Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
48The 30000$ Bounty Affair. RCE Missing authentication Exposed Jenkins instance NA Gokulsspace (@GokTest) Bug Bounty2023-05-282023-06-13
46Exploit an unexploitable XSS via an open redirect — A Real-Life Scenario from a Hacker’s Mindset XSS Open redirect NA Ziad Ali Bug Bounty2023-05-292023-06-13
45Hunting For Password Reset Tokens By Spraying And Using HTTP Pipelining Password reset Account takeover NA Tom Neaves Bug Bounty2023-05-302023-06-13
42Vulnerabilities In Apache Commons-Text 1.10.0 Path traversal XXE Apache Commons Text Chris (@mc_0wn) Bug Bounty2023-05-302023-06-13
38Ghost Sites: Stealing Data From Deactivated Salesforce Communities Salesforce Security misconfiguration NA Nitay Bachrach Bug Bounty2023-05-312023-06-13
37Anatomy of an IoT Exploit, from Hands-On to RCE IoT RCE Buffer Overflow Memory corruption Wavlink David Baker Bug Bounty2023-06-012023-06-13
36CVE-2023-24941: Microsoft Network File System Remote Code Execution RCE NFS Microsoft (Windows) Quinton Crist Bug Bounty2023-06-012023-06-13
35Bypassing An Industry-Leading WAF and Exploiting SQLi SQL injection WAF bypass NA Adeeb Shah Bug Bounty2023-06-012023-06-13
33Prototype Pollution Akamai Client-side prototype pollution WAF bypass NA Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2023-06-032023-06-13
32Rate Limit Bypass Leads to 0 Click ATO Rate limiting bypass Bruteforce Password reset Account takeover NA ZeroXUF (@ZeroXUF) Bug Bounty2023-06-042023-06-13
31How a misconfigured Lotus Domino Server can lead to Disclosure of PII Data of Employees, Configuration Details about the Active Directory, etc Lotus Domino Security misconfiguration Information disclosure NA Aayush Vishnoi (@AayushVishnoi10) Bug Bounty2023-06-042023-06-13
30AWS Chain Attack- Thousands of Vulnerable EKS Clusters AWS Kubernetes EKS Container escape Security misconfiguration NA Chen Shiri (@ChenShiri73) Bug Bounty2023-06-042023-06-13
27Bypassing CSP via DOM clobbering DOM Clobbering CSP bypass NA Gareth Heyes (@garethheyes) Bug Bounty2023-06-052023-06-13
26Storing Passwords - A Journey Of Common Pitfalls Pass-the-Hash Authentication flaw Security code review STARFACE RedTeam Pentesting (@RedTeamPT) Bug Bounty2023-06-052023-06-13
23CVE-2022-32902: Patch One Issue and Introduce Two TCC bypass Local Privilege Escalation Apple (macOS) Mickey Jin (@patch1t) Bug Bounty2023-06-062023-06-13
5How to prepare for PWK/OSCP, a noob-friendly guide OSCP Offensive Security @abatchy Certification Journey2017-03-042023-07-10
4Luke’s Ultimate OSCP Guide - Part 3 OSCP Offensive Security @hakluke Certification Journey2018-03-212023-07-10
3Luke’s Ultimate OSCP Guide - Part 2 OSCP Offensive Security @hakluke Certification Journey2018-02-162023-07-10
2Luke’s Ultimate OSCP Guide - Part 1 OSCP Offensive Security @hakluke Certification Journey2018-02-152023-07-10