Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2987$10000 Facebook SSRF (Bug Bounty) SSRF Meta / Facebook Amine Aboud (@amineaboud) Bug Bounty2020-12-032023-06-13
2900Story of a really cool SSRF bug. SSRF NA Vedant Tekale (@_justYnot) Bug Bounty2021-01-132023-06-13
2880SSRF Exploitation in Libreoffice Spreadsheet File Converter SSRF NA R4id3n (@R4id3n__) Bug Bounty2021-01-212023-06-13
2879Story Behind Sweet SSRF. SSRF XSS NA Rohit Soni (@streetofhacker) Bug Bounty2021-01-212023-06-13
2865Finding SSRF BY Full Automation SSRF NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-01-272023-06-13
2862Bragging Rights(Part 1): Short story of a bug wave IDOR Stored XSS SSRF Subdomain takeover Hardcoded credentials NA Manas Harsh (@ManasH4rsh) Bug Bounty2021-01-272023-06-13
2832Escalating SSRF to RCE SSRF RCE NA Sander Wind (@SanderWind) Bug Bounty2021-02-062023-06-13
2813[GITLAB] — Just another SSRF issue. SSRF GitLab Lyubomir Tsirkov (@lyubo_tsirkov) Bug Bounty2021-02-132023-06-13
2812[GITLAB] — Server Side Request Forgery in “Project Import” page. SSRF GitLab Lyubomir Tsirkov (@lyubo_tsirkov) Bug Bounty2021-02-132023-06-13
2765SSRF: Bypassing hostname restrictions with fuzzing SSRF Elastic Dominic (@dee__see) Bug Bounty2021-02-262023-06-13
2763CVE-2020–13956 Blind SSRF URL parsing issue Apache HttpClient Priyank (@Rev_Octo) Bug Bounty2021-02-262023-06-13
2752SSRF to fetch AWS credentials with full access to multiple services SSRF NA Zonduhackerone (@zonduu1) Bug Bounty2021-02-282023-06-13
2736Exploiting a hidden and forgotten Bug SSRF NA Aditya Verma (@0cirius0) Bug Bounty2021-03-072023-06-13
2730Write Up – Google VRP N/A: SSRF Bypass With Quadzero In Google Cloud Monitoring SSRF Google Omar Espino (@omespino) Bug Bounty2021-03-082023-06-13
2713An unknown Linux secret that turned SSRF to OS Command injection SSRF Command injection NA secureITmania (@secureitmania) Bug Bounty2021-03-172023-06-13
2707How I hacked Facebook: Part Two SSRF Account takeover Cookie manipulation Meta / Facebook Alaa Abdulridha (@alaa0x2) Bug Bounty2021-03-182023-06-13
2656Chaining an Blind SSRF bug to Get an RCE Blind SSRF RCE NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-04-072023-06-13
2652Cookie poisoning leads to DoS and Privacy Violation DoS SSRF CS Money Benjamin Walter Bug Bounty2021-04-092023-06-13
2627Blind SSRF to Port Scanning through response time SSRF NA Harish Bug Bounty2021-04-192023-06-13
2612AWS internal metadata accessed through SSRF by Chaining an Open Redirect bug SSRF Open redirect NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2021-04-242023-06-13
2597A tale of Html to Pdf converter ssrf and various bypasses SSRF NA Jatin Aesthetic (@techyfreakk) Bug Bounty2021-04-292023-06-13
2590How I got $400 for my first SSRF bug? SSRF NA Usama Varikkottil (@usama_dev) Bug Bounty2021-05-012023-06-13
2588SSRF Through PDF Generation SSRF NA Joshua Martinelle (@J0_mart) Bug Bounty2021-05-012023-06-13
2548Just Gopher It: Escalating a Blind SSRF to RCE for $15k SSRF RCE NA SirLeeroyJenkins (@SirLeeroyJenkin) Bug Bounty2021-05-172023-06-13
2542SSRF in PDF Renderer using SVG SSRF NA pwn.vg / Tomi (@mastomii) Bug Bounty2021-05-192023-06-13