Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4852POODLE SSLv3 bug on multiple twitter smtp servers Cryptographic issues Twitter Omar Espino (@omespino) Bug Bounty2018-02-212023-06-13
3638A mysterious bug in the firmware of Google%27s Titan M chip (CVE-2019-9465) Cryptographic issues Google Alexander Bakker Bug Bounty2020-02-292023-06-13
3483Weak Cryptography in Password Reset to Full Account Takeover Account takeover Password reset Cryptographic issues NA Harsh Bothra (@harshbothra_) Bug Bounty2020-05-152023-06-13
3135Advisory: security issues in AWS KMS and AWS Encryption SDKs Cryptographic issues Information disclosure AWS Thai Duong (@XorNinja) Bug Bounty2020-09-252023-06-13
3028Weak Cryptography to Account Takeover’s Cryptographic issues Account takeover IDOR NA letmeslidein (@VasuYadaav) Bug Bounty2020-11-152023-06-13
2952Hack crypto secrets from heap memory to exploit Android application Cryptographic issues NA secureITmania (@secureitmania) Bug Bounty2020-12-222023-06-13
1907Finding vulnerabilities in Swiss Post’s future e-voting system - Part 1 Insecure deserialization Cryptographic issues Swiss Post Ruben Santamarta (@reversemode) Bug Bounty2022-01-182023-06-13
1609CVE-2022-21449: Psychic Signatures in Java Signature bypass Cryptographic issues Oracle Neil Madden (@neilmaddog) Bug Bounty2022-04-192023-06-13
1529Finding vulnerabilities in Swiss Post%27s future e-voting system - Part 2 Insecure deserialization Cryptographic issues NA Ruben Santamarta (@reversemode) Bug Bounty2022-05-222023-06-13
1482ed25519-unsafe-libs Cryptographic issues NA Konstantinos Chalkias Bug Bounty2022-06-112023-06-13
1469Cryptographic Side-Channels (Timing Leaks) in JSBN Cryptographic issues Side-channel attack Timing attack Xfinity Opensource Soatok (@SoatokDhole) Bug Bounty2022-06-142023-06-13
1464Hertzbleed Attack Side-channel attack Hardware hacking Cryptographic issues Intel Cloudflare Microsoft Yingchen Wang (@YingchenWang96) Bug Bounty2022-06-142023-06-13
1174ASP.NET Boilerplate Multiple Vulnerabilities Authentication flaw Hardcoded credentials JWT Padding oracle attack Cryptographic issues Volosoft (ASP.NET Boilerplate) Sana Oshika (@bigshika) Bug Bounty2022-08-262023-06-13
1128How to Decrypt Manage Engine PMP Passwords for Fun and Domain Admin - a Red Teaming Tale Cryptographic issues Zoho (ManageEngine) smaury (@smaury92) Bug Bounty2022-09-052023-06-13
1022Practically-exploitable Cryptographic Vulnerabilities in Matrix Cryptographic issues Matrix Martin Albrecht (@martinralbrecht) Bug Bounty2022-09-282023-06-13
1016ECDSA Nonce Reuse Cryptographic issues NA Ingredous Labs Bug Bounty2022-09-292023-06-13
940Yet Another Telerik UI Revisit Cryptographic issues RCE Progress (Telerik) Paul Mueller Bug Bounty2022-10-192023-06-13
927SHA-3 Buffer Overflow Buffer Overflow Memory corruption Cryptographic issues XKCP Apple Python PHP PyPy SHA3 for Ruby Nicky Mouha Bug Bounty2022-10-202023-06-13
925The Curious Case Of The Password Database Cryptographic issues Zoho (ManageEngine) Travis Kaun (@W9HAX) Bug Bounty2022-10-202023-06-13
840Security and Privacy Failures in Popular 2FA Apps Cryptographic issues LastPass Google Twilio Microsoft Duo Salesforce Latch Zoho Conor Gilsenan Bug Bounty2022-11-112023-06-13
839Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures Signature bypass Signature forgery Cryptographic issues Windows Microsoft Simon Rohlmann Bug Bounty2022-11-112023-06-13
678Better Make Sure Your Password Manager Is Secure Hardcoded credentials XSS Cryptographic issues Authorization flaw Authentication bypass Click Studios kuekerino (@kuekerino) Bug Bounty2022-12-192023-06-13
543Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI Windows Cryptographic issues Microsoft Tomer Peled Bug Bounty2023-01-252023-06-13
502WEEKEND DESTROYER - RCE in Western Digital PR4100 NAS RCE Hardcoded credentials Privilege escalation Cryptographic issues Security code review Western Digital Pedro Ribeiro (@pedrib1337) Bug Bounty2023-02-022023-06-13
474Cracking The Odd Case Of Randomness In Java Cryptographic issues NA Joseph (@josep68_) Bug Bounty2023-02-092023-06-13