Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2626Harvesting Active Directory credentials via HTTP Request Smuggling HTTP request smuggling NA Tijme Gommers (@tijme) Bug Bounty2021-04-192023-06-13
2469Certified Pre-Owned Active Directory Privilege Escalation ADCS Windows Microsoft Will Schroeder (@harmj0y) Bug Bounty2021-06-172023-06-13
2068CVE-2021-42306 CredManifest: App Registration Certificates Stored in Azure Active Directory Information disclosure Microsoft Karl Fosaaen (@kfosaaen) Bug Bounty2021-11-172023-06-13
1658Azure Active Directory Exposes Internal Information Information disclosure Microsoft Secureworks Counter Threat Unit (@Secureworks) Bug Bounty2022-04-052023-06-13
1653Azure Active Directory Exposes Internal Information Cloud Information disclosure Azure AD Microsoft (Azure) Counter Threat Unit Research Team Bug Bounty2022-04-052023-06-13
1561Certifried: Active Directory Domain Privilege Escalation (CVE-2022–26923) Active Directory Privilege Escalation Microsoft Oliver Lyak (@ly4k_) Bug Bounty2022-05-102023-06-13
1560Diving Into Pre-created Computer Accounts Active Directory Local Privilege Escalation Windows NA Oddvar Moe (@Oddvarmoe) Bug Bounty2022-05-102023-06-13
1031New Attack Paths? AS Requested Service Tickets Local Privilege Escalation Windows Kerberos Active Directory Microsoft Charlie Clark (@exploitph) Bug Bounty2022-09-252023-06-13
893Abusing Windows’ tokens to compromise Active Directory without touching LSASS Local Privilege Escalation Windows Active Directory Privilege Escalation NA Aurélien Chalot (@Defte_) Bug Bounty2022-10-272023-06-13
870The power of adaptability through experience. Lateral movement Active Directory Privilege Escalation NA Mike Saunders (@hardwaterhacker) Bug Bounty2022-11-032023-06-13
824Relaying to AD Certificate Services over RPC Active Directory ADCS Windows NA Sylvain Heiniger (@sploutchy) Bug Bounty2022-11-162023-06-13
571Azure Active Directory Flaw Allowed SAML Persistence Azure AD SAML SSO Microsoft (Azure) Secureworks Counter Threat Unit (@Secureworks) Bug Bounty2023-01-182023-06-13
476Azure Ad Kerberos Tickets: Pivoting To The Cloud Active Directory Cloud Lateral movement NA Edwin David Bug Bounty2023-02-092023-06-13
300AD Security Research: Breaking Trust Transitivity Active Directory Privilege Escalation Microsoft (Windows) Charlie Clark (@exploitph) Bug Bounty2023-03-142023-06-13
242Protected Users: you thought you were safe uh? Active Directory Kerberos NTLM Internal pentest Microsoft (Windows) Aurélien CHALOT (@Defte_) Bug Bounty2023-03-312023-06-13
84From DA to EA with ESC5 Active Directory Privilege Escalation Internal pentest NA Andy Robbins (@_wald0) Bug Bounty2023-05-172023-06-13
49Anonymised Penetration Test Report Internal pentest RCE ADCS Active Directory Kerberos DHCPv6 LLMNR NA Volkis (@VolkisAU) Bug Bounty2023-05-282023-06-13
31How a misconfigured Lotus Domino Server can lead to Disclosure of PII Data of Employees, Configuration Details about the Active Directory, etc Lotus Domino Security misconfiguration Information disclosure NA Aayush Vishnoi (@AayushVishnoi10) Bug Bounty2023-06-042023-06-13