Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4118How I was able to get private ticket response panel and FortiGate web panel via blind XSS Blind XSS NA Bijan Murmu (@0xBijan) Bug Bounty2019-06-062023-06-13
4117Don’t underestimates the Errors They can provide good $$$ Bounty! Information disclosure Internal path disclosure Mamba Aditya Sharma (@Assass1nmarcos) Bug Bounty2019-06-072023-06-13
4116IDOR Leads To Project Takeover IDOR NA Hariharan.s (@DJHARIZ1) Bug Bounty2019-06-092023-06-13
4115Account takeover using IDOR and the misleading case of error 403. IDOR NA Plenum (@plenumlab) Bug Bounty2019-06-112023-06-13
4114Facebook Vulnerability: Non-unfriendable user in /hacked workflow Logic flaw Meta / Facebook Ritish Kumar Singh Bug Bounty2019-06-112023-06-13
4113Reflected XSS on Error Page Reflected XSS NA Tomi (@noobe_io) Bug Bounty2019-06-112023-06-13
4112Redstrom Denial Of Service — Write Up DoS NA Zerb0a Bug Bounty2019-06-122023-06-13
4111Chaining Improper Authorization To Race Condition To Harvest Credit Card Details : A Bug Bounty Story Authorization flaw Race condition NA Mandeep Jadon (@1337tr0lls) Bug Bounty2019-06-132023-06-13
4110How spending our Saturday hacking earned us 20k IDOR NA Matti Bijnens (@MattiBijnens) Bug Bounty2019-06-142023-06-13
4109IDOR — Account Takeover IDOR NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-06-142023-06-13
4108v1 Instance Metadata Service protections bypass SSRF Google Anthony Weems Bug Bounty2019-06-142023-06-13
4107Admin Account total Information Disclosure Source code disclosure Information disclosure NA Nishant Saurav (@inishantsinha) Bug Bounty2019-06-152023-06-13
4106XSSing Google Employees — Blind XSS on googleplex.com Blind XSS Google Thomas Orlita (@ThomasOrlita) Bug Bounty2019-06-152023-06-13
4105Fullscreen API Attack’s Revisited and the FaceBook NA Story Phishing Meta / Facebook Circle Ninja (@circleninja) Bug Bounty2019-06-152023-06-13
4104Complete Web Server Access Unrestricted file upload RCE NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-06-152023-06-13
4103Bug Bounty - Information Disclosure through error message + WAF Bypass led to Local File Inclusion WAF bypass LFI Information disclosure NA Λявєη (@spenkkkkk) Bug Bounty2019-06-152023-06-13
4102Stealing Cookies to Login in any Account Cookie theft NA Osama Avvan (@osamaavvan) Bug Bounty2019-06-162023-06-13
4101Account Takeover Worth $900 Account takeover CSRF NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-06-162023-06-13
4100How I earned $1,500 in just 15 mins due to Amazon S3 bucket misconfiguration? AWS misconfiguration Dropbox Muhammad Asim Shahzad (@protector47) Bug Bounty2019-06-162023-06-13
4099Password Bypass and Something Else… Authentication bypass NA Vibhurushi Chotaliya (@_Vibhurushi_) Bug Bounty2019-06-162023-06-13
4098Bypassing XSS filter and Stealing User Payment Data XSS NA Osama Avvan (@osamaavvan) Bug Bounty2019-06-172023-06-13
4097SQl Injection SQL injection NA Saad Ahmed (@XSaadAhmedX) Bug Bounty2019-06-172023-06-13
4096Parameter Pollution issue in API resulting $XXX HTTP parameter pollution NA Smaran Chand (@smaranchand) Bug Bounty2019-06-172023-06-13
4095Using Burp Suite match and replace settings to escalate your user privileges and find hidden features Client-side enforcement of server-side security New Relic Jon Bottarini (@jon_bottarini) Bug Bounty2019-06-172023-06-13
4094Reflected XSS in Tokopedia Train Ticket Reflected XSS New Relic Jon Bottarini (@jon_bottarini) Bug Bounty2019-06-172023-06-13