Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3844My First SSRF Using DNS Rebinding SSRF DNS rebinding NA Marek Geleta (@marek_geleta) Bug Bounty2019-11-112023-06-13
3843Keylogging users via Slack themes CSS injection Slack Matt Langlois (@fletchto99) Bug Bounty2019-11-112023-06-13
3842How i Bought VPS, Hosting, Domain only $0.01 Payment tampering NA Zerb0a Bug Bounty2019-11-122023-06-13
3841Bug Bounty: Broken API Authorization Authorization flaw NA Th3hidd3nmist (@th3_hidd3n_mist) Bug Bounty2019-11-122023-06-13
3840How I accidentally took down GitHub Actions DoS Commit Hash Collisions GitHub Teddy Katz (@not_aardvark) Bug Bounty2019-11-122023-06-13
3839Mass XS-Search using Cache Attack XS-Search Google Terjanq (@terjanq) Bug Bounty2019-11-122023-06-13
3838Command Injection Through BLH Broken link hijacking Meta / Facebook Shankar R (@trapp3r_hat) Bug Bounty2019-11-142023-06-13
3837[Server Side Request Forgery] Blind SSRF due to Sentry Misconfiguration SSRF NA Kent Bayron (@bayronkentoy) Bug Bounty2019-11-142023-06-13
3836Taking over Facebook Page Tabs Broken link hijacking Meta / Facebook Taking over Facebook Page Tabs Bug Bounty2019-11-142023-06-13
3835Chains on Chains!! Chaining several IDOR’s into Account Takeover(PART ONE) IDOR NA Daniel Marte (@DanielM59720745) Bug Bounty2019-11-152023-06-13
3834Authenticated CORS with Access-Control-Allow-Origin: * Caching issue Browser hacking Google (Chromium) BitK (@BitK_) Bug Bounty2019-11-152023-06-13
3833[Writeup][Bug Bounty][Tokopedia] Manipulation of Likes in Product Reviews [EN] IDOR Tokopedia Muhammad Thomas Fadhila Yahya (@fadhilthomas) Bug Bounty2019-11-152023-06-13
3831LDAP Admin Account Bypassed :) LDAP injection Authentication bypass NA Himanshu Pdy (@himanshu_pdy) Bug Bounty2019-11-162023-06-13
3830Privilege Escalation with simple recon Privilege escalation Blind XSS NA Mayur Gupta (@RisingHunter_) Bug Bounty2019-11-162023-06-13
3829Bypassing the patch for my previous Instagram bug. Authorization flaw Logic flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-11-182023-06-13
3828My First Bug ($500) No valid SPF records NA Abhishek Yadav (@abhishake100) Bug Bounty2019-11-182023-06-13
3827This is How I was able to hunt a rare bug in a private program Missing authentication Privilege escalation NA Abida Fahd Bug Bounty2019-11-182023-06-13
3826XSS in GMail’s AMP4Email via DOM Clobbering XSS DOM Clobbering Google Michał Bentkowski (@SecurityMB) Bug Bounty2019-11-182023-06-13
3825Million Users PII Leak Data Leak Information disclosure Blind XSS NA Shivbihari Pandey (@ninja_pandit_) Bug Bounty2019-11-182023-06-13
3823Broken session management leads to bypass 2FA and Permanent access to Facebook user’s Authentication bypass Meta / Facebook Mahmoud Barakat (@0xBarakat) Bug Bounty2019-11-192023-06-13
3822How I could delete Facebook Ask for Recommendations post’s place objects in comments IDOR Meta / Facebook Raja Sudhakar (@Rajasudhakar) Bug Bounty2019-11-202023-06-13
3821Subdomain Takeover via Campaignmonitor.com Subdomain takeover NA Mohamed Haron (@m7mdharon) Bug Bounty2019-11-202023-06-13
3820How I paid 2$ for a 1054$ XSS bug + 20 chars blind XSS payloads XSS NA Mohamed Daher (@DaherMohamed4) Bug Bounty2019-11-202023-06-13
3819Cracking reCAPTCHA, Turbo Intruder style Captcha bypass Race condition Google James Kettle (@albinowax) Bug Bounty2019-11-202023-06-13
3818Reply To Instagram Stories where privacy of who can reply is set to Nobody’. (Part 2) Authorization flaw Meta / Facebook Baibhav Anand (@SpongeBhav) Bug Bounty2019-11-212023-06-13