/1999/xhtml">
  <url>
    <loc>https://machevalia.blog/blog</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2025-11-08</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/cve-2025-56385-wellsky-harmony-sql-injection</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-11-08</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/multiple-vulnerabilities-in-centralsquare-etrakit-and-ivr</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-11-08</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/cve-2023-46013-eramba-community-edition-v3211-insecure-direct-object-reference-idor</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-11-08</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/215a7ed8-9572-4b53-98c8-e7bfb0d3e609/e5492c7e-0f51-4b47-95c4-c296fa2bc528.png</image:loc>
      <image:title>Blog - CVE-2023-46013 Eramba Community Edition v3.21.1 - Insecure Direct Object Reference (IDOR) - Make it stand out</image:title>
      <image:caption>Right click elipses of attachment to copy link address.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/7018c72b-c2f7-4b80-8f84-378d8b2b7f55/a9cb54e4-dc37-4191-8029-423741eb527c.png</image:loc>
      <image:title>Blog - CVE-2023-46013 Eramba Community Edition v3.21.1 - Insecure Direct Object Reference (IDOR) - Make it stand out</image:title>
      <image:caption>Attachment with direct object number in URL.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/6ef27df3-f672-493e-b75e-6f263a7fbdbf/1ddfbeca-02cc-4e03-a55e-4d85a206eb35.png</image:loc>
      <image:title>Blog - CVE-2023-46013 Eramba Community Edition v3.21.1 - Insecure Direct Object Reference (IDOR) - Make it stand out</image:title>
      <image:caption>Add attachment.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/when-uploads-break-xss-defenses</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2025-11-08</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/fc71e455-3e1d-42dc-97fc-0091ff12405c/svg_xss_example.png</image:loc>
      <image:title>Blog - When File Uploads Break XSS Defenses - Make it stand out</image:title>
      <image:caption>XSS via inlined SVG</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/the-dark-side-of-xss-weaponizing-xss-to-manipulate-and-deceive-for-social-engineering-purposes</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2023-03-29</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/the-freedom-in-being-different-how-courage-can-change-your-life</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2023-03-19</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/letsdefend-soc164-suspicious-mshta-behavior-walkthrough</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2023-02-05</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/923402ad-116a-4bc7-8503-d7a4a4d79972/lolbas-mshta-execute.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/4af84eb2-9535-4a07-bbe0-a3d9343063b9/ChatGPT.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/a81e132e-8cdb-4a80-ac40-fd20a4a5be98/clean_break_PS.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/93d978b1-566d-438a-8eea-6dcb56398b2b/alert-details.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/53accc09-e5c2-4a08-8a2f-97807fcdcedc/process-history.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/fc0b2b0b-d6a9-4654-b09d-4946633e5dc3/ChatGPT2.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/2a8ffb6d-8e8f-41b0-a982-53f17db5b9cb/parent-process-breakdown.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/844c7792-de19-49cb-a111-74e60f0265ad/cmdhistory.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/c4c97e03-7b10-4889-aba6-a7c1ea7c61e3/log-search.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/5c901370-40dd-420e-8595-6292d669ea8c/endpoint-security.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/75746b8e-fbfd-4b12-aeb9-c41507567999/virustotal.png</image:loc>
      <image:title>Blog - LetsDefend SOC164 - Suspicious Mshta Behavior Walkthrough - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/oscp-review</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2023-02-01</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/72b390a2-b260-44e6-b57b-33286e875835/oscp.png</image:loc>
      <image:title>Blog - OSCP Review - Make it stand out</image:title>
      <image:caption>Whatever it is, the way you tell your story online can make all the difference.</image:caption>
    </image:image>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/2022-bug-bounty-year-in-review</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-12-29</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/oswa-web-200-experience</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-12-29</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/red-team-tactics-loiding-a-door</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-12-29</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/cve-2022-34002-personnel-data-systems-pds-vista-7-local-file-inclusion</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-12-20</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/cve-2022-26959-northstar-club-management-software-version-6-3-full-blind-time-based-sql-injection</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-12-20</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/ivanti-epm-remote-code-execution</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-06-05</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/broken-access-control-idor</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-12-20</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/sqli-and-rce-in-quicklert-for-digium</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-02-22</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/access-control-violation-sensitive-data-exposure</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-02-19</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/remote-code-execution-in-tgz-file-upload</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-01-30</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/stored-cross-site-scripting-in-mediawiki</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-01-28</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/access-control-violation-wiki-page-creation</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-01-26</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/year-in-progress-2022</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <lastmod>2022-12-20</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Write+Ups</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Tutorial</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Experience</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Reviews</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Professional</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Opinion</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Vulnerability+Disclosure</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/General</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Uncategorized</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Mental+Health</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Bug+Bounty</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/category/Self+Development</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/CVE-2021-43970</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/Write-up</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/WEB-200</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/Year-in-Review</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/OSWA</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/Hacking</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/Public+Disclosure</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/CVE-2021-43969</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/Vulnerability+Disclosure</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/OffensiveSecurity</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/OffSec</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/Red+Teaming</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/blog/tag/Bug+Bounty</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://machevalia.blog/home</loc>
    <changefreq>daily</changefreq>
    <priority>1.0</priority>
    <lastmod>2025-10-03</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/91a7e6b1-c645-486c-8ea6-103dc415385d/20220401_095138.jpg</image:loc>
    </image:image>
  </url>
  <url>
    <loc>https://machevalia.blog/about</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2025-11-08</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/91a7e6b1-c645-486c-8ea6-103dc415385d/20220401_095138.jpg</image:loc>
    </image:image>
  </url>
  <url>
    <loc>https://machevalia.blog/videos</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2023-03-19</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/videos-1</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2022-12-17</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/courses</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2022-12-28</lastmod>
    <image:image>
      <image:loc>https://images.squarespace-cdn.com/content/v1/639bcf9ae1aabb6394c4c281/1672259066232-GJI0H3B3HY6P5A87CGER/unsplash-image-NoOrDKxUfzo.jpg</image:loc>
    </image:image>
  </url>
  <url>
    <loc>https://machevalia.blog/contact</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2023-02-05</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/references</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2022-12-20</lastmod>
  </url>
  <url>
    <loc>https://machevalia.blog/store</loc>
    <changefreq>daily</changefreq>
    <priority>0.75</priority>
    <lastmod>2023-02-03</lastmod>
  </url>
</urlset>

