New Writeup❗️
Date: Fri, 14 Oct 2022 17:26:11 GMT
Title: Story about Escalation of HTML Injection to EC2 Instance credentials leak
Link: https://medium.com/p/e2cbd7343a83
Date: Fri, 14 Oct 2022 17:26:11 GMT
Title: Story about Escalation of HTML Injection to EC2 Instance credentials leak
Link: https://medium.com/p/e2cbd7343a83
Medium
Story about Escalation of HTML Injection to EC2 Instance credentials leak
Hello all, Thank for the overwhelming response here I am with my new finding tale.
New Writeup❗️
Date: Sat, 01 Oct 2022 18:12:06 GMT
Title: Tale of Easy P1 Bugs in Wild
Link: https://medium.com/p/1b7f5bf80eef
Date: Sat, 01 Oct 2022 18:12:06 GMT
Title: Tale of Easy P1 Bugs in Wild
Link: https://medium.com/p/1b7f5bf80eef
Medium
Tale of Easy P1 Bugs in Wild
So after long time, i got back on bugcrowd where i had private program so i looked at scope it was wildcard (*.redicated.com) scope.I…
New Writeup❗️
Date: Thu, 31 Dec 2020 06:29:06 GMT
Title: Threat Hunting 101— Part1
Link: https://medium.com/p/4f7e544a2df2
Date: Thu, 31 Dec 2020 06:29:06 GMT
Title: Threat Hunting 101— Part1
Link: https://medium.com/p/4f7e544a2df2
Medium
Threat Hunting 101— Part1
This is a primer for threat hunting. I would be doing a series of articles around it. So let’s start by defining what threat hunting is…
New Writeup❗️
Date: Sun, 27 Sep 2020 21:51:31 GMT
Title: What is a Magic Byte and how to exploit
Link: https://medium.com/p/1e286da1c198
Date: Sun, 27 Sep 2020 21:51:31 GMT
Title: What is a Magic Byte and how to exploit
Link: https://medium.com/p/1e286da1c198
Medium
What is a Magic Byte and how to exploit
You might be wondering what exactly is magic byte and what is so magical about it. Don’t worry if you are a programmer you might already…
New Writeup❗️
Date: Sun, 13 Sep 2020 16:42:30 GMT
Title: Business logic vulnerabilities — Low-level logic flaw
Link: https://medium.com/p/f308a21a945d
Date: Sun, 13 Sep 2020 16:42:30 GMT
Title: Business logic vulnerabilities — Low-level logic flaw
Link: https://medium.com/p/f308a21a945d
Medium
Business logic vulnerabilities — Low-level logic flaw
This is the third of the series of articles for business logic vulnerabilities. This one is more complicated than the previous two.
New Writeup❗️
Date: Sat, 12 Sep 2020 12:30:20 GMT
Title: Business logic vulnerabilities — High-level logic vulnerability
Link: https://medium.com/p/9f89c7ac11b
Date: Sat, 12 Sep 2020 12:30:20 GMT
Title: Business logic vulnerabilities — High-level logic vulnerability
Link: https://medium.com/p/9f89c7ac11b
Medium
Business logic vulnerabilities — High-level logic vulnerability
This is the second in the series of various Business login vulnerabilities. You can find the first one here.
New Writeup❗️
Date: Tue, 08 Sep 2020 08:54:06 GMT
Title: Business Logic Vulnerabilities excessive client-side controls
Link: https://medium.com/p/c6a1f9a2e6ab
Date: Tue, 08 Sep 2020 08:54:06 GMT
Title: Business Logic Vulnerabilities excessive client-side controls
Link: https://medium.com/p/c6a1f9a2e6ab
Medium
Business Logic Vulnerabilities excessive client-side controls
Think of a scenario where you login to an eCommerce website to buy something. Below are the steps you will follow.
New Writeup❗️
Date: Mon, 06 Apr 2020 17:33:23 GMT
Title: $3K Bounty For Elastic-Search Takeover
Link: https://medium.com/p/70c0847d2e40
Date: Mon, 06 Apr 2020 17:33:23 GMT
Title: $3K Bounty For Elastic-Search Takeover
Link: https://medium.com/p/70c0847d2e40
Medium
$3K Bounty For Elastic-Search Takeover
Hello, Everyone
New Writeup❗️
Date: Fri, 25 Oct 2019 11:26:26 GMT
Title: How I Tookover a ldap server.
Link: https://medium.com/p/703209161001
Date: Fri, 25 Oct 2019 11:26:26 GMT
Title: How I Tookover a ldap server.
Link: https://medium.com/p/703209161001
Medium
How I Tookover a ldap server.
Intro
New Writeup❗️
Date: Tue, 16 Apr 2019 11:15:42 GMT
Title: How i found credential enriched redis dump
Link: https://medium.com/p/2b9e808024c4
Date: Tue, 16 Apr 2019 11:15:42 GMT
Title: How i found credential enriched redis dump
Link: https://medium.com/p/2b9e808024c4
Medium
How i found credential enriched redis dump
New Writeup❗️
Date: Wed, 29 Aug 2018 18:44:58 GMT
Title: A Infinite Loop Story.
Link: https://medium.com/p/f2bc05771a88
Date: Wed, 29 Aug 2018 18:44:58 GMT
Title: A Infinite Loop Story.
Link: https://medium.com/p/f2bc05771a88
Medium
A Infinite Loop Story.
Note: i have already covered this vulnerability previously 2 times on my blogs so you can check that out.
New Writeup❗️
Date: Tue, 28 Aug 2018 05:59:12 GMT
Title: How i found a 1500$ worth Deserialization vulnerability
Link: https://medium.com/p/9ce753416e0a
Date: Tue, 28 Aug 2018 05:59:12 GMT
Title: How i found a 1500$ worth Deserialization vulnerability
Link: https://medium.com/p/9ce753416e0a
Medium
How i found a 1500$ worth Deserialization vulnerability
Note before you start.
New Writeup❗️
Date: Fri, 01 Jun 2018 12:05:53 GMT
Title: How i converted SSRF TO XSS in jira.
Link: https://medium.com/p/e9f37ad5b158
Date: Fri, 01 Jun 2018 12:05:53 GMT
Title: How i converted SSRF TO XSS in jira.
Link: https://medium.com/p/e9f37ad5b158
Medium
How i converted SSRF TO XSS in jira.
I m very much into Bug Bounty and i spend my whole day doing this finding new and interesting stuff and kept on upgrading my recon…
New Writeup❗️
Date: Mon, 16 Apr 2018 16:20:33 GMT
Title: The Way I Recon
Link: https://medium.com/p/9956e2ed5ffa
Date: Mon, 16 Apr 2018 16:20:33 GMT
Title: The Way I Recon
Link: https://medium.com/p/9956e2ed5ffa
Medium
The Way I Recon
Many People ask me , how did you find that bug ? i have spend-ed many days but i didn’t found any Bug Yet .
New Writeup❗️
Date: Tue, 09 Apr 2019 12:45:52 GMT
Title: Obtaining XSS Using Moodle Features and Minor Bugs
Link: https://medium.com/p/2035665989cc
Date: Tue, 09 Apr 2019 12:45:52 GMT
Title: Obtaining XSS Using Moodle Features and Minor Bugs
Link: https://medium.com/p/2035665989cc
Medium
Obtaining XSS Using Moodle Features and Minor Bugs
Using login CSRF to turn self-XSS into real XSS.
New Writeup❗️
Date: Mon, 02 Mar 2020 00:16:03 GMT
Title: Discord embed spoofing
Link: https://medium.com/p/c6d07ab1decc
Date: Mon, 02 Mar 2020 00:16:03 GMT
Title: Discord embed spoofing
Link: https://medium.com/p/c6d07ab1decc
Medium
Discord embed spoofing
TLDR: I found a bug in the way the Discord clients parse URLs which makes my custom embed content appear to come from a legitimate domain.
New Writeup❗️
Date: Mon, 24 Feb 2020 01:54:55 GMT
Title: Breaking a Discord channel with a single message
Link: https://medium.com/p/5095eb7604f1
Date: Mon, 24 Feb 2020 01:54:55 GMT
Title: Breaking a Discord channel with a single message
Link: https://medium.com/p/5095eb7604f1
Medium
Breaking a Discord channel with a single message
Discord DoS with a single message TLDR: I discovered that sending the message https://%[email protected] from the mobile app would result in a permanent denial of service of a Discord channel on the web …
New Writeup❗️
Date: Wed, 21 Dec 2022 18:43:24 GMT
Title: My First Bug in Bugcrowd
Link: https://medium.com/p/76decc1f9901
Date: Wed, 21 Dec 2022 18:43:24 GMT
Title: My First Bug in Bugcrowd
Link: https://medium.com/p/76decc1f9901
Medium
My First Bug in Bugcrowd
Hi everybody
New Writeup❗️
Date: Sat, 05 Nov 2022 09:37:44 GMT
Title: Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Link: https://medium.com/p/d5c4868680f5
Date: Sat, 05 Nov 2022 09:37:44 GMT
Title: Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Link: https://medium.com/p/d5c4868680f5
Medium
Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Hello and welcome everyone to my story of how I got my first bounty on HackerOne by exploiting an SSRF that leaked Google cloud access…
New Writeup❗️
Date: Wed, 21 Sep 2022 18:28:07 GMT
Title: How I hacked an exam portal and got access to 10K+ users data including webcams
Link: https://medium.com/p/ec2262b43df7
Date: Wed, 21 Sep 2022 18:28:07 GMT
Title: How I hacked an exam portal and got access to 10K+ users data including webcams
Link: https://medium.com/p/ec2262b43df7
Medium
How I hacked an exam portal and got access to 10K+ users data including webcams
Hello guys, I am Faique a security researcher and a bug bounty hunter and I welcome you to my write-up on a story of a hack that I did…