Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1064Exploiting a Seagate service to create a SYSTEM shell (CVE-2022-40286) Local Privilege Escalation Windows Driver hacking Seagate x86matthew (@x86matthew) Bug Bounty2022-09-202023-06-13
1063Privilege Escalation Leads to making authenticated actions (payment processing, creating invoices.. etc) Privilege escalation Authorization flaw NA X-Vector (@XVector11) Bug Bounty2022-09-202023-06-13
1047Skype for Business Audit Part 1 - SKYPErsistence Local Privilege Escalation Windows Security code review Microsoft Florian Hauser (@frycos) Bug Bounty2022-09-222023-06-13
1038Microsoft Windows Shift F10 Bypass and Autopilot privilge escalation Local privilege escalation Microsoft Matek Kamilló (@k4m1ll0) Bug Bounty2022-09-242023-06-13
1031New Attack Paths? AS Requested Service Tickets Local Privilege Escalation Windows Kerberos Active Directory Microsoft Charlie Clark (@exploitph) Bug Bounty2022-09-252023-06-13
1028Discovering The Less-known Vulnerability In Oracle Peoplesoft TockenChpoken Privilege escalation Bruteforce Cookie manipulation NA RE:HACK (@rehackxyz) Bug Bounty2022-09-262023-06-13
1025Another Tale Of IBM I (AS/400) Hacking Local Privilege Escalation Midrange system Menu security NA pz Bug Bounty2022-09-282023-06-13
1024Two RCEs are better than one: write-up of an interesting lateral movement Local Privilege Escalation RCE NA Riccardo Malatesta (@seeu_inspace) Bug Bounty2022-09-282023-06-13
992SSD Advisory – pfSense Post Auth RCE RCE Privilege escalation pfSense 이예랑 (@yelang123x) Bug Bounty2022-10-062023-06-13
976Cold Hard Cache — Bypassing RPC Interface Security with Cache Abuse Privilege escalation Windows Microsoft - Bug Bounty2022-10-112023-06-13
971Broken Access Control leads to full team takeover and privilege escalation Broken Access Control Privilege escalation NA Abdelhameed Ghazy (@El3Etraa1) Bug Bounty2022-10-122023-06-13
964Code flaws leads to Org/Admin Account Takeover Privilege escalation Account takeover NA Saransh Saraf (@mr23r0) Bug Bounty2022-10-132023-06-13
953[CVE-2022-1786] A Journey To The Dawn Use-After-Free Memory corruption Local Privilege Escalation Google (kCTF) Linux Kernel Organization kylebot (@ky1ebot) Bug Bounty2022-10-152023-06-13
942The Danger of Falling to System Role in AWS SDK Client Cloud Privilege escalation Security misconfiguration NA Fracensco Lacerenza (@lacerenza_fra) Bug Bounty2022-10-182023-06-13
931A New Attack Surface on MS Exchange Part 4 - ProxyRelay! RCE Privilege escalation Microsoft Orange Tsai (@orange_8361) Bug Bounty2022-10-192023-06-13
922Sail away, sail away, sail away RCE Privilege escalation NA Reino Mostert Bug Bounty2022-10-212023-06-13
918Finding Multiple Security Issues on Agorapulse Log4shell RCE Information disclosure Broken Access Control Privilege escalation Agorapulse Snap Sec (@snap_sec) Bug Bounty2022-10-242023-06-13
917Atlassian Jira Align, Version 10.107.4 Advisory SSRF Broken Access Control Privilege escalation Atlassian Jacob Shafer (@fibbot) Bug Bounty2022-10-242023-06-13
901SiriSpy - iOS bug allowed apps to eavesdrop on your conversations with Siri iOS MacOS Bluetooth Local Privilege Escalation TCC bypass Apple Guilherme Rambo (@_inside) Bug Bounty2022-10-262023-06-13
898RC4 Is Still Considered Harmful Kerberos MiTM Local Privilege Escalation Downgrade attack Microsoft (Windows) James Forshaw (@tiraniddo) Bug Bounty2022-10-272023-06-13
893Abusing Windows’ tokens to compromise Active Directory without touching LSASS Local Privilege Escalation Windows Active Directory Privilege Escalation NA Aurélien Chalot (@Defte_) Bug Bounty2022-10-272023-06-13
889Technical Analysis of Windows CLFS Zero-Day Vulnerability CVE-2022-37969 - Part 1: Root Cause Analysis Local Privilege Escalation Windows Microsoft Zscaler Threatlabz (@Threatlabz) Bug Bounty2022-10-282023-06-13
870The power of adaptability through experience. Lateral movement Active Directory Privilege Escalation NA Mike Saunders (@hardwaterhacker) Bug Bounty2022-11-032023-06-13
869Invitation Hijacking Authorization flaw Privilege escalation NA vFlexo (@vflexo) Bug Bounty2022-11-032023-06-13
856Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049) Local Privilege Escalation Windows Microsoft Kuba Gretzky (@mrgretzky) Bug Bounty2022-11-082023-06-13