New Writeup❗️
Date: Thu, 10 Dec 2020 14:55:01 GMT
Title: How I dumped PII information of customers in an ecommerce site?
Link: https://medium.com/p/237761f813cf
Date: Thu, 10 Dec 2020 14:55:01 GMT
Title: How I dumped PII information of customers in an ecommerce site?
Link: https://medium.com/p/237761f813cf
Medium
How I dumped PII information of customers in an ecommerce site?
Like every website, the most interesting endpoint is always the image upload section.
So I fired my burp and was checking how the images…
So I fired my burp and was checking how the images…
New Writeup❗️
Date: Wed, 05 Aug 2020 12:23:09 GMT
Title: How I was able to do Mass Account Takeover[Bug Bounty]
Link: https://medium.com/p/b279af1ce62b
Date: Wed, 05 Aug 2020 12:23:09 GMT
Title: How I was able to do Mass Account Takeover[Bug Bounty]
Link: https://medium.com/p/b279af1ce62b
Medium
How I was able to do Mass Account Takeover[Bug Bounty]
This was one of the interesting bug that i found on a target.
New Writeup❗️
Date: Tue, 06 Jul 2021 12:01:32 GMT
Title: Exploiting Auto-save Functionality To Steal Login Credentials
Link: https://medium.com/p/bf4c7e1594da
Date: Tue, 06 Jul 2021 12:01:32 GMT
Title: Exploiting Auto-save Functionality To Steal Login Credentials
Link: https://medium.com/p/bf4c7e1594da
Medium
Exploiting Auto-save Functionality To Steal Login Credentials
Hi Folks! hope you all doing well it’s being a long time since I do a write-up, so this write-up is all about my tweet Exploiting/Chaining…
New Writeup❗️
Date: Wed, 14 Oct 2020 10:29:13 GMT
Title: Weaponizing XSS For Fun & Profit
Link: https://medium.com/p/a1414f3fcee9
Date: Wed, 14 Oct 2020 10:29:13 GMT
Title: Weaponizing XSS For Fun & Profit
Link: https://medium.com/p/a1414f3fcee9
Medium
Weaponizing XSS For Fun & Profit
Hi Folks! hope you all doing good so I am back with another amazing way of bypassing the WAF which is blocking me from weaponizing the XSS…
New Writeup❗️
Date: Thu, 01 Aug 2019 07:01:05 GMT
Title: Bypassing CORS
Link: https://medium.com/p/13e46987a45b
Date: Thu, 01 Aug 2019 07:01:05 GMT
Title: Bypassing CORS
Link: https://medium.com/p/13e46987a45b
Medium
Bypassing CORS
Hello friends this write-up is about who I bypass the CORS validation. Let assume the website name redact.com simple I login to website…
New Writeup❗️
Date: Tue, 16 Jul 2019 07:16:49 GMT
Title: Bypass CSRF With ClickJacking Worth $1250
Link: https://medium.com/p/6c70cc263f40
Date: Tue, 16 Jul 2019 07:16:49 GMT
Title: Bypass CSRF With ClickJacking Worth $1250
Link: https://medium.com/p/6c70cc263f40
Medium
Bypass CSRF With ClickJacking Worth $1250
Hello friends, I hope you all are doing well, so this write up is all about how I chain the to different vulnerabilities to update the…
New Writeup❗️
Date: Mon, 01 Jul 2019 08:12:50 GMT
Title: Accidental IDOR
Link: https://medium.com/p/8987a2728d4
Date: Mon, 01 Jul 2019 08:12:50 GMT
Title: Accidental IDOR
Link: https://medium.com/p/8987a2728d4
Medium
Accidental IDOR
Hi guys I hope you all are doing good so this write-up is all about the accidental IDOR that I found in the PRIVATE program so let assume…
New Writeup❗️
Date: Thu, 20 Jun 2019 20:11:08 GMT
Title: Self XSS To Evil XSS
Link: https://medium.com/p/bcf2494a82a4
Date: Thu, 20 Jun 2019 20:11:08 GMT
Title: Self XSS To Evil XSS
Link: https://medium.com/p/bcf2494a82a4
Medium
Self XSS To Evil XSS
Hi guy I hope you all are fine this POC is all about how I convert the Self XSS To Evil XSS so let assume the site PRIVATE.COM
New Writeup❗️
Date: Mon, 17 Jun 2019 18:19:51 GMT
Title: SQl Injection
Link: https://medium.com/p/c87a390afdd3
Date: Mon, 17 Jun 2019 18:19:51 GMT
Title: SQl Injection
Link: https://medium.com/p/c87a390afdd3
Medium
SQl Injection
Hy Guy’s this write up is all about my SQL Injection that I found in PRIVATE program running on BugCrowd
🗿1
New Writeup❗️
Date: Sun, 16 Jun 2019 19:42:56 GMT
Title: Account Takeover Worth $900
Link: https://medium.com/p/cacbe10de58e
Date: Sun, 16 Jun 2019 19:42:56 GMT
Title: Account Takeover Worth $900
Link: https://medium.com/p/cacbe10de58e
Medium
Account Takeover Worth $900
Hello guy’s I am back with another POC again this bug I found in PRIVATE program using on bugcrowd so without wasting the time let get…
New Writeup❗️
Date: Sat, 15 Jun 2019 20:15:01 GMT
Title: Complete Web Server Access
Link: https://medium.com/p/46d19279a2b
Date: Sat, 15 Jun 2019 20:15:01 GMT
Title: Complete Web Server Access
Link: https://medium.com/p/46d19279a2b
Medium
Complete Web Server Access
Hi guy I am back with another POC that I found in PRIVATE program on bugcrowd let get started. So let assume the SITE name private.com I…
New Writeup❗️
Date: Fri, 14 Jun 2019 09:59:56 GMT
Title: IDOR — Account Takeover
Link: https://medium.com/p/1ff5a2d03b8b
Date: Fri, 14 Jun 2019 09:59:56 GMT
Title: IDOR — Account Takeover
Link: https://medium.com/p/1ff5a2d03b8b
Medium
IDOR — Account Takeover
Hi Guy,
New Writeup❗️
Date: Mon, 14 Nov 2022 12:47:34 GMT
Title: XSS using a username
Link: https://medium.com/p/8a8ab1b79a77
Date: Mon, 14 Nov 2022 12:47:34 GMT
Title: XSS using a username
Link: https://medium.com/p/8a8ab1b79a77
Medium
XSS using a username
XSS triggered by exploiting a vulnerable input field of a signup page.
New Writeup❗️
Date: Sat, 24 Sep 2022 07:19:26 GMT
Title: Escalating SSTI to Reflected XSS using curly braces { }
Link: https://medium.com/p/825685bd93ec
Date: Sat, 24 Sep 2022 07:19:26 GMT
Title: Escalating SSTI to Reflected XSS using curly braces { }
Link: https://medium.com/p/825685bd93ec
Medium
SSTI to XSS using curly braces {}
SSTI -> Self XSS -> RXSS
New Writeup❗️
Date: Sun, 28 Aug 2022 15:03:59 GMT
Title: Unsubscribe any user’s e-mail notifications via IDOR
Link: https://medium.com/p/2c2e05b79dac
Date: Sun, 28 Aug 2022 15:03:59 GMT
Title: Unsubscribe any user’s e-mail notifications via IDOR
Link: https://medium.com/p/2c2e05b79dac
Medium
Unsubscribe any user’s e-mail notifications via IDOR
IDOR allows attacker to unsubscribe any user from the Websites email service.
New Writeup❗️
Date: Mon, 15 Aug 2022 00:31:08 GMT
Title: Business Logic Vulnerability via IDOR
Link: https://medium.com/p/6d510f1caea9
Date: Mon, 15 Aug 2022 00:31:08 GMT
Title: Business Logic Vulnerability via IDOR
Link: https://medium.com/p/6d510f1caea9
Medium
Business Logic Vulnerability via IDOR
Exploiting a Logic Vuln via IDOR. #Bugbounty
New Writeup❗️
Date: Sat, 13 Aug 2022 12:01:07 GMT
Title: Escalating Open Redirect to XSS
Link: https://medium.com/p/d2b9355e5f05
Date: Sat, 13 Aug 2022 12:01:07 GMT
Title: Escalating Open Redirect to XSS
Link: https://medium.com/p/d2b9355e5f05
Medium
Escalating Open Redirect to XSS
Hello everyone. Myself Sagar Sajeev.
New Writeup❗️
Date: Sat, 13 Aug 2022 05:32:56 GMT
Title: An Unusual Tale of Email Verification Bypass
Link: https://medium.com/p/dcf884d544eb
Date: Sat, 13 Aug 2022 05:32:56 GMT
Title: An Unusual Tale of Email Verification Bypass
Link: https://medium.com/p/dcf884d544eb
Medium
An Unusual Tale of Email Verification Bypass
Hey Guys. I’m Sagar Sajeev .
New Writeup❗️
Date: Fri, 12 Aug 2022 09:39:20 GMT
Title: File Upload Bypass to RCE == $$$$
Link: https://medium.com/p/76991b47ad8f
Date: Fri, 12 Aug 2022 09:39:20 GMT
Title: File Upload Bypass to RCE == $$$$
Link: https://medium.com/p/76991b47ad8f
Medium
File Upload Bypass to RCE == $$$$
Multiple ways to Bypass a File upload feature and chain it to an RCE.
New Writeup❗️
Date: Fri, 12 Aug 2022 05:40:21 GMT
Title: Browser Extensions which have landed $$$ !
Link: https://medium.com/p/28ea451d531c
Date: Fri, 12 Aug 2022 05:40:21 GMT
Title: Browser Extensions which have landed $$$ !
Link: https://medium.com/p/28ea451d531c
Medium
Browser Extensions which have landed $$$ !
What’s up everybody. My name is Sagar Sajeev.
New Writeup❗️
Date: Thu, 04 Aug 2022 21:35:52 GMT
Title: Server Side Template Injection-Something Distinct!
Link: https://medium.com/p/f0ac234e379
Date: Thu, 04 Aug 2022 21:35:52 GMT
Title: Server Side Template Injection-Something Distinct!
Link: https://medium.com/p/f0ac234e379
Medium
Server Side Template Injection-Something Distinct!
How’s it going guys! My name is Sagar Sajeev and this is my writeup about one of my recent SSTI (Server Side Template Injection) finding.