Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4888How I got $13337 bounty From Google Weak credentials Google Sreeram KL (@kl_sree) Bug Bounty2018-01-182023-06-13
4751How i was able to get admin panel on a private program Weak credentials NA Shahzad Sadiq (@ShahzadSadiq25) Bug Bounty2018-05-292023-06-13
4693Attacking PostgreSQL Database Bruteforce Weak credentials NA Vishnuraj Bug Bounty2018-07-162023-06-13
3385How I managed to Escalate privilege as admin Lack of rate limiting Bruteforce Weak credentials NA Abisheik Magesh (@AbisheikMagesh) Bug Bounty2020-06-162023-06-13
3373It took me only 5 minutes to find an RCE on Bentley RCE Weak credentials Bentley Divyansh Sharma Bug Bounty2020-06-212023-06-13
3106Exploiting Admin Panel Like a Boss Authorization bypass Weak credentials NA Shivam Kamboj Dattana (@sechunt3r) Bug Bounty2020-10-082023-06-13
2423Account Takeovers — Believe the Unbelievable Account takeover Session management issue Weak credentials Components with known vulnerabilities Password reset NA Nikhil (niks) (@niksthehacker) Bug Bounty2021-07-092023-06-13
2242Accessing Grofers Grafana Instance Using Shodan Weak credentials Grofers Lohith Gowda M (@lohigowda_in) Bug Bounty2021-09-082023-06-13
1734From Recon via Censys and DNSdumpster, to Getting P1 by Login Using Weak Password – “password” WAF bypass Weak credentials NA YoKo Kho (@YokoAcc) Bug Bounty2022-03-142023-06-13
1603Adventures Into The MeowCorp Bug Bounty Program Information disclosure Weak credentials SSRF .git folder disclosure RCE NA Nirmal Thapa (@tnirmalz) Bug Bounty2022-04-212023-06-13
1508How to find & access Admin Panel by digging into JS files…🥰 Weak credentials WAF bypass NA Ratnadip Gajbhiye (@scspcommunity) Bug Bounty2022-05-302023-06-13
1006Using Default Credential to Admin Account Takeover Weak credentials NA Rohit Kumar (Rohit_443) Bug Bounty2022-10-022023-06-13
906GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown OS command injection Arbitrary file read Information disclosure Account takeover Stored XSS Lack of rate limiting Weak credentials Password policy bypass GL.iNet Olivier Laflamme (@olivier_boschko) Bug Bounty2022-10-262023-06-13
874Chaining Multiple Vulnerabilities Leads to Remote Code Execution (RCE) on One of the Payment Service Companies. Exposed registration page Exposed Jenkins instance Weak credentials RCE NA Rohit Soni (@streetofhacker) Bug Bounty2022-11-022023-06-13
604“2022: A Year of Fascinating Discoveries” CSRF SSRF Blind XSS Password reset Hyperlink injection IDOR Weak credentials AWS misconfiguration NA dhakal_bibek (@dhakal__bibek) Bug Bounty2023-01-092023-06-13
163How careless default credentials impact to massive account takeover Authentication bypass Account takeover Weak credentials NA M Maulana Abdullah Bug Bounty2023-04-222023-06-13