New Writeup❗️
Date: Wed, 21 Dec 2022 18:43:24 GMT
Title: My First Bug in Bugcrowd
Link: https://medium.com/p/76decc1f9901
Date: Wed, 21 Dec 2022 18:43:24 GMT
Title: My First Bug in Bugcrowd
Link: https://medium.com/p/76decc1f9901
Medium
My First Bug in Bugcrowd
Hi everybody
New Writeup❗️
Date: Sat, 05 Nov 2022 09:37:44 GMT
Title: Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Link: https://medium.com/p/d5c4868680f5
Date: Sat, 05 Nov 2022 09:37:44 GMT
Title: Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Link: https://medium.com/p/d5c4868680f5
Medium
Story of a $1k bounty — SSRF to leaking access token and other sensitive information
Hello and welcome everyone to my story of how I got my first bounty on HackerOne by exploiting an SSRF that leaked Google cloud access…
New Writeup❗️
Date: Wed, 21 Sep 2022 18:28:07 GMT
Title: How I hacked an exam portal and got access to 10K+ users data including webcams
Link: https://medium.com/p/ec2262b43df7
Date: Wed, 21 Sep 2022 18:28:07 GMT
Title: How I hacked an exam portal and got access to 10K+ users data including webcams
Link: https://medium.com/p/ec2262b43df7
Medium
How I hacked an exam portal and got access to 10K+ users data including webcams
Hello guys, I am Faique a security researcher and a bug bounty hunter and I welcome you to my write-up on a story of a hack that I did…
New Writeup❗️
Date: Fri, 19 Aug 2022 17:40:02 GMT
Title: Account takeover worth $1000
Link: https://medium.com/p/611452063cf
Date: Fri, 19 Aug 2022 17:40:02 GMT
Title: Account takeover worth $1000
Link: https://medium.com/p/611452063cf
Medium
Account takeover worth $1000
How I was able to find account takeover bug in one of the biggest organization in the world
New Writeup❗️
Date: Sat, 16 Jul 2022 17:53:56 GMT
Title: First Bug Bounty from DOS: Taking the service down
Link: https://medium.com/p/30f9ad4e0246
Date: Sat, 16 Jul 2022 17:53:56 GMT
Title: First Bug Bounty from DOS: Taking the service down
Link: https://medium.com/p/30f9ad4e0246
Medium
First Bug Bounty from DOS: Taking the service down
Hello friends, This is Faique, a security researcher & an ethical hacker from India, and this is a journey to my first bug bounty.
New Writeup❗️
Date: Tue, 24 May 2022 22:06:54 GMT
Title: Bye Bye medium.com
Link: https://medium.com/p/8026b2a4291a
Date: Tue, 24 May 2022 22:06:54 GMT
Title: Bye Bye medium.com
Link: https://medium.com/p/8026b2a4291a
Medium
Bye Bye medium.com
No more medium.com in the future. I’ll publish my new blog posts here instead…see you there.
New Writeup❗️
Date: Wed, 30 Mar 2022 22:01:22 GMT
Title: Pwning 3CX Phone Management Backends from the Internet
Link: https://medium.com/p/d0096339dd88
Date: Wed, 30 Mar 2022 22:01:22 GMT
Title: Pwning 3CX Phone Management Backends from the Internet
Link: https://medium.com/p/d0096339dd88
Medium
Pwning 3CX Phone Management Backends from the Internet
After an unplanned journey with Microsoft Exchange the month before, I started to look for new interesting vulnerability research targets…
New Writeup❗️
Date: Wed, 12 Jan 2022 21:52:34 GMT
Title: Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)
Link: https://medium.com/p/bfa38f63a62d
Date: Wed, 12 Jan 2022 21:52:34 GMT
Title: Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)
Link: https://medium.com/p/bfa38f63a62d
Medium
Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)
This story begins with a series of fails, but why? That is because of my special relationship with the Microsoft Exchange codebase…
New Writeup❗️
Date: Mon, 11 May 2020 18:02:35 GMT
Title: Another Zoho ManageEngine Story
Link: https://medium.com/p/7b472f1515f5
Date: Mon, 11 May 2020 18:02:35 GMT
Title: Another Zoho ManageEngine Story
Link: https://medium.com/p/7b472f1515f5
Medium
Another Zoho ManageEngine Story
This is another white-box analysis story about a product from Zoho Corp (see my older blog post on OpManager SQLi). Since several critical…
New Writeup❗️
Date: Sun, 29 Dec 2019 22:10:39 GMT
Title: Yet Another .NET deserialization
Link: https://medium.com/p/35f6ce048df7
Date: Sun, 29 Dec 2019 22:10:39 GMT
Title: Yet Another .NET deserialization
Link: https://medium.com/p/35f6ce048df7
Medium
Yet Another .NET deserialization
This is my second post on white-box analysis but for another technology stack and vulnerability category: .NET deserialization leading to…
New Writeup❗️
Date: Sun, 13 Oct 2019 06:50:31 GMT
Title: Finding SQL injections fast with white-box analysis — a recent bug example
Link: https://medium.com/p/ca449bce6c76
Date: Sun, 13 Oct 2019 06:50:31 GMT
Title: Finding SQL injections fast with white-box analysis — a recent bug example
Link: https://medium.com/p/ca449bce6c76
Medium
Finding SQL injections fast with white-box analysis — a recent bug example
On September 13rd I submitted a bug for Zoho’s OpManager product. It was fixed quite fast by the development team and a new version 12.4…
🤡1
New Writeup❗️
Date: Sat, 15 Aug 2020 19:46:53 GMT
Title: A Country Hijacking
Link: https://medium.com/p/3180c24a14b5
Date: Sat, 15 Aug 2020 19:46:53 GMT
Title: A Country Hijacking
Link: https://medium.com/p/3180c24a14b5
Medium
A Country Hijacking
Hello All,
New Writeup❗️
Date: Tue, 12 Mar 2019 23:03:42 GMT
Title: Hack Your Form-New vector for Blind XSS
Link: https://medium.com/p/b7a50b808016
Date: Tue, 12 Mar 2019 23:03:42 GMT
Title: Hack Your Form-New vector for Blind XSS
Link: https://medium.com/p/b7a50b808016
Medium
Hack Your Form-New vector for Blind XSS
Hello Pentesters,
New Writeup❗️
Date: Tue, 12 Mar 2019 22:55:12 GMT
Title: Escalating SSRF to RCE
Link: https://medium.com/p/f28c482eb8b9
Date: Tue, 12 Mar 2019 22:55:12 GMT
Title: Escalating SSRF to RCE
Link: https://medium.com/p/f28c482eb8b9
Medium
Escalating SSRF to RCE
Escalating SSRF to RCE in AWS Elastic Beanstalk
New Writeup❗️
Date: Sun, 13 Jan 2019 17:56:21 GMT
Title: Hack Your Form — New vector for Blind XSS
Link: https://medium.com/p/da48eebd68a
Date: Sun, 13 Jan 2019 17:56:21 GMT
Title: Hack Your Form — New vector for Blind XSS
Link: https://medium.com/p/da48eebd68a
Medium
Hack Your Form — New vector for Blind XSS
Hello Pentesters,
New Writeup❗️
Date: Sun, 15 Apr 2018 17:01:54 GMT
Title: From InfoDisc to RCE to SOP Bypass
Link: https://medium.com/p/2d956b58796e
Date: Sun, 15 Apr 2018 17:01:54 GMT
Title: From InfoDisc to RCE to SOP Bypass
Link: https://medium.com/p/2d956b58796e
Medium
From InfoDisc to RCE to SOP Bypass
Hello Penetration Testers!
New Writeup❗️
Date: Thu, 23 Jun 2022 17:46:01 GMT
Title: Register form vulnerable to Stored XSS!
Link: https://medium.com/p/8259445df727
Date: Thu, 23 Jun 2022 17:46:01 GMT
Title: Register form vulnerable to Stored XSS!
Link: https://medium.com/p/8259445df727
Medium
Register form vulnerable to Stored XSS!
Hey Community !!
New Writeup❗️
Date: Fri, 11 Mar 2022 18:50:55 GMT
Title: Rate Limit Bypass at Readme.com
Link: https://medium.com/p/35c4fb0c7f85
Date: Fri, 11 Mar 2022 18:50:55 GMT
Title: Rate Limit Bypass at Readme.com
Link: https://medium.com/p/35c4fb0c7f85
Medium
Rate Limit Bypass at Readme.com
Hey Community !!
New Writeup❗️
Date: Thu, 03 Dec 2020 11:17:35 GMT
Title: भारतेन्दु युग
Link: https://medium.com/p/46c0d79434b1
Date: Thu, 03 Dec 2020 11:17:35 GMT
Title: भारतेन्दु युग
Link: https://medium.com/p/46c0d79434b1
Medium
भारतेन्दु युगीन पत्र पत्रिकाएं एवं हिंदी प्रदीप
2 ब्राह्मण पटरीका — https://drive.google.com/file/d/13KKhhCarkK3__c5boaEGVlf96-Kag_B0/view?usp=sharing
New Writeup❗️
Date: Tue, 05 Feb 2019 05:39:23 GMT
Title: How I hacked 40,000 user accounts of Microsoft using 2FA bypass(outlook.live.com).
Link: https://medium.com/p/13258785ec2f
Date: Tue, 05 Feb 2019 05:39:23 GMT
Title: How I hacked 40,000 user accounts of Microsoft using 2FA bypass(outlook.live.com).
Link: https://medium.com/p/13258785ec2f