Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4890My Research on Misconfigured Jenkins Servers Information disclosure Missing authentication Exposed Jenkins instance Google Tesco Pearson News Uk Mikail Tunç (@emtunc) Bug Bounty2018-01-182023-06-13
4305Third Party Android App Storing Facebook Data Insecurely (Facebook Data Abuse Program) Information disclosure Missing authentication Meta / Facebook Nightwatch Cybersecurity (@nightwatchcyber) Bug Bounty2019-02-142023-06-13
4285Swiss_E-Voting_Publications XSS XXE RCE Missing authentication Authentication flaw Hardcoded credentials Swiss E-Voting setuid0 (@_setuid0_) Bug Bounty2019-02-212023-06-13
4137Security assessment on the staging domains Missing authentication NA Tutorgeeks (@tutorgeeks) Bug Bounty2019-05-242023-06-13
3918How I found a simple and weird Account takeover bug Account takeover Missing authentication NA Bijan Murmu (@0xBijan) Bug Bounty2019-09-142023-06-13
3884How i Hacked BASF Company !! Missing authentication BASF Murtada Kamil Bug Bounty2019-10-102023-06-13
3827This is How I was able to hunt a rare bug in a private program Missing authentication Privilege escalation NA Abida Fahd Bug Bounty2019-11-182023-06-13
3581Exploiting magic links, critical bugs are one line away Information disclosure Missing authentication Razer 0xSha (@0xsha) Bug Bounty2020-03-272023-06-13
3468Teradici and CVE-2020-10965: An issue of routing. Missing authentication Teradici Benjamin Heald (@heald_ben) Bug Bounty2020-05-182023-06-13
3417Multiple Information exposed due to misconfigured Service-now ITSM instances Missing authentication Information disclosure NA Th3G3nt3lman (@Th3G3nt3lman) Bug Bounty2020-06-052023-06-13
3372How i was able to chain bugs and gain access to internal okta instance Missing authentication NA Mmohammed Eldeeb (@malcolmx0x) Bug Bounty2020-06-222023-06-13
3212InfluxDB Access at redact.8x8.com Missing authentication 8x8 Myo Min Thu (@myominthu1337) Bug Bounty2020-08-162023-06-13
3200A perfect duplicate or how to send an email with a spoofed invoice’s content Email spoofing Open mail relay Missing authentication NA Mateusz Olejarka (@molejarka) Bug Bounty2020-08-192023-06-13
3170From Android Static Analysis to RCE on Prod RCE Directory listing Missing authentication NA Aditya Dixit (@zombie007o) Bug Bounty2020-09-072023-06-13
3083300$ P3 Easy Bug in 30 Seconds Missing authentication Broken Access Control NA Omar Hamdy (@seaman00o) Bug Bounty2020-10-222023-06-13
2970How I hacked Facebook: Part One Missing authentication Authentication bypass Account takeover Meta / Facebook Alaa Abdulridha (@alaa0x2) Bug Bounty2020-12-112023-06-13
2569Unauthorized access to Django Admin Dashboard by endpoint leaked on GitHub Missing authentication Forced browsing NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-05-102023-06-13
2393Unauthenticated Access To MongoDB Database of Oracle Corporation Missing authentication Exposed administrative interface Oracle Pratikkhalane (@KhalanePratik) Bug Bounty2021-07-222023-06-13
2363From Hobby to Hacking Unrestricted file upload RCE Missing authentication NA Muhammad Syahrul Haniawan (@b0x_in) Bug Bounty2021-07-312023-06-13
2213From Google Dorking to Information Disclosure Information disclosure Missing authentication NA MikeChan Bug Bounty2021-09-182023-06-13
1350Good things takes time | Story of my first “valid” critical bug! Missing authentication Exposed administrative interface NA Kr1shna 4garwal (@Kr1shna4garwal) Bug Bounty2022-07-182023-06-13
1268From Shodan to RCE: That one time I hacked a Fortune 500 company. Missing authentication Arbitrary file read RCE Exposed Jenkins instance NA vimanari_ (@vimanari_) Bug Bounty2022-08-082023-06-13
1230Story of 5000$ bounty for Grafana Panel Access in Apple Missing authentication Information disclosure Apple hckerl00 (@lokeshg62498939) Bug Bounty2022-08-132023-06-13
1227How I got into the United Nations’ Hall of Fame Missing authentication United Nations Ameya Andhare (@cryptoknight028) Bug Bounty2022-08-142023-06-13
1226Hacking Zyxel IP cameras to gain a root shell Missing authentication DoS Information disclosure Local Privilege Escalation Zyxel Eric Urban Bug Bounty2022-08-142023-06-13