New Writeup❗️
Date: Wed, 03 Jun 2020 13:17:09 GMT
Title: From CRLF to Account Takeover
Link: https://medium.com/p/a94d7aa0d74e
Date: Wed, 03 Jun 2020 13:17:09 GMT
Title: From CRLF to Account Takeover
Link: https://medium.com/p/a94d7aa0d74e
Medium
From CRLF to Account Takeover
At the beginning of March,while researching one site I discovered the new functionality. The functionality allowed the user to login via…
New Writeup❗️
Date: Fri, 28 May 2021 23:28:53 GMT
Title: The beauty of chaining client-side bugs
Link: https://medium.com/p/759e1091eabf
Date: Fri, 28 May 2021 23:28:53 GMT
Title: The beauty of chaining client-side bugs
Link: https://medium.com/p/759e1091eabf
Medium
The beauty of chaining client-side bugs
This is part of a report of a bug that I sent back in 2020, changing of course the program name for obvious reasons.
New Writeup❗️
Date: Sat, 14 Dec 2019 03:49:41 GMT
Title: Weaponizing BURP to work as an evil SSRF Confluence Server.
Link: https://medium.com/p/e077d71b4ef2
Date: Sat, 14 Dec 2019 03:49:41 GMT
Title: Weaponizing BURP to work as an evil SSRF Confluence Server.
Link: https://medium.com/p/e077d71b4ef2
Medium
Weaponizing BURP to work as an evil SSRF Confluence Server.
I was doing bounty on a private H1 program that interacts with various external services one of them was Atlassian Confluence and Jira.
New Writeup❗️
Date: Fri, 11 Oct 2019 15:45:05 GMT
Title: Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Link: https://medium.com/p/daf7a82673ce
Date: Fri, 11 Oct 2019 15:45:05 GMT
Title: Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Link: https://medium.com/p/daf7a82673ce
Medium
Bypass Uppercase filters like a PRO (XSS Advanced Methods)
While we are not working on Pentesting for companies, we love to Bug Hunting on Hackerone.
New Writeup❗️
Date: Tue, 03 May 2022 19:16:45 GMT
Title: How I got a lousyT-Shirt from the Dutch Goverment.
Link: https://medium.com/p/2a0d13fe7675
Date: Tue, 03 May 2022 19:16:45 GMT
Title: How I got a lousyT-Shirt from the Dutch Goverment.
Link: https://medium.com/p/2a0d13fe7675
Medium
How I got a lousyT-Shirt from the Dutch Goverment.
Hello everyone,
my name is Max. I’m a Computer Science student and ethical hacker from Germany. Today I want to tell you how I hacked the…
my name is Max. I’m a Computer Science student and ethical hacker from Germany. Today I want to tell you how I hacked the…
New Writeup❗️
Date: Fri, 07 Oct 2022 16:37:05 GMT
Title: Insecure Comments
Link: https://medium.com/p/73399193f804
Date: Fri, 07 Oct 2022 16:37:05 GMT
Title: Insecure Comments
Link: https://medium.com/p/73399193f804
Medium
Insecure Comments
Hi All,
New Writeup❗️
Date: Thu, 28 Jul 2022 21:01:19 GMT
Title: Reading Message from Microsoft’s Private Yammer Group
Link: https://medium.com/p/6be844639bca
Date: Thu, 28 Jul 2022 21:01:19 GMT
Title: Reading Message from Microsoft’s Private Yammer Group
Link: https://medium.com/p/6be844639bca
Medium
Reading Message from Microsoft’s Private Yammer Group
Hi All,
New Writeup❗️
Date: Fri, 18 Mar 2022 19:24:09 GMT
Title: Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Link: https://medium.com/p/bed3b45e509
Date: Fri, 18 Mar 2022 19:24:09 GMT
Title: Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Link: https://medium.com/p/bed3b45e509
Medium
Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Hi Everyone,
New Writeup❗️
Date: Wed, 15 Dec 2021 22:06:28 GMT
Title: Broken Access Control
Link: https://medium.com/p/cc6cfd793b15
Date: Wed, 15 Dec 2021 22:06:28 GMT
Title: Broken Access Control
Link: https://medium.com/p/cc6cfd793b15
Medium
Broken Access Control
Part 0x01 | Improper Authorization could allow access to more than 100,000 Microsoft Dynamics 365 for Partner Users
New Writeup❗️
Date: Wed, 31 Aug 2022 11:45:56 GMT
Title: Saving 100,000 websites from a Watering Hole attack
Link: https://medium.com/p/a22f63a37f94
Date: Wed, 31 Aug 2022 11:45:56 GMT
Title: Saving 100,000 websites from a Watering Hole attack
Link: https://medium.com/p/a22f63a37f94
Medium
Saving 100,000 websites from a Watering Hole attack
Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects…
New Writeup❗️
Date: Wed, 20 Oct 2021 03:53:54 GMT
Title: From staging to 0 click account takeover
Link: https://medium.com/p/528a5ecaa3eb
Date: Wed, 20 Oct 2021 03:53:54 GMT
Title: From staging to 0 click account takeover
Link: https://medium.com/p/528a5ecaa3eb
Medium
From staging to 0 click account takeover
Often, as bug bounty hunters or pentesters, while doing our recon on a specific target, we come accross their staging or pre-production…
New Writeup❗️
Date: Thu, 18 Mar 2021 18:20:36 GMT
Title: Chaining bugs for the greater good
Link: https://medium.com/p/664412ae85f8
Date: Thu, 18 Mar 2021 18:20:36 GMT
Title: Chaining bugs for the greater good
Link: https://medium.com/p/664412ae85f8
Medium
Chaining bugs for the greater good
Hello internet hustlers ! After a while of going back and forth with myself, I have finally decided to start publishing some writeups…
New Writeup❗️
Date: Thu, 17 Nov 2022 04:43:09 GMT
Title: Information Exposure — My Fourth Finding on Hackerone!
Link: https://medium.com/p/4fc4461920c4
Date: Thu, 17 Nov 2022 04:43:09 GMT
Title: Information Exposure — My Fourth Finding on Hackerone!
Link: https://medium.com/p/4fc4461920c4
Medium
Information Exposure — My Fourth Finding on Hackerone!
Information Exposure Through Directory Listing — The bug title says everything about it. Find a path or URL on any website that's enable…
New Writeup❗️
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Medium
Improper Access Control — My Third Finding on HackerOne!
Improper Access Control means web application or software functions does not restrict or incorrectly restricts access and usage to any…
New Writeup❗️
Date: Sun, 23 Oct 2022 11:28:54 GMT
Title: Broken Link Hijacking — My Second Finding on Hackerone!
Link: https://medium.com/p/d715b0713fca
Date: Sun, 23 Oct 2022 11:28:54 GMT
Title: Broken Link Hijacking — My Second Finding on Hackerone!
Link: https://medium.com/p/d715b0713fca
Medium
Broken Link Hijacking — My Second Finding on Hackerone!
Broken Link Hijacking (BLH) or Link Takeover, whatever you called it, the concept is very simple. If you get any broken links of any…
New Writeup❗️
Date: Fri, 21 Oct 2022 05:10:56 GMT
Title: Information Disclosure — My First Finding on Hackerone!
Link: https://medium.com/p/e572cc07babb
Date: Fri, 21 Oct 2022 05:10:56 GMT
Title: Information Disclosure — My First Finding on Hackerone!
Link: https://medium.com/p/e572cc07babb
Medium
Information Disclosure — My First Finding on Hackerone!
Information Disclosure is a kind of bug that is not so hard to find but could has huge impact. Some time you could get a very sensitive…
New Writeup❗️
Date: Wed, 05 Oct 2022 20:59:28 GMT
Title: Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
Link: https://medium.com/p/99b4a1723051
Date: Wed, 05 Oct 2022 20:59:28 GMT
Title: Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
Link: https://medium.com/p/99b4a1723051
Medium
Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
CrazyHD is one of the famous torrent website in Bangladesh and India. People get pirated movies , paid courses , softwares and more in…
New Writeup❗️
Date: Tue, 30 Aug 2022 11:03:42 GMT
Title: Found SQL Injection Vulnerability on Government Organization Website!
Link: https://medium.com/p/3eb33c0c49a4
Date: Tue, 30 Aug 2022 11:03:42 GMT
Title: Found SQL Injection Vulnerability on Government Organization Website!
Link: https://medium.com/p/3eb33c0c49a4
Medium
Found SQL Injection Vulnerability on Government Organization Website!
Last night before going to sleep i make a quick search on google a dork to find vulnerable websites and found some interesting result and…
🗿1
New Writeup❗️
Date: Tue, 07 Dec 2021 23:05:25 GMT
Title: Introduction : Who am I ?
Link: https://medium.com/p/f6bbcc6cf201
Date: Tue, 07 Dec 2021 23:05:25 GMT
Title: Introduction : Who am I ?
Link: https://medium.com/p/f6bbcc6cf201
Medium
Introduction : Who am I ?
Hey there, everyone! 👋 I’m Mehedi Shakeel, an IT security professional hailing from Bangladesh. With a solid background in ethical…
New Writeup❗️
Date: Mon, 07 Nov 2022 19:09:38 GMT
Title: How we ‘hacked’ Telenet’s cybersecurity quiz
Link: https://medium.com/p/958c1d3ee2ba
Date: Mon, 07 Nov 2022 19:09:38 GMT
Title: How we ‘hacked’ Telenet’s cybersecurity quiz
Link: https://medium.com/p/958c1d3ee2ba
Medium
How we ‘hacked’ Telenet’s cybersecurity quiz
Not so long ago, Telenet Business ran a quiz to find the smartest cyber specialist. The quiz consisted out of 20 questions and your score…