New Writeup❗️
Date: Wed, 30 Nov 2022 02:28:25 GMT
Title: Stored XSS at https://www.tiktok.com/
Link: https://medium.com/p/11fed6db0590
Date: Wed, 30 Nov 2022 02:28:25 GMT
Title: Stored XSS at https://www.tiktok.com/
Link: https://medium.com/p/11fed6db0590
New Writeup❗️
Date: Thu, 25 Aug 2022 07:53:18 GMT
Title: SOLUTION to XSS Challenge From V1 — V8
Link: https://medium.com/p/5b17f1c2c07f
Date: Thu, 25 Aug 2022 07:53:18 GMT
Title: SOLUTION to XSS Challenge From V1 — V8
Link: https://medium.com/p/5b17f1c2c07f
Medium
SOLUTION to XSS Challenge From V1 — V8
Hi everyone,
New Writeup❗️
Date: Thu, 28 Jul 2022 15:09:00 GMT
Title: XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern
Link: https://medium.com/p/3bf727208cee
Date: Thu, 28 Jul 2022 15:09:00 GMT
Title: XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern
Link: https://medium.com/p/3bf727208cee
Medium
XSS in Open Redirect which uses attribute rel=”noopener follow” target=”_blank Via Browser Modern
Hi everyone
New Writeup❗️
Date: Wed, 29 Jun 2022 02:11:54 GMT
Title: XSS Blind Stored at 2 Assets TikTok
Link: https://medium.com/p/f32829f11e58
Date: Wed, 29 Jun 2022 02:11:54 GMT
Title: XSS Blind Stored at 2 Assets TikTok
Link: https://medium.com/p/f32829f11e58
Medium
XSS Blind Stored at 2 Assets TikTok
Hi everyone,
New Writeup❗️
Date: Thu, 16 Jun 2022 02:54:26 GMT
Title: XSS Blind Stored at Asset Domain Android Apps TikTok
Link: https://medium.com/p/ae2f4c2dbc07
Date: Thu, 16 Jun 2022 02:54:26 GMT
Title: XSS Blind Stored at Asset Domain Android Apps TikTok
Link: https://medium.com/p/ae2f4c2dbc07
Medium
XSS Blind Stored at Asset Domain Android Apps TikTok
Hi everyone
New Writeup❗️
Date: Sat, 28 May 2022 07:18:44 GMT
Title: The first XSS STORED find in YANDEX Bug Bounty Program
Link: https://medium.com/p/9faf8e5caa5
Date: Sat, 28 May 2022 07:18:44 GMT
Title: The first XSS STORED find in YANDEX Bug Bounty Program
Link: https://medium.com/p/9faf8e5caa5
Medium
The first XSS STORED find in YANDEX Bug Bounty Program
Assalamualaikum Bug Hunter & Hi Everyone.
New Writeup❗️
Date: Tue, 08 Mar 2022 05:50:14 GMT
Title: ($$$) IDOR via GET Request which can SOLD all User Products
Link: https://medium.com/p/2f5bc3ea1650
Date: Tue, 08 Mar 2022 05:50:14 GMT
Title: ($$$) IDOR via GET Request which can SOLD all User Products
Link: https://medium.com/p/2f5bc3ea1650
Medium
($$$) IDOR via GET Request which can SOLD all User Products
Hi everyone,
New Writeup❗️
Date: Tue, 25 Jan 2022 12:00:48 GMT
Title: First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft
Link: https://medium.com/p/a2c185c53074
Date: Tue, 25 Jan 2022 12:00:48 GMT
Title: First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft
Link: https://medium.com/p/a2c185c53074
Medium
First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft
Hi Everyone.
New Writeup❗️
Date: Tue, 11 Jan 2022 00:13:19 GMT
Title: [ CVE-2021-46146 ] Stored XSS via WikibaseMediaInfo caption fields at commons.wikimedia.org
Link: https://medium.com/p/46b75d92df7a
Date: Tue, 11 Jan 2022 00:13:19 GMT
Title: [ CVE-2021-46146 ] Stored XSS via WikibaseMediaInfo caption fields at commons.wikimedia.org
Link: https://medium.com/p/46b75d92df7a
Medium
[ CVE-2021-46146 ] Stored XSS via WikibaseMediaInfo caption fields at commons.wikimedia.org
Hi everyone,
New Writeup❗️
Date: Mon, 31 Oct 2022 08:17:15 GMT
Title: 2FA Bypass due to information disclosure & Improper access control.
Link: https://medium.com/p/f9a5a8a4e0af
Date: Mon, 31 Oct 2022 08:17:15 GMT
Title: 2FA Bypass due to information disclosure & Improper access control.
Link: https://medium.com/p/f9a5a8a4e0af
Medium
2FA Bypass due to information disclosure & Improper access control.
Today i will be explaining how i found a 2FA bypass while i was looking for DOS but DOS is possible if the logic isn’t implemented so its worth to look these types of vulnerabilities in…
New Writeup❗️
Date: Wed, 06 Apr 2022 02:27:47 GMT
Title: Watch out the links : Account takeover
Link: https://medium.com/p/32b9315390a7
Date: Wed, 06 Apr 2022 02:27:47 GMT
Title: Watch out the links : Account takeover
Link: https://medium.com/p/32b9315390a7
Medium
Watch out the links : Account takeover
This is my second writeup here :), Hope you find enjoy it too!
New Writeup❗️
Date: Sat, 02 Apr 2022 17:44:13 GMT
Title: Design Flaw — A Tale of Permanent DOS
Link: https://medium.com/p/a9ef05181083
Date: Sat, 02 Apr 2022 17:44:13 GMT
Title: Design Flaw — A Tale of Permanent DOS
Link: https://medium.com/p/a9ef05181083
Medium
Design Flaw — A Tale of Permanent DOS
This is my first writeup here on medium. Hope you enjoy it :). Feedbacks are always appreciated!
New Writeup❗️
Date: Tue, 05 Jan 2021 16:31:42 GMT
Title: Each and every request make sense…
Link: https://medium.com/p/4572b3205382
Date: Tue, 05 Jan 2021 16:31:42 GMT
Title: Each and every request make sense…
Link: https://medium.com/p/4572b3205382
Medium
Each and every request make sense…
Hello Everyone,
New Writeup❗️
Date: Mon, 12 Jul 2021 07:46:17 GMT
Title: eLearnSecurity(eCPPTv2) Review
Link: https://medium.com/p/1330823fab1a
Date: Mon, 12 Jul 2021 07:46:17 GMT
Title: eLearnSecurity(eCPPTv2) Review
Link: https://medium.com/p/1330823fab1a
Medium
eLearnSecurity(eCPPTv2) Review
Introduction -
New Writeup❗️
Date: Mon, 22 Mar 2021 04:17:38 GMT
Title: Exploiting CSRF (GET Methods)
Link: https://medium.com/p/60b56d15efa3
Date: Mon, 22 Mar 2021 04:17:38 GMT
Title: Exploiting CSRF (GET Methods)
Link: https://medium.com/p/60b56d15efa3
Medium
Exploiting CSRF (GET Methods)
Hey guys, hope you are doing well.
New Writeup❗️
Date: Mon, 04 Jan 2021 17:14:06 GMT
Title: CSRF Attack!!!
Link: https://medium.com/p/e7bb9f3f36e1
Date: Mon, 04 Jan 2021 17:14:06 GMT
Title: CSRF Attack!!!
Link: https://medium.com/p/e7bb9f3f36e1
Medium
CSRF Attack!!!
Hey guys, Hope you are doing well.
New Writeup❗️
Date: Thu, 12 May 2022 16:09:11 GMT
Title: Forging OAuth tokens using discovered client id and client secret
Link: https://medium.com/p/d224e4e7892a
Date: Thu, 12 May 2022 16:09:11 GMT
Title: Forging OAuth tokens using discovered client id and client secret
Link: https://medium.com/p/d224e4e7892a
Medium
Forging OAuth tokens using discovered client id and client secret
Below is a short story about leaked OAuth client id and client secret which I found in the page source that led to generating foreign…
New Writeup❗️
Date: Fri, 18 Nov 2022 21:54:15 GMT
Title: Remediation Archeology — Finding and Decoding an Ancient XSS
Link: https://medium.com/p/ea541c1106d1
Date: Fri, 18 Nov 2022 21:54:15 GMT
Title: Remediation Archeology — Finding and Decoding an Ancient XSS
Link: https://medium.com/p/ea541c1106d1
Medium
Remediation Archeology — Finding and Decoding an Ancient XSS
One of my favorite pastimes in Bug Bounty is reviewing my ancient (read: 2 or 3 years old) vulnerability reports. I feel like I’ve come a…
New Writeup❗️
Date: Fri, 21 May 2021 05:22:43 GMT
Title: Finding and Exploiting Unintended Functionality in Main Web App APIs
Link: https://medium.com/p/6eca3ef000af
Date: Fri, 21 May 2021 05:22:43 GMT
Title: Finding and Exploiting Unintended Functionality in Main Web App APIs
Link: https://medium.com/p/6eca3ef000af
Medium
Finding and Exploiting Unintended Functionality in Main Web App APIs
While hunting for bugs on Main Web Apps, I encounter tons of interesting APIs. Some are well secured, obscurely documented, and keep you in…
New Writeup❗️
Date: Sun, 04 Apr 2021 01:17:12 GMT
Title: Journeys in Quoteless and Multi Reflection XSS
Link: https://medium.com/p/b1d67bb0c5dd
Date: Sun, 04 Apr 2021 01:17:12 GMT
Title: Journeys in Quoteless and Multi Reflection XSS
Link: https://medium.com/p/b1d67bb0c5dd
Medium
Journeys in Quoteless and Multi Reflection XSS
Cross Site Scripting is a tricky bug to fix, and bypasses for these fixes can be even trickier. While there are several ways to remediate…
New Writeup❗️
Date: Mon, 28 Dec 2020 20:02:53 GMT
Title: How I Got My First Bounty & Hof From Google (CSRF Lead To Account Delete)
Link: https://medium.com/p/85f9906ba9ec
Date: Mon, 28 Dec 2020 20:02:53 GMT
Title: How I Got My First Bounty & Hof From Google (CSRF Lead To Account Delete)
Link: https://medium.com/p/85f9906ba9ec
Medium
How I Got My First Bounty & Hof From Google (CSRF Lead To Account Delete)
I am Bhupendra Rajbhar (Final Year Computer Engineering Student ) I have been started my bug bounty journey from march 2020 it was a…