Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4175How to bypass a 2FA with a HTTP header MFA bypass NA Yumi Bug Bounty2019-04-262023-06-13
4174Denial of Service using Cookie Bombing DoS Cookie bomb NA Ronak Patel (@ronak_9889) Bug Bounty2019-04-262023-06-13
4173"CI Knew There Would Be Bugs Here" — Exploring Continuous Integration Services as a Bug Bounty Hunter Information disclosure CI/CD NA EdOverflow (@EdOverflow) Bug Bounty2019-04-262023-06-13
4172Broken Access: Posting to Google private groups through any user in the group Authorization flaw Google Elber Andre (@Elber333) Bug Bounty2019-04-272023-06-13
4170Don’t Follow The Masses: Bug Hunting in JavaScript Engines Buffer Overflow Memory corruption Google Dimitri Fourny (@dimitrifourny) Bug Bounty2019-04-292023-06-13
4169From Reflected XSS to Account Takeover — Showing XSS Impact Reflected XSS Account takeover NA A Bug’z Life (@abugzlife1) Bug Bounty2019-04-302023-06-13
4168Reply To Instagram Stories where privacy of who can reply is set to Nobody’. Authorization flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-04-302023-06-13
4167From NA to $3000 : Facebook’s URL spoofing vulnerability URL spoofing Meta / Facebook Rahul Kankrale (@RahulKankrale) Bug Bounty2019-04-302023-06-13
4166Remote code execution On Microsoft edge using URL Protocol RCE Microsoft Matt harr0ey (@harr0ey) Bug Bounty2019-05-012023-06-13
4165XSS attacks on Googlebot allow search index manipulation Logic flaw Google Tom Anthony (@TomAnthonySEO) Bug Bounty2019-05-012023-06-13
4164Why You Shouldn%27t Use a Password Manager For Your Linode Account Account takeover Information disclosure Linode Utku Şen (@utkusen) Bug Bounty2019-05-022023-06-13
4163Tale of a Wormable Twitter XSS XSS Twitter Ahmed Elsobky Bug Bounty2019-05-022023-06-13
4162ESI Injection Part 2: Abusing specific implementations ESI injection RCE SSRF HTTP header injection NA Philippe Arteau (@h3xstream) Bug Bounty2019-05-022023-06-13
4161Server Side Request Forgery(SSRF){port issue hidden approch } SSRF NA Deepak Holani (@w_hat_boy) Bug Bounty2019-05-032023-06-13
4160Subdomain takeover [Awarded $200] Subdomain takeover ownCloud Friendly (@SkeletorKeys) Bug Bounty2019-05-072023-06-13
4159SQL injection through User-Agent SQL injection NA fr0stNuLL Bug Bounty2019-05-082023-06-13
41584x CSRFs Chained For Company Account Takeover CSRF Account takeover NA A Bug’z Life (@abugzlife1) Bug Bounty2019-05-082023-06-13
4157BLIND SSRF in *.stripe.com due to Sentry Misconfiguration Blind SSRF Stripe Oktavandi (@0ktavandi) Bug Bounty2019-05-092023-06-13
4156Stored XSS on Techprofile Microsoft Stored XSS Microsoft Mohammad Ali Syarief Bug Bounty2019-05-092023-06-13
4155Think Outside the Scope: Advanced CORS Exploitation Techniques CORS misconfiguration NA Ayoub (@sandh0t) Bug Bounty2019-05-142023-06-13
4154Is MIME Sniffing XSS a real thing? [The story of weird Google bug bounties] Stored XSS MIME sniffing Google Komodo Security Bug Bounty2019-05-152023-06-13
4153You do not need to run 80 reconnaissance tools to get access to user accounts Open redirect NA Stefano Vettorazzi (@stefanohablando) Bug Bounty2019-05-152023-06-13
4152From parameter pollution to XSS HTTP parameter pollution XSS NA Mo%27men Basel Bug Bounty2019-05-162023-06-13
4150Bypassing Instagram’s stories restriction Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-05-172023-06-13
4149Stealing Downloads from Slack Users CSRF Slack David Wells Bug Bounty2019-05-172023-06-13