Daily Writeups
3.55K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
๐Ÿ”–New Writeupโ—๏ธ
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
๐Ÿ—“Date: Tue, 07 Mar 2023 08:12:20 GMT
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
โœ๏ธTitle: Donโ€™t Send a Message to anyone Before Reading This: Account Takeover Vulnerability [External Audit]
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
๐Ÿ“ŽLink: https://medium.com/p/cf584a0c983c
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
Tags: #bug_bounty #penetration_testing #response_manipulation #account_takeover #authentication_bypass
๐Ÿ”–New Writeupโ—๏ธ
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
๐Ÿ—“Date: Fri, 29 Sep 2023 14:57:03 GMT
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
โœ๏ธTitle: Response Manipulation to Account Takeover
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
๐Ÿ“ŽLink: https://medium.com/p/f5a1dfe1d878
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #response_manipulation
โคท Title: Authentication Bypass via Response Manipulation
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Ahmed Salah
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Wed, 08 Jan 2025 23:35:03 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #typescript #response_manipulation #programming #authentication_bypass #cybersecurity
โคท Title: 2FA Bypass via Response manipulation
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: 0mex
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Fri, 17 Jan 2025 16:32:08 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #2fa_bypass #2fa_authentication #otp_bypass #bug_bounty_writeup #response_manipulation
โคท Title: Waiting for admin approve , I donโ€™t think so !
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Abdallah Ehab
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Sat, 26 Apr 2025 14:50:39 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #ethical_hacking #hunting #bug_bounty #response_manipulation
โคท Title: Waiting for admin approve , I donโ€™t think so !
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Abdallah Ehab
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Sat, 26 Apr 2025 14:50:39 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #ethical_hacking #hunting #bug_bounty #response_manipulation
โคท Title: Waiting for admin approve , I donโ€™t think so !
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Abdallah Ehab
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Sat, 26 Apr 2025 14:50:39 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #ethical_hacking #hunting #bug_bounty #response_manipulation
โคท Title: Privilege Escalation via Response Manipulation
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: MR SHAN
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Fri, 16 May 2025 18:59:37 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #bug_bounty_tips #response_manipulation #burpsuite #cybersecurity #bug_bounty
โคท Title: Access Bank Account Information via Response Manipulation
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: brbr0s
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Wed, 30 Jul 2025 14:16:54 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #bug_bounty_tips #bug_bounty_writeup #broken_access_control #response_manipulation #bug_bounty
โคท Title: Access Bank Account Information via Response Manipulation
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: brbr0s
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Thu, 07 Aug 2025 15:35:30 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #bug_bounty #bug_bounty_tips #bug_bounty_writeup #broken_access_control #response_manipulation
โคท Title: โ€œTrust, but Verify: The Hidden Dangers of Response Manipulation in Modern Applicationsโ€
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Abdullah Kala
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Mon, 29 Sep 2025 10:57:50 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #mobile_security #penetration_testing #application_security #business_logic #response_manipulation
โคท Title: โ€œTrust, but Verify: The Hidden Dangers of Response Manipulationโ€
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Abdullah Kala
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Mon, 29 Sep 2025 10:57:50 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #mobile_security #penetration_testing #application_security #business_logic #response_manipulation
โคท Title: How a Single Response Manipulation Led to Admin Takeoverโ€Šโ€”โ€ŠTamil Nadu Governmentโ€Šโ€”โ€ŠPoliceโ€ฆ
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Gokuleswaran B
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Sat, 01 Nov 2025 15:49:29 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #bug_bounty #response_manipulation #bug_bounty_tips #pentesting #appsec
โคท Title: Donโ€™t Trust the Response : How Response Manipulation Exposed a Business Logic Flaw
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Killua199
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Sat, 15 Nov 2025 10:56:06 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #penetration_testing #bug_bounty #owasp #response_manipulation #cybersecurity
โคท Title: Http Response Manipulation
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Neeraj kath
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Fri, 09 Jan 2026 09:53:53 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #penetration_testing #web_security #bug_bounty #response_manipulation #owasp
โคท Title: How a Simple Misconfiguration in the Invitation Link Led Me to Full Account Takeover
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: sudo
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Thu, 15 Jan 2026 17:08:19 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #response_manipulation #account_takeover #broken_access_control #auth_bypass #bug_bounty
โคท Title: Response Manipulation Leading to Free Plan Limit Bypass
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Mahmoud Gamal
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Wed, 25 Feb 2026 04:47:49 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #business_logic #writeup #bug_bounty #cybersecurity #response_manipulation
โคท Title: I tried to log into the website using the Client-Side Access Control bypassing technique.
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
๐€ช Author: Billy Elvonda Aron Umpel
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โดต Time: Wed, 25 Feb 2026 03:12:07 GMT
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
โŒ— Tags: #web_exploitation #hacking #response_manipulation