Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3270FFUF and my first bounty Information disclosure NA Suryansh Mansharamani Bug Bounty2020-07-292023-06-13
3269XSS, RCE & HTML File Upload in same endpoint XSS RCE Unrestricted file upload NA Tarikul Islam (@sa1tama0) Bug Bounty2020-07-292023-06-13
3268The Noob Way Of Taking Over Accounts Authorization flaw Account takeover Homograph attack NA Mudassir Sharief Bug Bounty2020-07-292023-06-13
3266One Click to Compromise -- Fun With ClickOnce Deployment Manifests NTLMv2 hash disclosure One-click execution of arbitrary .Net assemblies Windows Microsoft Dave Cossa (@G0ldenGunSec) Bug Bounty2020-07-302023-06-13
3265Exploiting Business Logic — Wallet Money Payment tampering Logic flaw NA Keshav Malik (@g0t_rOoT_) Bug Bounty2020-07-302023-06-13
3263New features means new bugs Logic flaw Authorization flaw Payment bypass NA Zseano (@zseano) Bug Bounty2020-07-302023-06-13
3262Using XAMPP and Burp Intruder when scanning for subdomains to look for interesting behaviour & code Information disclosure NA Zseano (@zseano) Bug Bounty2020-07-302023-06-13
3261Bypassing OTP via reset password OTP bypass NA Ahmed Cj (@0x0Cj) Bug Bounty2020-07-302023-06-13
3260Unauthd - Logic bugs FTW Logic flaw Apple Ilias Morad (@A2nkF_) Bug Bounty2020-07-312023-06-13
3259CVE-2020–9854: "Unauthd" - (three) logic bugs ftw! Local Privilege Escalation Logic flaw Apple Ilias Morad (@A2nkF_) Bug Bounty2020-08-012023-06-13
3258CVE-2020-13379 Unauthenticated Full-Read SSRF in Grafana SSRF Open redirect NA Justin Gardner (@Rhynorater) Bug Bounty2020-08-012023-06-13
3257Refocusing in bug hunting, Bonus: An interestingly simple to test CSRF bypass CSRF NA Vuk Ivanovic Bug Bounty2020-08-012023-06-13
3256CVE-2020–9854: "Unauthd" MacOS Local Privilege Escalation SIP bypass Apple (macOS) Ilias Morad (@A2nkF_) Bug Bounty2020-08-012023-06-13
3255Multi-factor Auth Bypass with Password Reset Function MFA bypass Password reset Account takeover NA Vaibhav Joshi (@vj0shii) Bug Bounty2020-08-022023-06-13
3254Banning users Race condition Race condition NA Saddam Hussain (@wisdomfreak1) Bug Bounty2020-08-022023-06-13
3250Amazon AWS Bastion - Logger Bypass Logging bypass Local Privilege Escalation AWS Denis Andzakovic Bug Bounty2020-08-032023-06-13
3249How I was able to do Mass Account Takeover[Bug Bounty] Account takeover Password reset NA Not Rickyy (@RickyyNot) Bug Bounty2020-08-052023-06-13
3248I want all these features Logic flaw Payment tampering NA Mohamed Ayad Bug Bounty2020-08-052023-06-13
3247CSRF PoC mistake that broke crucial functions for the end user/victim Logic flaw NA Vuk Ivanovic Bug Bounty2020-08-052023-06-13
3246The Case of the Missing Cache Keys Web cache poisoning NA Aaron Costello (@ConspiracyProof) Bug Bounty2020-08-052023-06-13
3245Apache Example Servlet leads to $$$$ Clickjacking NA Debangshu Kundu (@debangshu_kundu) Bug Bounty2020-08-062023-06-13
3240Exploiting JWT - Lack of Signature Verification Account takeover NA Aditya Dixit (@zombie007o) Bug Bounty2020-08-062023-06-13
3239The feature works as intended, but what’s in the source? Information disclosure NA Zseano (@zseano) Bug Bounty2020-08-082023-06-13
3237Bug Hunting with Param Miner: Cache poisoning with XSS, a peculiar case XSS Web cache poisoning NA Vuk Ivanovic Bug Bounty2020-08-082023-06-13
3234Bypassing 403 Authentication bypass NA Michael Hyndman (@michaelhyndman) Bug Bounty2020-08-092023-06-13