Writeups
Spotlight
Add Your Writeup
Blogs
Contact Us
Register
Login
Write-ups
Check The Published Writeups
Search
Reset
WDB
Title
Tags
Programs
Authors
Type
Publication
Added
5086
Penetrating PornHub – XSS vulns galore (plus a cool shirt!)
XSS
PornHub
Jon Bottarini (@jon_bottarini)
Bug Bounty
2017-03-16
2023-06-13
5081
Inspect Element leads to Stripe Account Lockout Authentication Bypass
Authentication bypass
Stripe
Jon Bottarini (@jon_bottarini)
Bug Bounty
2017-04-03
2023-06-13
4904
Abusing internal API to achieve IDOR in New Relic
IDOR
New Relic
Jon Bottarini (@jon_bottarini)
Bug Bounty
2018-01-02
2023-06-13
4834
GraphQL abuse: Bypass account level permissions through parameter smuggling
GraphQL
Privilege escalation
New Relic
Jon Bottarini (@jon_bottarini)
Bug Bounty
2018-03-14
2023-06-13
4539
Get as image function pulls any Insights/NRQL data from any New Relic account (IDOR)
IDOR
New Relic
Jon Bottarini (@jon_bottarini)
Bug Bounty
2018-10-09
2023-06-13
4095
Using Burp Suite match and replace settings to escalate your user privileges and find hidden features
Client-side enforcement of server-side security
New Relic
Jon Bottarini (@jon_bottarini)
Bug Bounty
2019-06-17
2023-06-13
4094
Reflected XSS in Tokopedia Train Ticket
Reflected XSS
New Relic
Jon Bottarini (@jon_bottarini)
Bug Bounty
2019-06-17
2023-06-13
2007
Don’t Reply: A Clever Phishing Method In Apple’s Mail App
Phishing
Apple
Jon Bottarini (@jon_bottarini)
Bug Bounty
2021-12-09
2023-06-13