Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3974[Business Logic] Bypassing Nickname Feature Logic flaw NA Kent Bayron / kntx (@bayronkentoy) Bug Bounty2019-08-142023-06-13
3970How I was able to earn 1000$ with just 10 minutes of bug bounty? Password reset NA Ninad Mathpati (@ninad_mathpati) Bug Bounty2019-08-172023-06-13
3967U.S. Department of Defense - Info Disclosure and SQLi Writeup Information disclosure SQL injection U.S. Dept Of Defense Aaron Esau (@arinerron) Bug Bounty2019-08-192023-06-13
3957From Github Recon To Account Takeover Information disclosure Account takeover NA Dipak kumar Das (@d1pakdas) Bug Bounty2019-08-242023-06-13
3955Bug Bounty: Bypassing a crappy WAF to exploit a blind SQL injection Blind SQL injection NA Robin Verton (@robinverton) Bug Bounty2019-08-252023-06-13
3952Private bug bounty $$,$$$ USD: “RCE as root on Marathon-Mesos instance” RCE NA Omar Espino (@omespino) Bug Bounty2019-08-272023-06-13
3951How to look for JS files Vulnerability for fun and profit? Information disclosure NA Yeasir Arafat Bug Bounty2019-08-272023-06-13
3949Shodan is your friend!!! If you ignore him you will lose many… SQL injection Authentication bypass NA Vijaysimha Reddy Bathini (@fatratfatrat) Bug Bounty2019-08-282023-06-13
3948My First LFI LFI NA Tirtha Mandal (@tirtha_mandal) Bug Bounty2019-08-312023-06-13
3947Graphql Bug to Steal Anyone’s Address Information disclosure GraphQL NA Pratik Yadav (@PratikY9967) Bug Bounty2019-09-012023-06-13
3944RCE using Path Traversal RCE Path traversal NA inc0gbyt3 (@incogbyte) Bug Bounty2019-09-022023-06-13
3943Add new user with Admin permission and takeover the organization Authorization flaw Privilege escalation NA Tarek Mohamed (@Conan0x3) Bug Bounty2019-09-042023-06-13
3942Exposed Jenkins to RCE on 8 Adobe Experience Managers RCE Exposed Jenkins instance NA Corben Leo (@hacker_) Bug Bounty2019-09-042023-06-13
3940DOM Based XSS in Private Program DOM XSS NA Mohamed Haron (@m7mdharon) Bug Bounty2019-09-052023-06-13
3939Super Glamorous Recon with Intended Functionalities SSTI XSS NA hateshape (@hateshaped) Bug Bounty2019-09-062023-06-13
3938Finding Gem in Someone’s Report: Instant $500USD at HackerOne Platform Information disclosure NA Hisoka Morou Bug Bounty2019-09-072023-06-13
3937Write up of two HTTP Requests Smuggling HTTP request smuggling NA C1h2e1 (@C1h2e11) Bug Bounty2019-09-072023-06-13
3936Exploiting JSONP and Bypassing Referer Check Information disclosure JSONP NA Osama Avvan (@osamaavvan) Bug Bounty2019-09-072023-06-13
3934Oculus identity verification bypass through brute-force OTP bypass Lack of rate limiting Meta / Facebook karthik kumar reddy (@karthiksunny007) Bug Bounty2019-09-092023-06-13
3931H1-4420: From Quiz to Admin - Chaining Two 0-Days to Compromise An Uber Wordpress Stored XSS SQL injection Uber Julien Ahrens (@MrTuxracer) Bug Bounty2019-09-102023-06-13
3929Pwn Them All #BugBounty Host header injection Password reset NA Bilal Khan (@bilalmerokhel) Bug Bounty2019-09-112023-06-13
3927How does my recon win $250 in 15 minutes Open redirect NA Hein Thant Zin (@H3Lowr) Bug Bounty2019-09-122023-06-13
3925Exploiting File Uploads Pt. 2 – A Tale of a $3k worth RCE. Unrestricted file upload RCE NA HackerOn2Wheels (@HackerOn2Wheels) Bug Bounty2019-09-132023-06-13
3924HTTP Request Smuggling CL.TE HTTP request smuggling NA memN0ps (@memN0ps) Bug Bounty2019-09-132023-06-13
3923Unauthorized access to all user information leaks Information disclosure NA C1h2e1 (@C1h2e11) Bug Bounty2019-09-132023-06-13