New Writeup❗️
Date: Fri, 17 Feb 2023 15:00:27 GMT
Title: $$$$ IDOR’s — How to find IDORs in Ecommerce sites?
Link: https://medium.com/p/d112bd946fcf
Date: Fri, 17 Feb 2023 15:00:27 GMT
Title: $$$$ IDOR’s — How to find IDORs in Ecommerce sites?
Link: https://medium.com/p/d112bd946fcf
Medium
$$$$ IDOR’s — How to find IDORs in Ecommerce sites?
Introduction:
New Writeup❗️
Date: Sun, 07 Aug 2022 09:57:49 GMT
Title: How I got a $10,000 Penetration Testing Project/Job with Bug Bounty
Link: https://medium.com/p/b38ab4357ce4
Date: Sun, 07 Aug 2022 09:57:49 GMT
Title: How I got a $10,000 Penetration Testing Project/Job with Bug Bounty
Link: https://medium.com/p/b38ab4357ce4
Medium
How I got a $10,000 Penetration Testing Project/Job with Bug Bounty
Introduction:
New Writeup❗️
Date: Wed, 16 Feb 2022 11:04:34 GMT
Title: How I earned $9000 with Privilege escalations
Link: https://medium.com/p/b187d1f8f4fe
Date: Wed, 16 Feb 2022 11:04:34 GMT
Title: How I earned $9000 with Privilege escalations
Link: https://medium.com/p/b187d1f8f4fe
Medium
How I earned $9000 with Privilege escalations
Hello Community, It’s my very first time that I am sharing my experience and knowledge with you guys and I hope it will add some values to…
New Writeup❗️
Date: Fri, 26 Mar 2021 10:43:15 GMT
Title: How to bypass CloudFlare bot protection ?
Link: https://medium.com/p/1f2c6c0c36fb
Date: Fri, 26 Mar 2021 10:43:15 GMT
Title: How to bypass CloudFlare bot protection ?
Link: https://medium.com/p/1f2c6c0c36fb
Medium
How to bypass CloudFlare bot protection ?
Several months ago I submitted what appeared to be a security flaw to CloudFalre’s bugbounty program. According to them, this is not a…
New Writeup❗️
Date: Wed, 14 Jul 2021 07:06:31 GMT
Title: RFD Vulnerability And Content-Disposition Header Bypass Story!
Link: https://medium.com/p/f8f962f54c7d
Date: Wed, 14 Jul 2021 07:06:31 GMT
Title: RFD Vulnerability And Content-Disposition Header Bypass Story!
Link: https://medium.com/p/f8f962f54c7d
Medium
RFD Vulnerability And Content-Disposition Header Bypass Story!
Hey everyone! Hope everyone doing good.
New Writeup❗️
Date: Sat, 29 Aug 2020 08:24:45 GMT
Title: OAuth Phishing - 2020
Link: https://medium.com/p/9b2e1d00888d
Date: Sat, 29 Aug 2020 08:24:45 GMT
Title: OAuth Phishing - 2020
Link: https://medium.com/p/9b2e1d00888d
Medium
OAuth Phishing - 2020
Hello Everyone,
New Writeup❗️
Date: Wed, 31 Jul 2019 12:31:22 GMT
Title: Journey Of My First Bug Bounty.
Link: https://medium.com/p/72175d903ce3
Date: Wed, 31 Jul 2019 12:31:22 GMT
Title: Journey Of My First Bug Bounty.
Link: https://medium.com/p/72175d903ce3
Medium
Journey Of My First Bug Bounty.
Hello everyone,
New Writeup❗️
Date: Sat, 12 Jun 2021 18:47:22 GMT
Title: Story of Account Takeover : Using Social Login with Mass Assignment Vulnerability to hack accounts !
Link: https://medium.com/p/21e4d5856f5e
Date: Sat, 12 Jun 2021 18:47:22 GMT
Title: Story of Account Takeover : Using Social Login with Mass Assignment Vulnerability to hack accounts !
Link: https://medium.com/p/21e4d5856f5e
Medium
Story of Account Takeover : Using Social Login with Mass Assignment Vulnerability to hack accounts !
Hey everyone, this is Mohammad Kaif aka mkahmad an 18 year old Security Researcher & Bug Hunter from Varanasi, India.
New Writeup❗️
Date: Tue, 20 Dec 2022 15:58:54 GMT
Title: How I found my first XSS on a Bug Bounty Program
Link: https://medium.com/p/c41107617ce1
Date: Tue, 20 Dec 2022 15:58:54 GMT
Title: How I found my first XSS on a Bug Bounty Program
Link: https://medium.com/p/c41107617ce1
Medium
How I found my first XSS on a Bug Bounty Program
Hello there, Welcome back to my Article.
New Writeup❗️
Date: Tue, 20 Dec 2022 15:41:29 GMT
Title: How I got my SIDN Swag
Link: https://medium.com/p/3c95cef07883
Date: Tue, 20 Dec 2022 15:41:29 GMT
Title: How I got my SIDN Swag
Link: https://medium.com/p/3c95cef07883
Medium
How I got my SIDN Swag
Hello guys, how are you? I’m writing an article after a very long time.
New Writeup❗️
Date: Sun, 16 Jan 2022 10:45:58 GMT
Title: How i was able to see Sensitive Information on One of the India’s best School Website.
Link: https://medium.com/p/5800b5ab834c
Date: Sun, 16 Jan 2022 10:45:58 GMT
Title: How i was able to see Sensitive Information on One of the India’s best School Website.
Link: https://medium.com/p/5800b5ab834c
Medium
How i was able to see Sensitive Information on One of the India’s best School Website.
Hello Readers,
New Writeup❗️
Date: Tue, 11 May 2021 15:05:07 GMT
Title: TryHackMe : Basic Pentesting CTF
Link: https://medium.com/p/e510d9597881
Date: Tue, 11 May 2021 15:05:07 GMT
Title: TryHackMe : Basic Pentesting CTF
Link: https://medium.com/p/e510d9597881
Medium
TryHackMe : Basic Pentesting CTF
Nmap :
New Writeup❗️
Date: Fri, 22 Jan 2021 12:17:35 GMT
Title: $10,000 for automatic email confirmation bug in Microsoft’s Edge browser
Link: https://medium.com/p/22f15ceccb4a
Date: Fri, 22 Jan 2021 12:17:35 GMT
Title: $10,000 for automatic email confirmation bug in Microsoft’s Edge browser
Link: https://medium.com/p/22f15ceccb4a
Medium
$10,000 for automatic email confirmation bug in Microsoft’s Edge browser
Hey folks, welcome to my first bug bounty writeup, which I found on Microsoft Edge (Chromium) browser.
New Writeup❗️
Date: Thu, 03 Dec 2020 08:17:51 GMT
Title: Leaking Credit card Activity in logs? Yes Sir!
Link: https://medium.com/p/b988bb6c0c2
Date: Thu, 03 Dec 2020 08:17:51 GMT
Title: Leaking Credit card Activity in logs? Yes Sir!
Link: https://medium.com/p/b988bb6c0c2
Medium
Leaking Credit card Activity in logs? Yes Sir!
Hello again, This is the easiest bug you can find while testing an android application. When you report it, you’re gonna be the problem…
New Writeup❗️
Date: Sat, 21 Nov 2020 13:26:21 GMT
Title: Weird (im)possible XSS on error page
Link: https://medium.com/p/a0b943ead41
Date: Sat, 21 Nov 2020 13:26:21 GMT
Title: Weird (im)possible XSS on error page
Link: https://medium.com/p/a0b943ead41
Medium
Weird (im)possible XSS on error page
Hello all,
New Writeup❗️
Date: Mon, 09 Jan 2023 13:27:14 GMT
Title: Hacking Hackers for fun and profit
Link: https://medium.com/p/784e6c7897e8
Date: Mon, 09 Jan 2023 13:27:14 GMT
Title: Hacking Hackers for fun and profit
Link: https://medium.com/p/784e6c7897e8
Medium
Hacking Hackers for fun and profit
This story will be in several parts. In each of the situations, I had to face unexpected results. By and large, these are stories that have…
New Writeup❗️
Date: Fri, 19 Nov 2021 08:02:47 GMT
Title: How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Link: https://medium.com/p/d4ff8e7dbef1
Date: Fri, 19 Nov 2021 08:02:47 GMT
Title: How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Link: https://medium.com/p/d4ff8e7dbef1
Medium
How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Below you will learn in detail about the discovered vulnerability that allowed me to get about 15000$ in bounty with all secrets from the…
New Writeup❗️
Date: Tue, 13 Jul 2021 18:52:54 GMT
Title: Credential stuffing in Bug bounty hunting
Link: https://medium.com/p/7168dc1d3153
Date: Tue, 13 Jul 2021 18:52:54 GMT
Title: Credential stuffing in Bug bounty hunting
Link: https://medium.com/p/7168dc1d3153
Medium
Credential stuffing in Bug bounty hunting
Bug hunting is not always about looking for classic vulnerabilities (XSS, SQLi, SSRF, RCE, etc). Sometimes it is a search for a new problem…
New Writeup❗️
Date: Thu, 07 Jan 2021 09:33:09 GMT
Title: $10,000 for a vulnerability that doesn’t exist
Link: https://medium.com/p/9dbc63684e94
Date: Thu, 07 Jan 2021 09:33:09 GMT
Title: $10,000 for a vulnerability that doesn’t exist
Link: https://medium.com/p/9dbc63684e94
Medium
$10,000 for a vulnerability that doesn’t exist
A couple of months ago, an interesting story happened to me. I caught a Path Traversal issue with no chance to reproduce it again.
New Writeup❗️
Date: Wed, 03 Jun 2020 13:17:09 GMT
Title: From CRLF to Account Takeover
Link: https://medium.com/p/a94d7aa0d74e
Date: Wed, 03 Jun 2020 13:17:09 GMT
Title: From CRLF to Account Takeover
Link: https://medium.com/p/a94d7aa0d74e
Medium
From CRLF to Account Takeover
At the beginning of March,while researching one site I discovered the new functionality. The functionality allowed the user to login via…
New Writeup❗️
Date: Fri, 28 May 2021 23:28:53 GMT
Title: The beauty of chaining client-side bugs
Link: https://medium.com/p/759e1091eabf
Date: Fri, 28 May 2021 23:28:53 GMT
Title: The beauty of chaining client-side bugs
Link: https://medium.com/p/759e1091eabf
Medium
The beauty of chaining client-side bugs
This is part of a report of a bug that I sent back in 2020, changing of course the program name for obvious reasons.