Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2945Chaining CORS by Reflected xss to Account takeover #My first Blog CORS misconfiguration Reflected XSS Account takeover NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2020-12-262023-06-13
2865Finding SSRF BY Full Automation SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-01-272023-06-13
2851Android apk leaks access token to takeover the whole infrastructure Information disclosure Hardcoded credentials Android NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-01-302023-06-13
2727Finding Basic Authtoken in JAVASCRIPT file BY Full Automation Information disclosure NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-03-102023-06-13
2656Chaining an Blind SSRF bug to Get an RCE Blind SSRF RCE NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-04-072023-06-13
2628Unauthorized access to admin setpassword page BY bypassing 403 Forbidden Authorization flaw NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-04-182023-06-13
2612AWS internal metadata accessed through SSRF by Chaining an Open Redirect bug SSRF Open redirect NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-04-242023-06-13
2587Chaining CSRF with XSS to deactivate Mass user accounts by single click CSRF XSS NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-05-022023-06-13
2569Unauthorized access to Django Admin Dashboard by endpoint leaked on GitHub Missing authentication Forced browsing NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-05-102023-06-13
2515Escalating SSRF to Accessing all user PII information by aws metadata SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-05-312023-06-13
2511Escalating SSRF to Accessing all user PII information by aws metadata SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-06-012023-06-13
2498How Github recon help me to find NINE FULL SSRF Vulnerability with AWS metadata access SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-06-062023-06-13
2397How I was able Find mass leaked AWS s3 bucket from js File AWS misconfiguration NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-07-202023-06-13
2325Finding multiple SSRF with aws metadata access on A BANK system SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-08-142023-06-13
2010Exploiting S3 bucket with path folder to Access PII info of A BANK AWS misconfiguration Information disclosure NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-12-092023-06-13
1465Automating reflected XSS with burp-suite Intruder Reflected XSS NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2022-06-142023-06-13
1164How I found reflected XSS on IDFC Bank with burp-suite Intruder Reflected XSS IDFC Bank Santosh Kumar Sha (@killmongar1996) Bug Bounty2022-08-282023-06-13
1163Out-Of-Bond Remote code Execution(RCE) on De Nederlandsche Bank N.V. with burp-suite collaborator OS command injection RCE De Nederlandsche Bank Santosh Kumar Sha (@killmongar1996) Bug Bounty2022-08-282023-06-13
277How I got access to Essilor International company customer PII INFO by AWS metadata access through SSRF SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2023-03-212023-06-13