Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
411How I got into Nokia HOF in 5 Mins Information disclosure Nokia Abdelrhman Allam (@sl4x0) Bug Bounty2023-02-222023-06-13
368How a simple IDOR impacted the data of thousands of customers of an Indian automotive giant Account takeover Information disclosure IDOR NA Kushal Jain Bug Bounty2023-03-012023-06-13
362How I Earned $$$ for Excessive Data Exposure Through Directory Traversal Leads to Product Price Manipulation Path traversal Information disclosure Payment bypass NA Mohamed Shibil Bug Bounty2023-03-032023-06-13
352JS file enumeration for bug bounty hunters Information disclosure IDOR NA Aadarsh Anand (@ScreamZoro) Bug Bounty2023-03-042023-06-13
342Remote Stealth Brute-force of Oracle Database Passwords Bruteforce Information disclosure Authentication bypass Components with known vulnerabilities NA Viktor Markopoulos Bug Bounty2023-03-062023-06-13
333The story of becoming a Super Admin Hardcoded credentials Account takeover Information disclosure NA Ömer Kepenek (@omer_kepenek) Bug Bounty2023-03-082023-06-13
321Default Credentials on Sony- Swag Time Hardcoded credentials Information disclosure Sony Arman (@M7arm4n) Bug Bounty2023-03-102023-06-13
283Exploiting aCropalypse: Recovering Truncated PNGs Privacy issue Information disclosure Android Google David Buchanan (@David3141593) Bug Bounty2023-03-182023-06-13
263Using an Undocumented Amplify API to Leak AWS Account IDs Cloud Information disclosure AWS Nick Frichette (@frichette_n) Bug Bounty2023-03-272023-06-13
247How to avoid the aCropalypse Privacy issue Information disclosure Android Google Microsoft Henrik Brodin Bug Bounty2023-03-302023-06-13
245From an Innocent api-key to PII data Information disclosure Hardcoded API keys NA g30rgy th3 d4rk (@Crypt0g30rgy) Bug Bounty2023-03-302023-06-13
232Holiday Hunting With Aquatone SSRF Missing authentication Information disclosure NA Kuldeep Pandya (@kuldeepdotexe) Bug Bounty2023-04-032023-06-13
213Account Take Over (Via an API) Account takeover Information disclosure Broken Access Control Cryptographic issues NA Thabiso Mokoena Bug Bounty2023-04-102023-06-13
196From Django Debug Mode to PII Data Leak of more than 500+ Employees due Broken Access Control and IDOR Debug mode enabled IDOR Information disclosure JWT Broken Access Control Exposed registration page NA Aayush Vishnoi (@AayushVishnoi10) Bug Bounty2023-04-142023-06-13
190Multiple Critical Vulnerabilities In Strapi Versions <=4.7.1 Authentication bypass SSTI RCE Amazon cognito misconfiguration Information disclosure Strapi GhostCcamm (@GhostCcamm) Bug Bounty2023-04-172023-06-13
162Discord Rich Presence LeonardSSH.vscord Information disclosure vscord Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2023-04-232023-06-13
145How I Chained an Information Disclosure Bug with SQL Injection SQL injection .git folder disclosure NA Mba-oji Chiagoziem (@g0ziem) Bug Bounty2023-04-302023-06-13
140Unauthorized access to the admin panel via leaked credentials on the WayBackMachine Information disclosure NA Arman (@M7arm4n) Bug Bounty2023-05-012023-06-13
137Placeholder for Dayzzz: Abusing placeholders to extract customer informations SSTI Information disclosure GitHub Ophion Security (@OphionSecurity) Bug Bounty2023-05-012023-06-13
127The Art of Information Disclosure: A Deep Dive into CVE-2022-37985, a Unique Information Disclosure Vulnerability in Windows Graphics Component Out-of-bounds Read Memory corruption Microsoft (Windows) Bing Sun Bug Bounty2023-05-032023-06-13
114How a simple Directory Listing leads to PII Data Leakage, Remote Code Execution and many more vulnerabilities on a HR management subdomain RCE Unrestricted file upload Stored XSS Information disclosure Directory listing NA Aayush Vishnoi (@AayushVishnoi10) Bug Bounty2023-05-072023-06-13
107Testing a new encrypted messaging app%27s extraordinary claims Android Firebase Cryptographic issues Privacy issue Information disclosure Converso Crnković Bug Bounty2023-05-102023-06-13
78A $1,000,000 bounty? The KuCoin User Information Leak Information disclosure Zendesk Authorization flaw Security misconfiguration NA Corben Leo (@hacker_) Bug Bounty2023-05-182023-06-13
71Exposing iCloud user’s Name, phone numbers, and email addresses. Information disclosure Apple (iCloud) Renganathan (@IamRenganathan) Bug Bounty2023-05-202023-06-13
70Why You Should Always Check The Audit Log [Medium] — $500 Information disclosure NA Emanuel Beni Harijanto Bug Bounty2023-05-202023-06-13