Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4799From an error message to DB disclosure Hardcoded credentials NA Yumi Bug Bounty2018-04-172023-06-13
4613https://medium.com/@mahitman1/i-own-your-customers-22e965761abd Information disclosure Hardcoded credentials AWS misconfiguration NA Muhammad Abdullah Bug Bounty2018-09-012023-06-13
4285Swiss_E-Voting_Publications XSS XXE RCE Missing authentication Authentication flaw Hardcoded credentials Swiss E-Voting setuid0 (@_setuid0_) Bug Bounty2019-02-212023-06-13
3656Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC Information disclosure Hardcoded credentials NA Muhammad Khizer Javed (@khizer_javed47) Bug Bounty2020-02-192023-06-13
3321From N/A to Resolved For BackBlaze Android App[Hackerone Platform] Bucket Takeover Hardcoded credentials Information disclosure BackBlaze Sahil Tikoo (@viperbluff) Bug Bounty2020-07-092023-06-13
3316Tenda AC15 AC1900 Vulnerabilities Discovered and Exploited CSRF XSS Hardcoded credentials RCE Tenda Sanjana Sarda Bug Bounty2020-07-102023-06-13
2886Let’s know How I have explored the buried secrets in React Native application Information disclosure Hardcoded credentials NA secureITmania (@secureitmania) Bug Bounty2021-01-182023-06-13
2862Bragging Rights(Part 1): Short story of a bug wave IDOR Stored XSS SSRF Subdomain takeover Hardcoded credentials NA Manas Harsh (@ManasH4rsh) Bug Bounty2021-01-272023-06-13
2851Android apk leaks access token to takeover the whole infrastructure Information disclosure Hardcoded credentials Android NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-01-302023-06-13
2510Admin Panel? Pwned! Information disclosure Hardcoded credentials NA Splintersec (@splint3rsec) Bug Bounty2021-06-022023-06-13
2198Facebook Messenger for MacOS contained valid hardcoded FB access token (employee%27s token?) Hardcoded credentials Meta / Facebook Dzmitry Lukyanenka (@vulnano) Bug Bounty2021-09-232023-06-13
1898Solarwinds Web Help Desk: When the Helpdesk is too Helpful Information disclosure Hardcoded credentials SolarWinds Assetnote Security Research Team (@assetnote) Bug Bounty2022-01-232023-06-13
1674Write Up – Finapi (Open Banking API) Oauth Credentials Exposed In Plain Text In Android App Hardcoded credentials Android NA Omar Espino (@omespino) Bug Bounty2022-04-012023-06-13
1598Fuzzing and credentials leakage..awesome bug hunting writeup Hardcoded credentials Information disclosure NA Abdalrahman Alshammas Bug Bounty2022-04-252023-06-13
1449Personal Access Token Disclosure in Asana Desktop Application Information disclosure Hardcoded credentials Asana Lauritz Holtmann (@_lauritz_) Bug Bounty2022-06-182023-06-13
1319With Management Comes Risk: Finding Flaws in FileWave MDM Authentication bypass Hardcoded credentials Information disclosure Filewave Claroty%27s Team82 (@Claroty) Bug Bounty2022-07-252023-06-13
1189Patch bypass for [CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager Hardcoded credentials Information disclosure SAP Arpine Maghakyan Bug Bounty2022-08-222023-06-13
1174ASP.NET Boilerplate Multiple Vulnerabilities Authentication flaw Hardcoded credentials JWT Padding oracle attack Cryptographic issues Volosoft (ASP.NET Boilerplate) Sana Oshika (@bigshika) Bug Bounty2022-08-262023-06-13
1131Hacking My Helium Crypto Miner Hardcoded credentials Missing authentication RCE Local Privilege Escalation Pycom Md. Asif Hossain (@0x0asif) Bug Bounty2022-09-052023-06-13
1107Baxter SIGMA Spectrum Infusion Pumps: Multiple Vulnerabilities (FIXED) Hardcoded credentials Memory corruption MiTM Information disclosure Baxter Healthcare Deral Heiland (@Percent_X) Bug Bounty2022-09-082023-06-13
831SSD Advisory – Cisco Secure Manager Appliance jwt_api_impl Hardcoded JWT Secret Elevation of Privilege Hardcoded credentials Security code review JWT Privilege escalation Cisco - Bug Bounty2022-11-142023-06-13
771[Hacking Bank] The Second Story of Finding Critical Vulnerabilities on Banking Application Android Hardcoded credentials IDOR NA Abdelhak Kharroubi Bug Bounty2022-11-262023-06-13
734Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys Android Hardcoded credentials Client-side encryption bypass NA Aditya Dixit (@zombie007o) Bug Bounty2022-12-032023-06-13
678Better Make Sure Your Password Manager Is Secure Hardcoded credentials XSS Cryptographic issues Authorization flaw Authentication bypass Click Studios kuekerino (@kuekerino) Bug Bounty2022-12-192023-06-13
591YAFPC — Unauthenticated Remote Code Execution Authentication bypass Hardcoded credentials RCE NA Luke Paris Bug Bounty2023-01-142023-06-13