Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3283DNS Rebinding, The treacherous attack it can be DNS rebinding NA Vuk Ivanovic Bug Bounty2020-07-252023-06-13
3257Refocusing in bug hunting, Bonus: An interestingly simple to test CSRF bypass CSRF NA Vuk Ivanovic Bug Bounty2020-08-012023-06-13
3247CSRF PoC mistake that broke crucial functions for the end user/victim Logic flaw NA Vuk Ivanovic Bug Bounty2020-08-052023-06-13
3237Bug Hunting with Param Miner: Cache poisoning with XSS, a peculiar case XSS Web cache poisoning NA Vuk Ivanovic Bug Bounty2020-08-082023-06-13
3225Cache poisoning of wget Web cache poisoning NA Vuk Ivanovic Bug Bounty2020-08-122023-06-13
3221False2True, Match and Replace bug hunting — A cautionary tale Privilege escalation NA Vuk Ivanovic Bug Bounty2020-08-142023-06-13
3203Fun with header and forget password, with a twist: Password reset Host header injection NA Vuk Ivanovic Bug Bounty2020-08-182023-06-13
3196Upload to the future IDOR NA Vuk Ivanovic Bug Bounty2020-08-222023-06-13
3187Accessing the website directly through its IP address, a case of a poorly hidden sql injection SQL injection NA Vuk Ivanovic Bug Bounty2020-08-272023-06-13
3184The Importance of keeping up to date, or how I found an interesting bug thanks to a tweet Stored XSS NA Vuk Ivanovic Bug Bounty2020-08-292023-06-13
3140Fun with Header and Forget Password HTTP header injection NA Vuk Ivanovic Bug Bounty2020-09-222023-06-13
2859Business Logic Error Methodology (easy way) + PoC-s Logic flaw NA Vuk Ivanovic Bug Bounty2021-01-282023-06-13
2479Importance of burp history analysis to bypass 403 403 bypass NA Vuk Ivanovic Bug Bounty2021-06-152023-06-13
2132A story of another awesome old school hacking that lead to a cool P1 bug 403 bypass NA Vuk Ivanovic Bug Bounty2021-10-222023-06-13
1352FFUF-ing RECON, or how to get to P1–P3 from a slightly different recon vHost misconfiguration 403 bypass Information disclosure NA Vuk Ivanovic Bug Bounty2022-07-172023-06-13
1220Salesforce bug hunting to Critical bug Information disclosure Salesforce NA Vuk Ivanovic Bug Bounty2022-08-152023-06-13
469Disabling js for the win Unrestricted file upload RCE NA Vuk Ivanovic Bug Bounty2023-02-102023-06-13