New Writeup❗️
Date: Tue, 09 Feb 2021 17:59:56 GMT
Title: Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
Link: https://medium.com/p/4a5d60fec610
Date: Tue, 09 Feb 2021 17:59:56 GMT
Title: Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
Link: https://medium.com/p/4a5d60fec610
Medium
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
The Story of a Novel Supply Chain Attack
New Writeup❗️
Date: Wed, 08 Jan 2020 16:05:16 GMT
Title: The Bug That Exposed Your PayPal Password
Link: https://medium.com/p/539fc2896da9
Date: Wed, 08 Jan 2020 16:05:16 GMT
Title: The Bug That Exposed Your PayPal Password
Link: https://medium.com/p/539fc2896da9
Medium
The Bug That Exposed Your PayPal Password
And Credit Card Number Too
New Writeup❗️
Date: Mon, 30 Oct 2017 15:00:09 GMT
Title: How I hacked Google’s bug tracking system itself for $15,600 in bounties
Link: https://medium.com/p/58f86cc9f9a5
Date: Mon, 30 Oct 2017 15:00:09 GMT
Title: How I hacked Google’s bug tracking system itself for $15,600 in bounties
Link: https://medium.com/p/58f86cc9f9a5
Medium
How I hacked Google’s bug tracking system itself for $15,600 in bounties
Easy Bugs for Hard Cash
New Writeup❗️
Date: Wed, 14 Dec 2022 21:10:13 GMT
Title: Unprotected API endpoint at HAwebsso.nl
Link: https://medium.com/p/5f1951e212fe
Date: Wed, 14 Dec 2022 21:10:13 GMT
Title: Unprotected API endpoint at HAwebsso.nl
Link: https://medium.com/p/5f1951e212fe
Medium
Unprotected API endpoint at HAwebsso.nl
Background
As some might know, I work as a medical doctor (general practitioner) by day and as a security researcher by night. One of my…
As some might know, I work as a medical doctor (general practitioner) by day and as a security researcher by night. One of my…
New Writeup❗️
Date: Thu, 06 Aug 2020 12:44:49 GMT
Title: Blind SQL Injection at fasteditor.hema.com
Link: https://medium.com/p/6ac140c0d1a3
Date: Thu, 06 Aug 2020 12:44:49 GMT
Title: Blind SQL Injection at fasteditor.hema.com
Link: https://medium.com/p/6ac140c0d1a3
Medium
Blind SQL Injection at fasteditor.hema.com
A full write-up that explains the discovery and exploitation of a blind SQL injection bug.
🗿1
New Writeup❗️
Date: Thu, 06 Aug 2020 12:21:53 GMT
Title: Reflected XSS at fotoservice.hema.nl
Link: https://medium.com/p/af344ef63433
Date: Thu, 06 Aug 2020 12:21:53 GMT
Title: Reflected XSS at fotoservice.hema.nl
Link: https://medium.com/p/af344ef63433
Medium
Reflected XSS at fotoservice.hema.nl
A full write-up that learns the reader how to find reflected XSS and open redirect bugs. Hema.nl was used as an real life example.
New Writeup❗️
Date: Tue, 12 May 2020 09:20:53 GMT
Title: Stored XSS in Paytium 3.0.13 WordPress Plugin
Link: https://medium.com/p/3157ee37eb8f
Date: Tue, 12 May 2020 09:20:53 GMT
Title: Stored XSS in Paytium 3.0.13 WordPress Plugin
Link: https://medium.com/p/3157ee37eb8f
Medium
Stored XSS in Paytium 3.0.13 WordPress Plugin
A full write up: How to find a stored XSS bug in a Wordpress plugin and create a proof of concept payload that hijacks the full…
New Writeup❗️
Date: Sat, 06 Apr 2019 12:40:26 GMT
Title: Email content spoofing at IKEA.com
Link: https://medium.com/p/ea76c17605ee
Date: Sat, 06 Apr 2019 12:40:26 GMT
Title: Email content spoofing at IKEA.com
Link: https://medium.com/p/ea76c17605ee
Medium
Email content spoofing at IKEA.com
IKEA.com did not check the fields being used in one of their email forms. This resulted in the creation of fully signed phishing email.
New Writeup❗️
Date: Thu, 04 Apr 2019 09:46:04 GMT
Title: Leaked Salesforce API access token at IKEA.com
Link: https://medium.com/p/132eea3844e0
Date: Thu, 04 Apr 2019 09:46:04 GMT
Title: Leaked Salesforce API access token at IKEA.com
Link: https://medium.com/p/132eea3844e0
Medium
Leaked Salesforce API access token at IKEA.com
A leaked Salesforce API key leads to a potential data leak at IKEA.com. A step by step write-up how this bug was found.
New Writeup❗️
Date: Sun, 07 Oct 2018 10:29:32 GMT
Title: Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
Link: https://medium.com/p/db6188acedd9
Date: Sun, 07 Oct 2018 10:29:32 GMT
Title: Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
Link: https://medium.com/p/db6188acedd9
Medium
Persistent XSS (unvalidated Open Graph embed) at LinkedIn.com
A full write-up how we created a phishing login on LinkedIn.com by manipulating Open Graph Tags used by their blogging platform.
New Writeup❗️
Date: Wed, 02 Nov 2022 12:31:20 GMT
Title: How I Get 5x Swag From Sony
Link: https://medium.com/p/102dbefd0c2c
Date: Wed, 02 Nov 2022 12:31:20 GMT
Title: How I Get 5x Swag From Sony
Link: https://medium.com/p/102dbefd0c2c
Medium
How I Get 5x Swag From Sony
Assalamu Alaikum
I am Naeem Ahmed Sayed.
This is my 2nd bug hunting writeup. I started to bug bounty on January 2020. I want to share with…
I am Naeem Ahmed Sayed.
This is my 2nd bug hunting writeup. I started to bug bounty on January 2020. I want to share with…
New Writeup❗️
Date: Thu, 30 Sep 2021 19:42:31 GMT
Title: How I get my first p1 bug from Bugcrowd vdp program With my Phone
Link: https://medium.com/p/e1eb1444146c
Date: Thu, 30 Sep 2021 19:42:31 GMT
Title: How I get my first p1 bug from Bugcrowd vdp program With my Phone
Link: https://medium.com/p/e1eb1444146c
Medium
How I get my first p1 bug from Bugcrowd vdp program With my Phone
Assalamu Alaikum I am Naeem Ahmed Sayed. This is my first bug bounty writeup. I started to bug bounty on January 2020. I want to share with…
New Writeup❗️
Date: Fri, 16 Dec 2022 07:48:48 GMT
Title: Param Hunting to Injections
Link: https://medium.com/p/4365da5447cf
Date: Fri, 16 Dec 2022 07:48:48 GMT
Title: Param Hunting to Injections
Link: https://medium.com/p/4365da5447cf
Medium
Param Hunting to Injections
Hey hackers! How’s your week going?
New Writeup❗️
Date: Wed, 16 Nov 2022 18:57:59 GMT
Title: Frida & Objection without Jailbreak!
Link: https://medium.com/p/27a66501bf38
Date: Wed, 16 Nov 2022 18:57:59 GMT
Title: Frida & Objection without Jailbreak!
Link: https://medium.com/p/27a66501bf38
Medium
Frida & Objection without Jailbreak! 🔥🔥
So are you the one who stops security testing if Jailbreak Detection is not bypassed?? No worries, we have got you covered! A method to…
New Writeup❗️
Date: Tue, 08 Nov 2022 18:22:17 GMT
Title: Cool Recon techniques every hacker misses! Episode 3
Link: https://medium.com/p/3812e7da3425
Date: Tue, 08 Nov 2022 18:22:17 GMT
Title: Cool Recon techniques every hacker misses! Episode 3
Link: https://medium.com/p/3812e7da3425
Medium
Cool Recon techniques every hacker misses! Episode 3🔥🔥
Welcome to the 3rd Episode of Cool Recon Techniques. We are back with some more cool recon techniques which we think hackers out there…
New Writeup❗️
Date: Sun, 30 Oct 2022 10:31:40 GMT
Title: Android Pentesting 101 — Part 3
Link: https://medium.com/p/2bf846b05594
Date: Sun, 30 Oct 2022 10:31:40 GMT
Title: Android Pentesting 101 — Part 3
Link: https://medium.com/p/2bf846b05594
Medium
Android Pentesting 101 — Part 3
Welcome to Part 3 of Android Pentesting. This series is about how you can hack into Android and find vulnerabilities in it using various…
New Writeup❗️
Date: Tue, 25 Oct 2022 06:27:36 GMT
Title: Android Pentesting 101 — Part 2
Link: https://medium.com/p/419facdf11c1
Date: Tue, 25 Oct 2022 06:27:36 GMT
Title: Android Pentesting 101 — Part 2
Link: https://medium.com/p/419facdf11c1
Medium
Android Pentesting 101 — Part 2
Welcome to Part 2 of Android Pentesting. This series is about how you can hack into Android and find vulnerabilities in it using various…
New Writeup❗️
Date: Sat, 22 Oct 2022 08:57:35 GMT
Title: Android Pentesting 101 — Part 1
Link: https://medium.com/p/8e31b8cd8b2b
Date: Sat, 22 Oct 2022 08:57:35 GMT
Title: Android Pentesting 101 — Part 1
Link: https://medium.com/p/8e31b8cd8b2b
Medium
Android Pentesting 101 — Part 1
Welcome to this new series of Android Pentesting. This series is about how you can hack into Android and find vulnerabilities in it using…
New Writeup❗️
Date: Tue, 04 Oct 2022 09:23:02 GMT
Title: Bugcrowd — Tale of multiple misconfigurations!! ❌
Link: https://medium.com/p/cb5b98f09302
Date: Tue, 04 Oct 2022 09:23:02 GMT
Title: Bugcrowd — Tale of multiple misconfigurations!! ❌
Link: https://medium.com/p/cb5b98f09302
Medium
Bugcrowd — Tale of multiple misconfigurations!! ❌
Welcome to this new article. This article is a story about misconfigurations found on a domain. Since it is a private program let’s call…
New Writeup❗️
Date: Sun, 18 Sep 2022 17:00:04 GMT
Title: Cool Recon techniques every hacker misses! Episode 2
Link: https://medium.com/p/8024e8338756
Date: Sun, 18 Sep 2022 17:00:04 GMT
Title: Cool Recon techniques every hacker misses! Episode 2
Link: https://medium.com/p/8024e8338756
Medium
Cool Recon techniques every hacker misses! Episode 2🔥🔥
Welcome to the 2nd Episode of Cool Recon Techniques. We are back with some more cool recon techniques which we think hackers out there…
New Writeup❗️
Date: Wed, 31 Aug 2022 16:03:22 GMT
Title: Mass Hunting CVE’s Part-1
Link: https://medium.com/p/1e162ba6028b
Date: Wed, 31 Aug 2022 16:03:22 GMT
Title: Mass Hunting CVE’s Part-1
Link: https://medium.com/p/1e162ba6028b
Medium
Mass Hunting CVE’s Part-1👀🔥
CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws. A CVE number uniquely…