Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4631User credential are sent in clear text in Whatsapp web— FIXED | Facebook Bug Bounty Credentials sent over unencrypted channel Meta / Facebook Thuvarakan Nakarajah Bug Bounty2018-08-182023-06-13
2474Story of Google Hall of Fame and Private program bounty worth $$$$ Exposed registration page Google Basavaraj Banakar (@basu_banakar) Bug Bounty2021-06-162023-06-13
1978How I was able to bypass WAF and find the origin IP and a few sensitive files WAF bypass NA Jan Muhammad Zaidi (@hasanakajan) Bug Bounty2021-12-222023-06-13
1687How I bypassed 403 forbidden domain using a simple trick 403 bypass NA Jan Muhammad Zaidi (@hasanakajan) Bug Bounty2022-03-292023-06-13
1628MY First Bug In Hackerone Information disclosure NA anjaneyulu kanakatla Bug Bounty2022-04-142023-06-13
1569Its all about 2fa bypass, or Account Takeover Password reset Account takeover OTP bypass NA anjaneyulu kanakatla Bug Bounty2022-05-082023-06-13
1403Vertical Privilege Escalation: The user can takeover an admin account via response manipulation Privilege escalation HTTP response manipulation NA Jan Muhammad Zaidi (@hasanakajan) Bug Bounty2022-07-022023-06-13
1357Business logic error Logic flaw NA anjaneyulu kanakatla Bug Bounty2022-07-162023-06-13
793SSRF via DNS Rebinding (CVE-2022–4096) SSRF DNS rebinding TOCTOU Appsmith Basavaraj Banakar (@basu_banakar) Bug Bounty2022-11-222023-06-13
629An amazing way to turn a xss into an ATO XSS Account takeover NA Naka Bug Bounty2023-01-022023-06-13
462SSRF That Allowed Us to Access Whole Infra Web Services and Many More SSRF NA Basavaraj Banakar (@basu_banakar) Bug Bounty2023-02-122023-06-13