Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3262Using XAMPP and Burp Intruder when scanning for subdomains to look for interesting behaviour & code Information disclosure NA Zseano (@zseano) Bug Bounty2020-07-302023-06-13
3239The feature works as intended, but what’s in the source? Information disclosure NA Zseano (@zseano) Bug Bounty2020-08-082023-06-13
3235Hacking Zoom: Uncovering Tales of Security Vulnerabilities in Zoom Information disclosure RCE Memory leak Zoom Mazin Ahmed (@mazen160) Bug Bounty2020-08-082023-06-13
3233My 2nd 4digit Bug Bounty From Facebook Logic flaw Information disclosure Meta / Facebook Sudip Shah Bug Bounty2020-08-102023-06-13
3229How I was able to find page/personal account disclosure on Instagram Information disclosure Meta / Facebook Ajay Gautam (@evilboyajay) Bug Bounty2020-08-112023-06-13
3222Leaking AWS Metadata - The Unusual Way Information disclosure RCE NA Shubham Garg (@nullb0t) Bug Bounty2020-08-132023-06-13
3208Firebase Cloud Messaging Service Takeover: A small research that led to 30k$+ in bounties Hardcoded API keys Information disclosure Google Abss (@absshax) Bug Bounty2020-08-172023-06-13
3202Escalating a GitHub leak to takeover entire organization Information disclosure NA Shashank (@cyberboyIndia) Bug Bounty2020-08-182023-06-13
3201Django debug mode to RCE in Microsoft acquisition Information disclosure RCE Microsoft Syed Abuthahir (@writerabu) Bug Bounty2020-08-192023-06-13
3191Waze: How I Tracked Your Mother Logic flaw Information disclosure Google (Waze) Peter Gasper (@malgregator) Bug Bounty2020-08-252023-06-13
3167How often do we overlook vulnerabilities? Information disclosure HackerOne Baibhav Anand (@SpongeBhav) Bug Bounty2020-09-092023-06-13
3139#Bugbounty- “How I was able to see other users Payments in a travel application” — IDOR #800$ IDOR Information disclosure NA ganiganesh (@ganiganeshss79) Bug Bounty2020-09-222023-06-13
3136PII Leakage via IDOR + Weak PasswordReset = Full Account Takeover IDOR Information disclosure NA Pradeep Kumar (@Killer007p) Bug Bounty2020-09-252023-06-13
3135Advisory: security issues in AWS KMS and AWS Encryption SDKs Cryptographic issues Information disclosure AWS Thai Duong (@XorNinja) Bug Bounty2020-09-252023-06-13
3130P1: Critical - Discovering and Foiling a Threat Actor Information disclosure NA Jackson Henry (@JacksonHHax) Bug Bounty2020-09-272023-06-13
3128Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts GCP bucket misconfiguration Information disclosure Cloud Google Thomas Orlita (@ThomasOrlita) Bug Bounty2020-09-292023-06-13
3125Story of a weird vulnerability I found on Facebook Authentication bypass Information disclosure Meta / Facebook Amine Aboud (@amineaboud) Bug Bounty2020-09-302023-06-13
3119Spend more time doing recon, you’ll find more BUGS. Reflected XSS Information disclosure NA Vedant Tekale (@_justYnot) Bug Bounty2020-10-032023-06-13
3117Easy wins : verbose error worth Facebook HOF Information disclosure Meta / Facebook Mukul Lohar (@ironfisto) Bug Bounty2020-10-052023-06-13
311590 days, 16 bugs, and an Azure Sphere Challenge Local privilege escalation RCE DoS Information disclosure Microsoft Cisco Talos Bug Bounty2020-10-062023-06-13
3113Sensitive Info Leak in Curve App [Bug Bounty] Information disclosure Curve ΡRΛSΞUDΟ ® (@praseudo) Bug Bounty2020-10-072023-06-13
3103JS is l0ve ❤️. Information disclosure API key leakage NA Shivam Kamboj Dattana (@sechunt3r) Bug Bounty2020-10-092023-06-13
3099Disclose Emails, phone numbers, more For Facebook users who tried to add funds to their account Information disclosure Meta / Facebook Mustafa Ahmed (@mustafa0x2021) Bug Bounty2020-10-122023-06-13
3088Back to 2019: Disclosure Employers PII and Credentials Information disclosure NA Wh11teW0lf (@wh11tew0lf) Bug Bounty2020-10-202023-06-13
3078Link Previews: How a Simple Feature Can Have Privacy and Security Risks Information disclosure Discord Meta / Facebook Google LINE LinkedIn Slack Twitter Zoom Talal Haj Bakry (@parasarora06) Bug Bounty2020-10-252023-06-13