This host serves proof-of-concept artifacts attached to vulnerability reports
submitted through authorized bug bounty programs. Each artifact lives at an
unguessable path of the form /p/<id>/<name>.html or
/p/<id>/<name>.py, and the link is shared only inside
the report it belongs to.
There is no index, no directory listing, and no upload endpoint. Content is published over SSH by the researcher and is static — nothing here executes on this server.
If you are a triager or a security team and reached this page from a report, the full artifact URL is in the report body. If you believe something here is being misused, or you want an artifact taken down, contact the researcher via the report thread or at the profiles below.
bugcrowd.com/h/SergioC · hackerone.com/sergioc
Artifacts are published solely to help a receiving security team reproduce an issue they have invited testing on, and are removed once the corresponding report is closed.