Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2932API based IDOR to leaking Private IP address of 6000 businesses IDOR NA Rafi Ahamed (Leonidas D. Ace) Bug Bounty2021-01-012023-06-13
2928Exploiting Max. Character Limitation Logic flaw DoS NA Sunil Yedla (@sunilyedla2) Bug Bounty2021-01-052023-06-13
2927Privilege Escalation: From being a normal user to admin Privilege escalation Broken Access Control NA Akshar Tank Bug Bounty2021-01-052023-06-13
2926Each and every request make sense… Privilege escalation Exposed JWT generation endpoint JWT NA Akshar Tank Bug Bounty2021-01-052023-06-13
2925Incident Response during Christmas Subdomain takeover NA TMO Bug Bounty2021-01-052023-06-13
2924Achieving Remote Code Execution By Exploiting Variable Check Feature RCE NA Shawar Khan (@ShawarkOFFICIAL) Bug Bounty2021-01-062023-06-13
2921Subdomain Take Over Worth 100£ Subdomain takeover NA c0d3x27 (@c0d3x27) Bug Bounty2021-01-072023-06-13
2920Stored XSS on Product Description [HIGH] — $400 Stored XSS NA Emanuel Beni Harijanto Bug Bounty2021-01-072023-06-13
2918$10,000 for a vulnerability that doesn’t exist Path traversal NA Valeriy Shevchenko (@Krevetk0Valeriy) Bug Bounty2021-01-072023-06-13
2916Information Disclosure through Signup Endpoint Information disclosure NA Sunil Yedla (@sunilyedla2) Bug Bounty2021-01-082023-06-13
2914Exploiting Application-Level Profile Semantics (APLS) APLS misconfiguration API misconfiguration NA Niemand (@niemand_sec) Bug Bounty2021-01-082023-06-13
2912A %27Novel%27 Way to Bypass Executable Signature Checks with Electron Local Privilege Escalation NA Parsia Hackerman (@cryptogangsta) Bug Bounty2021-01-082023-06-13
2911How I was able to Regain access to account deleted by Admin leading to $$$ Logic flaw Authorization flaw NA Rajesh Ranjan (@_rajesh_ranjan_) Bug Bounty2021-01-102023-06-13
2909Weblogic Remote Code Execution (Exploiting CVE-2019-2725) RCE NA Mahmoud Gamal (@Zombiehelp54) Bug Bounty2021-01-102023-06-13
2906Guest Blog Post: Leaking silhouettes of cross-origin images Side-channel information leakage Browser hacking Mozilla Google (Chrome) Aleksejs Popovs (@aleksejspopovs) Bug Bounty2021-01-112023-06-13
2905Unrestricted File Upload Unrestricted file upload NA Binamra Pandey Bug Bounty2021-01-122023-06-13
2904CSRF with IDOR - A Deadly Combo CSRF IDOR NA Jerry Shah (@Jerry) Bug Bounty2021-01-122023-06-13
2903Stealing User Information Via XSS Via Parameter Pollution Open redirect XSS NA Hamza Avvan (@hamzaavvan) Bug Bounty2021-01-122023-06-13
2900Story of a really cool SSRF bug. SSRF NA Vedant Tekale (@_justYnot) Bug Bounty2021-01-132023-06-13
2899How I managed to trigger a Stored-XSS in an online store with the help of Cache Poisoning Web cache poisoning Stored XSS NA Schizo! Bug Bounty2021-01-142023-06-13
2896Insertion Of Malicious Links For Execution In Profile Picture - Unvalidated User Input In MS Sharepoint 2019 (CVE-2020-1456) XSS Microsoft David (@slashcrypto) Bug Bounty2021-01-152023-06-13
2895How I hijacked the top-level domain of a sovereign state Domain takeover Internet Bug Bounty Fredrik N. Almroth (@Almroot) Bug Bounty2021-01-152023-06-13
2892Hacking naked Akamai ARL at scale Akamai ARL attack NA Randy Gingeleski (@gingeleski) Bug Bounty2021-01-152023-06-13
2891Weaponizing Apify for mass bug bounty $$$ Akamai ARL attack NA Randy Gingeleski (@gingeleski) Bug Bounty2021-01-162023-06-13
2889My first and last crit of 2020 on Hackerone Lack of rate limiting Bruteforce IDOR Password reset Account takeover NA Takester (@dhiraj_ramteke) Bug Bounty2021-01-162023-06-13