Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5008Getting access to 25k employees details Exposed registration page NA Sahil Ahamad (@ehsahil) Bug Bounty2017-08-112023-06-13
3528From Recon to P1 (Critical) — An Easy Win Exposed registration page NA Harsh Bothra (@harshbothra_) Bug Bounty2020-04-242023-06-13
3272Company’s zendesk subdomain lead to hidden access. Exposed registration page NA himanshu pdy (@himanshu_pdy) Bug Bounty2020-07-282023-06-13
2704How to Harpon Big Blue! Logic flaw Exposed registration page IBM Clark Voss (@clark_voss) Bug Bounty2021-03-192023-06-13
2502403 Forbidden Bypass OTP bypass Exposed registration page XSS NA th3.d1p4k (@DipakPanchal05) Bug Bounty2021-06-042023-06-13
2474Story of Google Hall of Fame and Private program bounty worth $$$$ Exposed registration page Google Basavaraj Banakar (@basu_banakar) Bug Bounty2021-06-162023-06-13
2281ATO of WordPress Website “4 digits €€€€ Bounty in 5 Minute!” Exposed registration page Account takeover NA Ritesh Gohil (@RiteshG37659480) Bug Bounty2021-08-292023-06-13
1555From android app to access admin dashboard Exposed registration page Account takeover NA Oday Alhalabi (@OdayAlhalabi) Bug Bounty2022-05-132023-06-13
1554My New Discovery In Oracle E-Business Login Panel That Allowed To Access For All Employees Information%27s & In Some cases Passwords At More Than 1000 Companies Exposed registration page NA Orwa Atyat (@GodfatherOrwa) Bug Bounty2022-05-142023-06-13
938Found vulnaribility on subdomain of nasa.gov simply using censys Exposed registration page NASA hacker_might Bug Bounty2022-10-192023-06-13
874Chaining Multiple Vulnerabilities Leads to Remote Code Execution (RCE) on One of the Payment Service Companies. Exposed registration page Exposed Jenkins instance Weak credentials RCE NA Rohit Soni (@streetofhacker) Bug Bounty2022-11-022023-06-13
816Security concerns with the e-Tugra certificate authority Default credentials Exposed registration page e-Tugra Ian Carroll (@iangcarroll) Bug Bounty2022-11-172023-06-13
776Hacking Dutch Government-Broken Authentication To Full Website Takeover (P1) Exposed registration page Dutch Government V1dr4X Bug Bounty2022-11-262023-06-13
641Unauthorized Sign-up on Subdomain of Subdomain leading to Organization takeover worth $2000 Exposed registration page NA Manav Bankatwala (@ManavBankatwala) Bug Bounty2022-12-282023-06-13
196From Django Debug Mode to PII Data Leak of more than 500+ Employees due Broken Access Control and IDOR Debug mode enabled IDOR Information disclosure JWT Broken Access Control Exposed registration page NA Aayush Vishnoi (@AayushVishnoi10) Bug Bounty2023-04-142023-06-13