Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1211Monitoring Linux host metrics with the Node Exporter information disclosure $350 Information disclosure Missing authentication Slack Dhamotharan (@Dhamu_offi) Bug Bounty2022-08-162023-06-13
1193How a Port scan got me Nokia Hall of Fame Missing authentication Information disclosure Nokia Mani Sashank Bug Bounty2022-08-222023-06-13
1155My findings on Hack U.S Program Missing authentication .git folder disclosure Information disclosure U.S. Dept Of Defense Charansai Bug Bounty2022-08-302023-06-13
1131Hacking My Helium Crypto Miner Hardcoded credentials Missing authentication RCE Local Privilege Escalation Pycom Md. Asif Hossain (@0x0asif) Bug Bounty2022-09-052023-06-13
1015Orange Arbitrary Command Execution RCE Docker daemon misconfiguration Missing authentication Orange Omar Hashem (@OmarHashem666) Bug Bounty2022-09-292023-06-13
967Compromising a Backup System by iSCSI Interface During a Routine Penetration Test Missing authentication NA Bruno Oliveira Bug Bounty2022-10-132023-06-13
919Missing Authentication in ZKTeco ZEM/ZMM Web Interface Missing authentication ZKTeco RedTeam Pentesting (@RedTeamPT) Bug Bounty2022-10-242023-06-13
781Legally hacking a Government Satellite? Missing authentication OS command injection RCE NA RiotSecTeam (@RiotSecTeam) Bug Bounty2022-11-242023-06-13
690Unprotected API endpoint at HAwebsso.nl leads to data leak of +15k medical doctor usernames & password hashes SSO IDOR Missing authentication HAwebsso.nl Jonathan Bouman (@JonathanBouman) Bug Bounty2022-12-142023-06-13
508Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails RCE Security code review Missing authentication Insecure deserialization IBM Maxwell Garrett (@TheGrandPew) Bug Bounty2023-02-022023-06-13
471Information disclosure or GDPR breach? A Google tale… Privacy issue Information disclosure Missing authentication Google Luke Berner Bug Bounty2023-02-102023-06-13
449Assumed Breach Assessment Case Study: Uncovering WeSecureApp’s Approach Internal pentest Missing authentication Hardcoded credentials Cloud NA WeSecureApp (@wesecureapp) Bug Bounty2023-02-142023-06-13
408Exploit Airlines that use T-Mobile for Free WiFi Wifi Payment bypass MAC address spoofing Missing authentication T-Mobile cylect.io (@cylect_io) Bug Bounty2023-02-232023-06-13
393Unauthenticated GraphQL Introspection and API calls GraphQL Missing authentication NA Osama Avvan (@osamaavvan) Bug Bounty2023-02-262023-06-13
355Unauthorized Access To Admin Panel via Swagger Missing authentication Broken Access Control Coca-Cola Arman (@M7arm4n) Bug Bounty2023-03-042023-06-13
328The Silent Spy Among Us: Modern Attacks Against Smart Intercoms IoT OS command injection Missing authentication MiTM SIP Akuvox Claroty%27s Team82 (@Claroty) Bug Bounty2023-03-092023-06-13
232Holiday Hunting With Aquatone SSRF Missing authentication Information disclosure NA Kuldeep Pandya (@kuldeepdotexe) Bug Bounty2023-04-032023-06-13
68AEM Bug in Adobe AEM Missing authentication Security misconfiguration Adobe Muhammad Mater (@micro0x00) Bug Bounty2023-05-202023-06-13
48The 30000$ Bounty Affair. RCE Missing authentication Exposed Jenkins instance NA Gokulsspace (@GokTest) Bug Bounty2023-05-282023-06-13