New Writeup❗️
Date: Mon, 06 Apr 2020 17:33:23 GMT
Title: $3K Bounty For Elastic-Search Takeover
Link: https://medium.com/p/70c0847d2e40
Date: Mon, 06 Apr 2020 17:33:23 GMT
Title: $3K Bounty For Elastic-Search Takeover
Link: https://medium.com/p/70c0847d2e40
Medium
$3K Bounty For Elastic-Search Takeover
Hello, Everyone
New Writeup❗️
Date: Fri, 25 Oct 2019 11:26:26 GMT
Title: How I Tookover a ldap server.
Link: https://medium.com/p/703209161001
Date: Fri, 25 Oct 2019 11:26:26 GMT
Title: How I Tookover a ldap server.
Link: https://medium.com/p/703209161001
Medium
How I Tookover a ldap server.
Intro
New Writeup❗️
Date: Tue, 16 Apr 2019 11:15:42 GMT
Title: How i found credential enriched redis dump
Link: https://medium.com/p/2b9e808024c4
Date: Tue, 16 Apr 2019 11:15:42 GMT
Title: How i found credential enriched redis dump
Link: https://medium.com/p/2b9e808024c4
Medium
How i found credential enriched redis dump
New Writeup❗️
Date: Wed, 29 Aug 2018 18:44:58 GMT
Title: A Infinite Loop Story.
Link: https://medium.com/p/f2bc05771a88
Date: Wed, 29 Aug 2018 18:44:58 GMT
Title: A Infinite Loop Story.
Link: https://medium.com/p/f2bc05771a88
Medium
A Infinite Loop Story.
Note: i have already covered this vulnerability previously 2 times on my blogs so you can check that out.
New Writeup❗️
Date: Tue, 28 Aug 2018 05:59:12 GMT
Title: How i found a 1500$ worth Deserialization vulnerability
Link: https://medium.com/p/9ce753416e0a
Date: Tue, 28 Aug 2018 05:59:12 GMT
Title: How i found a 1500$ worth Deserialization vulnerability
Link: https://medium.com/p/9ce753416e0a
Medium
How i found a 1500$ worth Deserialization vulnerability
Note before you start.
New Writeup❗️
Date: Fri, 01 Jun 2018 12:05:53 GMT
Title: How i converted SSRF TO XSS in jira.
Link: https://medium.com/p/e9f37ad5b158
Date: Fri, 01 Jun 2018 12:05:53 GMT
Title: How i converted SSRF TO XSS in jira.
Link: https://medium.com/p/e9f37ad5b158
Medium
How i converted SSRF TO XSS in jira.
I m very much into Bug Bounty and i spend my whole day doing this finding new and interesting stuff and kept on upgrading my recon…
New Writeup❗️
Date: Mon, 16 Apr 2018 16:20:33 GMT
Title: The Way I Recon
Link: https://medium.com/p/9956e2ed5ffa
Date: Mon, 16 Apr 2018 16:20:33 GMT
Title: The Way I Recon
Link: https://medium.com/p/9956e2ed5ffa
Medium
The Way I Recon
Many People ask me , how did you find that bug ? i have spend-ed many days but i didn’t found any Bug Yet .
New Writeup❗️
Date: Tue, 09 Apr 2019 12:45:52 GMT
Title: Obtaining XSS Using Moodle Features and Minor Bugs
Link: https://medium.com/p/2035665989cc
Date: Tue, 09 Apr 2019 12:45:52 GMT
Title: Obtaining XSS Using Moodle Features and Minor Bugs
Link: https://medium.com/p/2035665989cc
Medium
Obtaining XSS Using Moodle Features and Minor Bugs
Using login CSRF to turn self-XSS into real XSS.
New Writeup❗️
Date: Mon, 02 Mar 2020 00:16:03 GMT
Title: Discord embed spoofing
Link: https://medium.com/p/c6d07ab1decc
Date: Mon, 02 Mar 2020 00:16:03 GMT
Title: Discord embed spoofing
Link: https://medium.com/p/c6d07ab1decc
Medium
Discord embed spoofing
TLDR: I found a bug in the way the Discord clients parse URLs which makes my custom embed content appear to come from a legitimate domain.
New Writeup❗️
Date: Mon, 24 Feb 2020 01:54:55 GMT
Title: Breaking a Discord channel with a single message
Link: https://medium.com/p/5095eb7604f1
Date: Mon, 24 Feb 2020 01:54:55 GMT
Title: Breaking a Discord channel with a single message
Link: https://medium.com/p/5095eb7604f1
Medium
Breaking a Discord channel with a single message
Discord DoS with a single message TLDR: I discovered that sending the message https://%[email protected] from the mobile app would result in a permanent denial of service of a Discord channel on the web …
New Writeup❗️
Date: Wed, 21 Dec 2022 18:43:24 GMT
Title: My First Bug in Bugcrowd
Link: https://medium.com/p/76decc1f9901
Date: Wed, 21 Dec 2022 18:43:24 GMT
Title: My First Bug in Bugcrowd
Link: https://medium.com/p/76decc1f9901
Medium
My First Bug in Bugcrowd
Hi everybody
New Writeup❗️
Date: Sat, 05 Nov 2022 09:37:44 GMT
Title: Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Link: https://medium.com/p/d5c4868680f5
Date: Sat, 05 Nov 2022 09:37:44 GMT
Title: Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Link: https://medium.com/p/d5c4868680f5
Medium
Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Hello and welcome everyone to my story of how I got my first bounty on HackerOne by exploiting an SSRF that leaked Google cloud access…
New Writeup❗️
Date: Wed, 21 Sep 2022 18:28:07 GMT
Title: How I hacked an exam portal and got access to 10K+ users data including webcams
Link: https://medium.com/p/ec2262b43df7
Date: Wed, 21 Sep 2022 18:28:07 GMT
Title: How I hacked an exam portal and got access to 10K+ users data including webcams
Link: https://medium.com/p/ec2262b43df7
Medium
How I hacked an exam portal and got access to 10K+ users data including webcams
Hello guys, I am Faique a security researcher and a bug bounty hunter and I welcome you to my write-up on a story of a hack that I did…
New Writeup❗️
Date: Fri, 19 Aug 2022 17:40:02 GMT
Title: Account takeover worth $1000
Link: https://medium.com/p/611452063cf
Date: Fri, 19 Aug 2022 17:40:02 GMT
Title: Account takeover worth $1000
Link: https://medium.com/p/611452063cf
Medium
Account takeover worth $1000
How I was able to find account takeover bug in one of the biggest organization in the world
New Writeup❗️
Date: Sat, 16 Jul 2022 17:53:56 GMT
Title: First Bug Bounty from DOS: Taking the service down
Link: https://medium.com/p/30f9ad4e0246
Date: Sat, 16 Jul 2022 17:53:56 GMT
Title: First Bug Bounty from DOS: Taking the service down
Link: https://medium.com/p/30f9ad4e0246
Medium
First Bug Bounty from DOS: Taking the service down
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.
New Writeup❗️
Date: Tue, 24 May 2022 22:06:54 GMT
Title: Bye Bye medium.com
Link: https://medium.com/p/8026b2a4291a
Date: Tue, 24 May 2022 22:06:54 GMT
Title: Bye Bye medium.com
Link: https://medium.com/p/8026b2a4291a
Medium
Bye Bye medium.com
No more medium.com in the future. I’ll publish my new blog posts here instead…see you there.
New Writeup❗️
Date: Wed, 30 Mar 2022 22:01:22 GMT
Title: Pwning 3CX Phone Management Backends from the Internet
Link: https://medium.com/p/d0096339dd88
Date: Wed, 30 Mar 2022 22:01:22 GMT
Title: Pwning 3CX Phone Management Backends from the Internet
Link: https://medium.com/p/d0096339dd88
Medium
Pwning 3CX Phone Management Backends from the Internet
After an unplanned journey with Microsoft Exchange the month before, I started to look for new interesting vulnerability research targets…
New Writeup❗️
Date: Wed, 12 Jan 2022 21:52:34 GMT
Title: Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)
Link: https://medium.com/p/bfa38f63a62d
Date: Wed, 12 Jan 2022 21:52:34 GMT
Title: Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)
Link: https://medium.com/p/bfa38f63a62d
Medium
Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)
This story begins with a series of fails, but why? That is because of my special relationship with the Microsoft Exchange codebase…
New Writeup❗️
Date: Mon, 11 May 2020 18:02:35 GMT
Title: Another Zoho ManageEngine Story
Link: https://medium.com/p/7b472f1515f5
Date: Mon, 11 May 2020 18:02:35 GMT
Title: Another Zoho ManageEngine Story
Link: https://medium.com/p/7b472f1515f5
Medium
Another Zoho ManageEngine Story
This is another white-box analysis story about a product from Zoho Corp (see my older blog post on OpManager SQLi). Since several critical…
New Writeup❗️
Date: Sun, 29 Dec 2019 22:10:39 GMT
Title: Yet Another .NET deserialization
Link: https://medium.com/p/35f6ce048df7
Date: Sun, 29 Dec 2019 22:10:39 GMT
Title: Yet Another .NET deserialization
Link: https://medium.com/p/35f6ce048df7
Medium
Yet Another .NET deserialization
This is my second post on white-box analysis but for another technology stack and vulnerability category: .NET deserialization leading to…