⤷ Title: Server-Side Request Forgery (SSRF): From Ping to RCE
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 10:07:27 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #bug_bounty #bugbounty_tips #hacking
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 10:07:27 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #bug_bounty #bugbounty_tips #hacking
Medium
Server-Side Request Forgery (SSRF): From Ping to RCE
Why I'm Writing This
⤷ Title: Exploiting Logic Flaw to Bypass Payment Using Fractional Quantities
════════════════════════
𐀪 Author: Hamzadzworm
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 14:31:09 GMT
════════════════════════
⌗ Tags: #infosec #bugbounty_tips #bug_bounty_writeup #information_security #infosec_write_ups
════════════════════════
𐀪 Author: Hamzadzworm
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 14:31:09 GMT
════════════════════════
⌗ Tags: #infosec #bugbounty_tips #bug_bounty_writeup #information_security #infosec_write_ups
Medium
Exploiting Logic Flaw to Bypass Payment Using Fractional Quantities
Hi, My name is Abdelkader Mouaz and also know as Hamzadzworm
⤷ Title: How I Hunt for Swagger UI on Real Targets (A Practical Guide for Bug Bounty Hunters)
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 14:41:41 GMT
════════════════════════
⌗ Tags: #swagger_ui #bugbounty_tips #bugbounty_writeup #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 14:41:41 GMT
════════════════════════
⌗ Tags: #swagger_ui #bugbounty_tips #bugbounty_writeup #cybersecurity #bug_bounty
Medium
🔍 How I Hunt for Swagger UI on Real Targets (A Practical Guide for Bug Bounty Hunters)
Yesterday, we talked about what Swagger UI is — that clean little interface that shows all the API endpoints and lets you hit “Try it out”…
⤷ Title: The Danger of Simplicity: How a Default Credential Led to Full Account Access
════════════════════════
𐀪 Author: Samet Yiğit
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 17:46:19 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #ödülavcılığı #bug_bounty #bugbounty_tips
════════════════════════
𐀪 Author: Samet Yiğit
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 17:46:19 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #ödülavcılığı #bug_bounty #bugbounty_tips
Medium
The Danger of Simplicity: How a Default Credential Led to Full Account Access
In the world of bug bounty, we often get distracted by complex blind SSRFs or intricate race conditions. However, sometimes the most…
⤷ Title: Cybersecurity Roadmap (Beginner → Pro)
════════════════════════
𐀪 Author: Mr. Lucifer
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 07:41:26 GMT
════════════════════════
⌗ Tags: #bugbounty_tips #it_security #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Mr. Lucifer
════════════════════════
ⴵ Time: Thu, 01 Jan 2026 07:41:26 GMT
════════════════════════
⌗ Tags: #bugbounty_tips #it_security #bug_bounty #cybersecurity
Medium
🚀 Cybersecurity Roadmap (Beginner to Pro)
This roadmap is for students, beginners, and self-learners who want to enter cybersecurity without confusion and build real skills, not…
⤷ Title: IDOR Vulnerability in Dictionary Endpoint — Arbitrary Deletion of User Items (€€€)
════════════════════════
𐀪 Author: Hasan Khan
════════════════════════
ⴵ Time: Sat, 31 Jan 2026 12:56:51 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_hunting #bug_bounty_writeup #api_pentesting #bugbounty_tips
════════════════════════
𐀪 Author: Hasan Khan
════════════════════════
ⴵ Time: Sat, 31 Jan 2026 12:56:51 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_hunting #bug_bounty_writeup #api_pentesting #bugbounty_tips
Medium
IDOR Vulnerability in Dictionary Endpoint — Arbitrary Deletion of User Items (€€€)
IDOR Vulnerability in Dictionary Endpoint — Arbitrary Deletion of User Items (€€€) Author: Hasan_Khan0x Reward: €€€ Program: Responsible Disclosure Bug Bounty Checklist Used …
⤷ Title: When length - 32 Goes Negative: A Small Check, Real Memory Bug in wolfSSL
════════════════════════
𐀪 Author: MostReal
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 16:39:25 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #hacking #coding #bugbounty_tips
════════════════════════
𐀪 Author: MostReal
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 16:39:25 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #hacking #coding #bugbounty_tips
Medium
When length - 32 Goes Negative: A Small Check, Real Memory Bug in wolfSSL
While looking at the TLS 1.3 session ticket handling in wolfSSL, I found a small boundary issue inside SetTicket() in src/internal.c. At first glance, it looks harmless. Just some pointer math and a length check. But the details matter. The code builds a…
⤷ Title: Intigriti XSS Challenge (InkDrop) Write-up — Stored XSS via Preview + JSONP Callback
════════════════════════
𐀪 Author: Java Coder
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 13:54:31 GMT
════════════════════════
⌗ Tags: #intigriti #bugbounty_writeup #bugbounty_tips #pentesting #web_security
════════════════════════
𐀪 Author: Java Coder
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 13:54:31 GMT
════════════════════════
⌗ Tags: #intigriti #bugbounty_writeup #bugbounty_tips #pentesting #web_security
Medium
Intigriti XSS Challenge (InkDrop) Write-up — Stored XSS via Preview + JSONP Callback
CTF solve report: Stored XSS by chaining unsanitized markdown rendering, preview script re-injection, and JSONP callback reflection
⤷ Title: When a Composite Checkout Keeps Pricing From a State That No Longer Exists
════════════════════════
𐀪 Author: sin99xx
════════════════════════
ⴵ Time: Sun, 15 Mar 2026 17:21:51 GMT
════════════════════════
⌗ Tags: #ethical_hacking #security #cybersecurity #bugbounty_tips #bug_bounty
════════════════════════
𐀪 Author: sin99xx
════════════════════════
ⴵ Time: Sun, 15 Mar 2026 17:21:51 GMT
════════════════════════
⌗ Tags: #ethical_hacking #security #cybersecurity #bugbounty_tips #bug_bounty
Medium
When a Composite Checkout Keeps Pricing From a State That No Longer Exists
Most payment bugs people look for are obvious: changing a price, reusing a discount, forcing a negative total, or finding a race condition.
⤷ Title: [Technical Analysis] Critical Business Logic Flaw Chain Leading to Account Takeover (ATO) via OAUTH…
════════════════════════
𐀪 Author: Tthanhkhoa
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 12:21:08 GMT
════════════════════════
⌗ Tags: #account_takover #bugbounty_tips #api_security
════════════════════════
𐀪 Author: Tthanhkhoa
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 12:21:08 GMT
════════════════════════
⌗ Tags: #account_takover #bugbounty_tips #api_security
Medium
[Technical Analysis] Critical Business Logic Flaw Chain Leading to Account Takeover (ATO) via OAUTH and Email Change Flow
Short Description: An attacker can take over any account ([email protected]) solely under the condition that the victim has NOT yet…
❤1