Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2735Finding Hidden Login Endpoint Exposing Secret `Client ID` Information disclosure NA Ahmad Halabi (@Ahmad_Halabi_) Bug Bounty2021-03-072023-06-13
2727Finding Basic Authtoken in JAVASCRIPT file BY Full Automation Information disclosure NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-03-102023-06-13
2718Facebook Group Members Disclosure. Information disclosure Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2021-03-152023-06-13
2717De-anonymize the members of a private Facebook Group as a non-member. GraphQL Information disclosure Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2021-03-152023-06-13
2716API Misconfiguration which leads to unauthorized access to servicedesk tickets Information disclosure NA Gaurav Popalghat (@N008x) Bug Bounty2021-03-162023-06-13
2715Voice Confusion When Commenting On Watch Party Information disclosure Meta / Facebook Prakash Panta (@prakashpanta268) Bug Bounty2021-03-162023-06-13
2698Finding My First Critical Vulnerability Information disclosure NA Thexssrat (@theXSSrat) Bug Bounty2021-03-212023-06-13
2689Increasing impact of Information Disclosure — Full Account Takeover ! Information disclosure Password reset NA Abhisek R (@abh1sek_r) Bug Bounty2021-03-262023-06-13
2677Zero click vulnerability in Apple’s macOS Mail Account takeover Information disclosure RCE Apple Mikko Kenttälä (@Turmio_) Bug Bounty2021-04-012023-06-13
2650Unauthenticated Account Takeover Through Forget Password Password reset Account takeover Information disclosure NA Nikhil (niks) (@niksthehacker) Bug Bounty2021-04-122023-06-13
2646Bug Bounty - Information Disclosure through error message + WAF Bypass led to Local File Inclusion LFI Information disclosure NA Arben Shala (@arbennsh) Bug Bounty2021-04-132023-06-13
2624Auth Bypass in Google Workspace Real Time Collaboration Authentication bypass Information disclosure Google David Schütz (@xdavidhu) Bug Bounty2021-04-202023-06-13
2617PrivateDrop: Breaking and Fixing Apple AirDrop Privacy issue Information disclosure Apple Alexander Heinrich Bug Bounty2021-04-212023-06-13
2600How did I earn €€€€ by breaking the back-end logic of the server Logic flaw Information disclosure NA Dewanand Vishal (@dewcode91) Bug Bounty2021-04-282023-06-13
2598De-anonymising Anonymous Animals in Google Workspace Privacy issue Information disclosure Google David Schütz (@xdavidhu) Bug Bounty2021-04-292023-06-13
2594How I was able to Retrieve your Personal Documents using the Wayback Machine! Privacy issue Information disclosure NA Savir Suda (@savxiety) Bug Bounty2021-04-302023-06-13
2570Microsoft bug bounty writeup Information disclosure Microsoft th3.d1p4k (@DipakPanchal05) Bug Bounty2021-05-082023-06-13
2533Victim’s Anti CSRF Token could be exposed to Third-party Applications installed on user’s Device (500$) Information disclosure Meta / Facebook Rohit kumar (@rohitcoder) Bug Bounty2021-05-212023-06-13
2532Finding and Exploiting Unintended Functionality in Main Web App APIs IDOR Information disclosure Privilege escalation NA Bend Theory (@bendtheory) Bug Bounty2021-05-212023-06-13
2521Github, The Goldmine for P1s and P2s - Sensitive Information Exposure via Github by a Company Employee Information disclosure NA Savir Suda (@savxiety) Bug Bounty2021-05-282023-06-13
2513Facebook Page Admin Disclosure Information disclosure Meta / Facebook Kunjan Nayak (@kunjannayak5) Bug Bounty2021-05-312023-06-13
2510Admin Panel? Pwned! Information disclosure Hardcoded credentials NA Splintersec (@splint3rsec) Bug Bounty2021-06-022023-06-13
2488How I was able to bypass the admin panel without the credentials. Information disclosure NA Pratikkhalane (@KhalanePratik) Bug Bounty2021-06-122023-06-13
2458Cracking Encrypted Credit Card Numbers Exposed By API Information disclosure Weak crypto NA Craig Hays (@craighays) Bug Bounty2021-06-222023-06-13
2456How i was able to get Appreciation from the organization of a website just by changing a sign..!!! Information disclosure Source code disclosure NA Fardeen Ahmed (@fardeenahmed411) Bug Bounty2021-06-232023-06-13