New Writeup❗️
Date: Sat, 04 Sep 2021 12:08:16 GMT
Title: How i hacked BBC mail servers
Link: https://medium.com/p/e61bb6faed2d
Date: Sat, 04 Sep 2021 12:08:16 GMT
Title: How i hacked BBC mail servers
Link: https://medium.com/p/e61bb6faed2d
Medium
How i hacked BBC mail servers
Walk-through in hacking BBC mail servers through chained vulnerability
New Writeup❗️
Date: Sun, 27 Dec 2020 00:31:03 GMT
Title: Cyber Talents New Year CTF — Note Checker SQLi Challenge
Link: https://medium.com/p/7427328a455
Date: Sun, 27 Dec 2020 00:31:03 GMT
Title: Cyber Talents New Year CTF — Note Checker SQLi Challenge
Link: https://medium.com/p/7427328a455
Medium
Cyber Talents New Year CTF — Note Checker SQLi Challenge
Hey Hunters !!, This cyber talents ctf was very crazy and excited specially this challenge -Note Checker- it was semi-hard but also very…
New Writeup❗️
Date: Sun, 15 Nov 2020 21:33:28 GMT
Title: RCE via Server-Side Template Injection
Link: https://medium.com/p/ad46f8e0c2ae
Date: Sun, 15 Nov 2020 21:33:28 GMT
Title: RCE via Server-Side Template Injection
Link: https://medium.com/p/ad46f8e0c2ae
Medium
RCE via Server-Side Template Injection
In this write-up, we’ll see how I identified a remote code execution vulnerability and bypassed the Akamai WAF rule(s). While I was doing…
New Writeup❗️
Date: Tue, 10 Nov 2020 05:29:18 GMT
Title: BugPoC XSS Challenge- Wacky
Link: https://medium.com/p/e64255b543f2
Date: Tue, 10 Nov 2020 05:29:18 GMT
Title: BugPoC XSS Challenge- Wacky
Link: https://medium.com/p/e64255b543f2
Medium
BugPoC XSS Challenge- Wacky
Introduction
New Writeup❗️
Date: Sat, 29 Jan 2022 09:52:24 GMT
Title: Eliminating Authorization Vulnerabilities with Dacquiri
Link: https://medium.com/p/882b38146f36
Date: Sat, 29 Jan 2022 09:52:24 GMT
Title: Eliminating Authorization Vulnerabilities with Dacquiri
Link: https://medium.com/p/882b38146f36
Medium
Eliminating Authorization Vulnerabilities with Dacquiri
Dacquiri identifies and eliminates authorization vulnerabilities by turning them into compiler errors.
New Writeup❗️
Date: Tue, 22 Mar 2022 01:48:29 GMT
Title: Story about more than 3.5 million PII leakage in Yahoo!!! (Using an IOS) Bug worth $9,500
Link: https://medium.com/p/3a530210dcc6
Date: Tue, 22 Mar 2022 01:48:29 GMT
Title: Story about more than 3.5 million PII leakage in Yahoo!!! (Using an IOS) Bug worth $9,500
Link: https://medium.com/p/3a530210dcc6
Medium
Story about more than 3.5 million PII leakage in Yahoo!!! (Using an IOS) Bug worth $9,500
Hello GUYS,
New Writeup❗️
Date: Wed, 27 Apr 2022 16:29:14 GMT
Title: Bypassing WAF for $2222
Link: https://medium.com/p/f99b80cfdb9b
Date: Wed, 27 Apr 2022 16:29:14 GMT
Title: Bypassing WAF for $2222
Link: https://medium.com/p/f99b80cfdb9b
Medium
LFI On the Documentation Page
I know it’s been a very long time since I last published my article on how I was able to find RCE on Bentley systems. For the last 1–1.5…
New Writeup❗️
Date: Sun, 21 Jun 2020 11:54:17 GMT
Title: It took me only 5 minutes to find an RCE on Bentley
Link: https://medium.com/p/38265da15788
Date: Sun, 21 Jun 2020 11:54:17 GMT
Title: It took me only 5 minutes to find an RCE on Bentley
Link: https://medium.com/p/38265da15788
Medium
It took me only 5 minutes to find an RCE on Bentley
Hi Guys,
New Writeup❗️
Date: Wed, 24 Aug 2022 23:02:13 GMT
Title: Chaining Telegram bugs to steal session-related files.
Link: https://medium.com/p/c90eac4749bd
Date: Wed, 24 Aug 2022 23:02:13 GMT
Title: Chaining Telegram bugs to steal session-related files.
Link: https://medium.com/p/c90eac4749bd
Medium
Chaining Telegram bugs to steal session-related files.
We will discuss the chaining of two bugs on the telegram android application, which can make malicious applications steal internal telegram…
New Writeup❗️
Date: Mon, 18 Oct 2021 23:31:52 GMT
Title: Exploiting Request forgery on Mobile Applications.
Link: https://medium.com/p/e1d196d187b3
Date: Mon, 18 Oct 2021 23:31:52 GMT
Title: Exploiting Request forgery on Mobile Applications.
Link: https://medium.com/p/e1d196d187b3
Medium
Exploiting Request forgery on Mobile Applications.
We will tell a story about the Request forgery family and how it can attack mobile applications.
New Writeup❗️
Date: Thu, 18 Mar 2021 01:01:52 GMT
Title: TikTok for Android 1-Click RCE
Link: https://medium.com/p/240266e78105
Date: Thu, 18 Mar 2021 01:01:52 GMT
Title: TikTok for Android 1-Click RCE
Link: https://medium.com/p/240266e78105
Medium
TikTok for Android 1-Click RCE
Chaining multiple bugs on TikTok for Android to achieving Remote code execution in the application’s context.
New Writeup❗️
Date: Fri, 02 Oct 2020 13:47:58 GMT
Title: Arbitrary code execution on Facebook for Android through download feature
Link: https://medium.com/p/fb6826e33e0f
Date: Fri, 02 Oct 2020 13:47:58 GMT
Title: Arbitrary code execution on Facebook for Android through download feature
Link: https://medium.com/p/fb6826e33e0f
Medium
Arbitrary code execution on Facebook for Android through download feature
TL;DR
New Writeup❗️
Date: Fri, 13 Dec 2019 18:44:55 GMT
Title: Vimeo upload function SSRF
Link: https://medium.com/p/7466d8630437
Date: Fri, 13 Dec 2019 18:44:55 GMT
Title: Vimeo upload function SSRF
Link: https://medium.com/p/7466d8630437
Medium
Vimeo upload function SSRF
TL;DR
New Writeup❗️
Date: Sun, 01 Nov 2020 20:12:58 GMT
Title: An often overlooked Oauth misconfiguration.
Link: https://medium.com/p/7d2d441eae1f
Date: Sun, 01 Nov 2020 20:12:58 GMT
Title: An often overlooked Oauth misconfiguration.
Link: https://medium.com/p/7d2d441eae1f
Medium
An often overlooked Oauth misconfiguration.
Good afternoon.
New Writeup❗️
Date: Thu, 24 Jun 2021 13:35:34 GMT
Title: From Information Disclosure to interesting Privilege Escalation
Link: https://medium.com/p/61ed3aaaf218
Date: Thu, 24 Jun 2021 13:35:34 GMT
Title: From Information Disclosure to interesting Privilege Escalation
Link: https://medium.com/p/61ed3aaaf218
Medium
From Information Disclosure to interesting Privilege Escalation
Cool information disclosure which leads me to be an admin of the application eventually.
New Writeup❗️
Date: Wed, 15 Feb 2023 19:13:06 GMT
Title: Leaking internal CMS_OIDs gives access to internal Facebook support pages.
Link: https://medium.com/p/6ed1dbd94c11
Date: Wed, 15 Feb 2023 19:13:06 GMT
Title: Leaking internal CMS_OIDs gives access to internal Facebook support pages.
Link: https://medium.com/p/6ed1dbd94c11
Medium
Leaking internal CMS_OIDs gives access to internal Facebook support pages.
The Facebook help or support centre consists from 2 levels
New Writeup❗️
Date: Mon, 31 Jan 2022 15:25:30 GMT
Title: Disclose author of anonymous post on GAAP GraphQL object
Link: https://medium.com/p/b07145966b8
Date: Mon, 31 Jan 2022 15:25:30 GMT
Title: Disclose author of anonymous post on GAAP GraphQL object
Link: https://medium.com/p/b07145966b8
Medium
Disclose author of anonymous post on GAAP GraphQL object
The Facebook GraphQL object GroupAnonAuthorProfile has a field which lead to infer identity of author of anonymous post.
New Writeup❗️
Date: Thu, 26 Aug 2021 10:27:38 GMT
Title: Show Facebook stack trace error messages
Link: https://medium.com/p/97485f04898a
Date: Thu, 26 Aug 2021 10:27:38 GMT
Title: Show Facebook stack trace error messages
Link: https://medium.com/p/97485f04898a
Medium
Show Facebook stack trace error messages
Some raw stack trace error messages could be showed to the user when doing specific requests. include debugging info and some filenames…
New Writeup❗️
Date: Sun, 18 Apr 2021 19:31:25 GMT
Title: (POC) Untrim any live video on Facebook
Link: https://medium.com/p/ad6b97bad7c0
Date: Sun, 18 Apr 2021 19:31:25 GMT
Title: (POC) Untrim any live video on Facebook
Link: https://medium.com/p/ad6b97bad7c0
Medium
(POC) Untrim any live video on Facebook
Description / Impact
New Writeup❗️
Date: Sat, 17 Apr 2021 22:29:08 GMT
Title: (POC) Update business fyi message as Facebook page analyst
Link: https://medium.com/p/d36170fdede2
Date: Sat, 17 Apr 2021 22:29:08 GMT
Title: (POC) Update business fyi message as Facebook page analyst
Link: https://medium.com/p/d36170fdede2
Medium
(POC) Update business fyi message as Facebook page analyst
Description / Impact