New Writeup❗️
Date: Sun, 10 Apr 2022 21:01:03 GMT
Title: XSS | HTML Injection and File Upload Bypass in HUAWEI Subdomain
Link: https://medium.com/p/64966ba4f4ac
Date: Sun, 10 Apr 2022 21:01:03 GMT
Title: XSS | HTML Injection and File Upload Bypass in HUAWEI Subdomain
Link: https://medium.com/p/64966ba4f4ac
Medium
XSS | HTML Injection and File Upload Bypass in HUAWEI Subdomain
Hi all :) I hope you are all good :)
New Writeup❗️
Date: Sat, 02 Oct 2021 20:45:16 GMT
Title: Admin Username Disclosure
Link: https://medium.com/p/9c03dd30e8dd
Date: Sat, 02 Oct 2021 20:45:16 GMT
Title: Admin Username Disclosure
Link: https://medium.com/p/9c03dd30e8dd
Medium
Admin Username Disclosure
My youtube Channel: https://www.youtube.com/watch?v=IPmpQa1iUEA
Please subscribe and support me :)
Please subscribe and support me :)
New Writeup❗️
Date: Sat, 25 Sep 2021 22:13:37 GMT
Title: Stored and Reflected XSS and reported
Link: https://medium.com/p/e69ac5750fb1
Date: Sat, 25 Sep 2021 22:13:37 GMT
Title: Stored and Reflected XSS and reported
Link: https://medium.com/p/e69ac5750fb1
Medium
Stored and Reflected XSS and reported
My youtube Channel: https://www.youtube.com/watch?v=IPmpQa1iUEA
Please subscribe and support me :)
Please subscribe and support me :)
New Writeup❗️
Date: Thu, 23 Sep 2021 05:21:32 GMT
Title: [Bug Bounty Writeups] Exploiting Cross Site Scripting XSS
Link: https://medium.com/p/5dde1473af3f
Date: Thu, 23 Sep 2021 05:21:32 GMT
Title: [Bug Bounty Writeups] Exploiting Cross Site Scripting XSS
Link: https://medium.com/p/5dde1473af3f
Medium
[Bug Bounty Writeups] Exploiting Cross Site Scripting XSS
This Writeup shows how important it is to test every single input field on any Website even if it is just a form. So let us start :)
New Writeup❗️
Date: Fri, 17 Aug 2018 14:45:30 GMT
Title: YAHOO IDOR -elimination of any comment
Link: https://medium.com/p/e898f4f955f1
Date: Fri, 17 Aug 2018 14:45:30 GMT
Title: YAHOO IDOR -elimination of any comment
Link: https://medium.com/p/e898f4f955f1
Medium
YAHOO IDOR -elimination of any comment
Hello everyone, my name is Bernardo and I’m from Chile, this time I bring you a bug (IDOR) that I found in Yahoo that allows you to remove…
New Writeup❗️
Date: Wed, 13 Jun 2018 16:43:44 GMT
Title: Vulnerability Netflix (cross-site-scripting) XSS
Link: https://medium.com/p/d44010142e2c
Date: Wed, 13 Jun 2018 16:43:44 GMT
Title: Vulnerability Netflix (cross-site-scripting) XSS
Link: https://medium.com/p/d44010142e2c
Medium
Vulnerability Netflix (cross-site-scripting) XSS
Today I wanted to share with you my first vulnerability found in the bugbounty programs. It's the first time I do a POST about a bug. I…
New Writeup❗️
Date: Thu, 16 Feb 2023 07:39:11 GMT
Title: Misusing Azure to get pre-login system shell on your managed device
Link: https://medium.com/p/3f213b976683
Date: Thu, 16 Feb 2023 07:39:11 GMT
Title: Misusing Azure to get pre-login system shell on your managed device
Link: https://medium.com/p/3f213b976683
Medium
Misusing Azure to get pre-login system shell on your managed device
and how you can disable the Bitlocker Recovery key visibility in Azure.
New Writeup❗️
Date: Tue, 22 Nov 2022 09:06:00 GMT
Title: Bug Bounty Tips and Getting Persistence With Electron Applications
Link: https://medium.com/p/c538d4dda446
Date: Tue, 22 Nov 2022 09:06:00 GMT
Title: Bug Bounty Tips and Getting Persistence With Electron Applications
Link: https://medium.com/p/c538d4dda446
Medium
Bug Bounty Tips and Getting Persistence With Electron Applications
By repacking asar files, electron applications, and other bug bounty tips. Starring Signal, Discord, Nordpass, and more
New Writeup❗️
Date: Wed, 16 Nov 2022 09:27:11 GMT
Title: DLL Hijacking Persistence Using Discord
Link: https://medium.com/p/80691a63c559
Date: Wed, 16 Nov 2022 09:27:11 GMT
Title: DLL Hijacking Persistence Using Discord
Link: https://medium.com/p/80691a63c559
Medium
DLL Hijacking Persistence Using Discord
How old hacking techniques like DLL Hijacking still work in the present day and how you can find them yourself.
New Writeup❗️
Date: Sat, 12 Nov 2022 13:28:47 GMT
Title: Getting Stealthy Persistence Using Visual Studio Code
Link: https://medium.com/p/67e731bea34a
Date: Sat, 12 Nov 2022 13:28:47 GMT
Title: Getting Stealthy Persistence Using Visual Studio Code
Link: https://medium.com/p/67e731bea34a
Medium
Getting Stealthy Persistence Using Visual Studio Code
By misusing the settings file
New Writeup❗️
Date: Fri, 11 Nov 2022 07:46:26 GMT
Title: Getting persistence using Git bash
Link: https://medium.com/p/e82c999652f
Date: Fri, 11 Nov 2022 07:46:26 GMT
Title: Getting persistence using Git bash
Link: https://medium.com/p/e82c999652f
Medium
Getting persistence using Git bash
Gething persistence with the windows terminal made me eager to search for more possible persistence methods. Being a full time software…
New Writeup❗️
Date: Wed, 09 Nov 2022 06:50:36 GMT
Title: Stealthy Persistence While Using Windows Terminal.
Link: https://medium.com/p/ff6f4927563a
Date: Wed, 09 Nov 2022 06:50:36 GMT
Title: Stealthy Persistence While Using Windows Terminal.
Link: https://medium.com/p/ff6f4927563a
Medium
Stealthy Persistence While Using Windows Terminal.
By misusing the setting file
New Writeup❗️
Date: Thu, 03 Nov 2022 06:16:49 GMT
Title: How I could have been the administrator for all Dutch companies and create invoices and still can…
Link: https://medium.com/p/de181160cec5
Date: Thu, 03 Nov 2022 06:16:49 GMT
Title: How I could have been the administrator for all Dutch companies and create invoices and still can…
Link: https://medium.com/p/de181160cec5
Medium
How I could have been the administrator for all Dutch companies and create invoices. And still can be…
This is how I got administrator rights for all Dutch companies with the ability to write invoices on a Dutch government agency application.
New Writeup❗️
Date: Tue, 13 Sep 2022 16:10:09 GMT
Title: Blind XSS and Time-Based SQL Injection to Admin Panel Control and Database Takeover
Link: https://medium.com/p/9b7645a53748
Date: Tue, 13 Sep 2022 16:10:09 GMT
Title: Blind XSS and Time-Based SQL Injection to Admin Panel Control and Database Takeover
Link: https://medium.com/p/9b7645a53748
Medium
Blind XSS and Time-Based SQL Injection to Admin Panel Control and Database Takeover
Hello Fellas,
🗿1
New Writeup❗️
Date: Fri, 12 Aug 2022 06:23:52 GMT
Title: Contentful Access Token Disclosure in Android APK
Link: https://medium.com/p/ace5f7bdf98
Date: Fri, 12 Aug 2022 06:23:52 GMT
Title: Contentful Access Token Disclosure in Android APK
Link: https://medium.com/p/ace5f7bdf98
Medium
Contentful Access Token Disclosure in Android APK
Hello, My name is Ali, a Penetration Tester and a Certified Ethical Hacker. It’s my first write-up of 2022 on Android APK Pen testing. I…
New Writeup❗️
Date: Sat, 24 Dec 2022 05:35:59 GMT
Title: How I hacked into police and ivoted attack to RCE
Link: https://medium.com/p/83e5c7e5dfd6
Date: Sat, 24 Dec 2022 05:35:59 GMT
Title: How I hacked into police and ivoted attack to RCE
Link: https://medium.com/p/83e5c7e5dfd6
Medium
How I hacked into police and ivoted attack to RCE
Let’s breach in guys,So there was Section for the appreciation letters on site which has public appreciation letters of police.wich has…
New Writeup❗️
Date: Fri, 14 Oct 2022 17:26:11 GMT
Title: Story about Escalation of HTML Injection to EC2 Instance credentials leak
Link: https://medium.com/p/e2cbd7343a83
Date: Fri, 14 Oct 2022 17:26:11 GMT
Title: Story about Escalation of HTML Injection to EC2 Instance credentials leak
Link: https://medium.com/p/e2cbd7343a83
Medium
Story about Escalation of HTML Injection to EC2 Instance credentials leak
Hello all, Thank for the overwhelming response here I am with my new finding tale.
New Writeup❗️
Date: Sat, 01 Oct 2022 18:12:06 GMT
Title: Tale of Easy P1 Bugs in Wild
Link: https://medium.com/p/1b7f5bf80eef
Date: Sat, 01 Oct 2022 18:12:06 GMT
Title: Tale of Easy P1 Bugs in Wild
Link: https://medium.com/p/1b7f5bf80eef
Medium
Tale of Easy P1 Bugs in Wild
So after long time, i got back on bugcrowd where i had private program so i looked at scope it was wildcard (*.redicated.com) scope.I…
New Writeup❗️
Date: Thu, 31 Dec 2020 06:29:06 GMT
Title: Threat Hunting 101— Part1
Link: https://medium.com/p/4f7e544a2df2
Date: Thu, 31 Dec 2020 06:29:06 GMT
Title: Threat Hunting 101— Part1
Link: https://medium.com/p/4f7e544a2df2
Medium
Threat Hunting 101— Part1
This is a primer for threat hunting. I would be doing a series of articles around it. So let’s start by defining what threat hunting is…
New Writeup❗️
Date: Sun, 27 Sep 2020 21:51:31 GMT
Title: What is a Magic Byte and how to exploit
Link: https://medium.com/p/1e286da1c198
Date: Sun, 27 Sep 2020 21:51:31 GMT
Title: What is a Magic Byte and how to exploit
Link: https://medium.com/p/1e286da1c198
Medium
What is a Magic Byte and how to exploit
You might be wondering what exactly is magic byte and what is so magical about it. Don’t worry if you are a programmer you might already…