New Writeup❗️
Date: Fri, 10 Jul 2020 14:58:45 GMT
Title: Open-redirection leads to a bounty
Link: https://medium.com/p/d94029e11d17
Date: Fri, 10 Jul 2020 14:58:45 GMT
Title: Open-redirection leads to a bounty
Link: https://medium.com/p/d94029e11d17
Medium
Open-redirection leads to a bounty
Hey guys Pratik this side. In this writeup, I’m going to share some of my open-redirection hunts and what resources I use to find…
New Writeup❗️
Date: Fri, 06 Jan 2023 11:12:28 GMT
Title: Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability
Link: https://medium.com/p/813d2a07a4ed
Date: Fri, 06 Jan 2023 11:12:28 GMT
Title: Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability
Link: https://medium.com/p/813d2a07a4ed
Medium
Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability
First, we need to know what Identity-Aware Proxy (IAP) is and how it works to exploit it…
New Writeup❗️
Date: Sun, 10 Jan 2021 15:37:35 GMT
Title: Unauthorized Access to OData Entities + $2K Bounty From Microsoft
Link: https://medium.com/p/e070b2ef88c2
Date: Sun, 10 Jan 2021 15:37:35 GMT
Title: Unauthorized Access to OData Entities + $2K Bounty From Microsoft
Link: https://medium.com/p/e070b2ef88c2
Medium
Unauthorized Access to OData Entities + $2K Bounty From Microsoft
Hi, this post is about one of the vulnerabilities I found from Microsoft.
New Writeup❗️
Date: Thu, 02 Mar 2023 07:52:41 GMT
Title: How I was able to get Account Takeover from Broken brute-force protection, multiple credentials per…
Link: https://medium.com/p/b90077e9a52f
Date: Thu, 02 Mar 2023 07:52:41 GMT
Title: How I was able to get Account Takeover from Broken brute-force protection, multiple credentials per…
Link: https://medium.com/p/b90077e9a52f
Medium
How I was able to get Account Takeover from Broken brute-force protection, multiple credentials per…
Hello everyone! Today, I wanna share with you how I was able to perform an Account Takeover through a broken brute-force protection with…
New Writeup❗️
Date: Sun, 18 Dec 2022 02:46:58 GMT
Title: How I was able to steal users credentials via Swagger UI DOM-XSS
Link: https://medium.com/p/e84255eb8c96
Date: Sun, 18 Dec 2022 02:46:58 GMT
Title: How I was able to steal users credentials via Swagger UI DOM-XSS
Link: https://medium.com/p/e84255eb8c96
Medium
How I was able to steal users credentials via Swagger UI DOM-XSS
Hello guys, today I’m gonna explain how i got DOM-XSS from Swagger-UI and exploit it to make HTML and JAVASCRIPT injections to create a…
New Writeup❗️
Date: Thu, 17 Feb 2022 14:55:59 GMT
Title: UP-SOLVING Combination Lock
Link: https://medium.com/p/a2422c22be1a
Date: Thu, 17 Feb 2022 14:55:59 GMT
Title: UP-SOLVING Combination Lock
Link: https://medium.com/p/a2422c22be1a
Medium
UP-SOLVING Combination Lock
Hi my name is Mohamed Reda , I'm a cyber security research, I'm studding stat/computer science at faculty of science Ain Shames university…
New Writeup❗️
Date: Mon, 31 Aug 2020 08:29:04 GMT
Title: A duplicate P1’s story.
Link: https://medium.com/p/89e2995530cb
Date: Mon, 31 Aug 2020 08:29:04 GMT
Title: A duplicate P1’s story.
Link: https://medium.com/p/89e2995530cb
Medium
A duplicate P1’s story.
Introduction
New Writeup❗️
Date: Tue, 25 Aug 2020 08:33:19 GMT
Title: How i found 3 SSRF in one day on different bug bounty targets.
Link: https://medium.com/p/62e91b4268f8
Date: Tue, 25 Aug 2020 08:33:19 GMT
Title: How i found 3 SSRF in one day on different bug bounty targets.
Link: https://medium.com/p/62e91b4268f8
Medium
How i found 3 SSRF in one day on different bug bounty targets
This blog is about how i approach a bug bounty target, and how i got 3 SSRF in 5–6 hours after choosing a target. I hope you will enjoy…
New Writeup❗️
Date: Fri, 14 Sep 2018 14:28:36 GMT
Title: Hacking your own antivirus for fun and profit (Safe browsing gone wrong)
Link: https://medium.com/p/365db9d1d3f7
Date: Fri, 14 Sep 2018 14:28:36 GMT
Title: Hacking your own antivirus for fun and profit (Safe browsing gone wrong)
Link: https://medium.com/p/365db9d1d3f7
Medium
Hacking your own antivirus for fun and profit (Safe browsing gone wrong)
Bullguard has a safe browsing feature to prevent their users from entering websites that contain malware, phishing or other malicious…
New Writeup❗️
Date: Tue, 01 Jan 2019 12:24:58 GMT
Title: A Curious Case From Little To Complete Email Verification Bypass
Link: https://medium.com/p/2c7570040e7e
Date: Tue, 01 Jan 2019 12:24:58 GMT
Title: A Curious Case From Little To Complete Email Verification Bypass
Link: https://medium.com/p/2c7570040e7e
Medium
A Curious Case From Little To Complete Email Verification Bypass
Implementing a secure email verification mechanism is easy to mess up. A slight mistake in validation can lead to minor issues or…
New Writeup❗️
Date: Fri, 12 Jun 2020 19:49:27 GMT
Title: DoS and BugBounties :A series of DoS attacks on HackerOne
Link: https://medium.com/p/9c8316e192c9
Date: Fri, 12 Jun 2020 19:49:27 GMT
Title: DoS and BugBounties :A series of DoS attacks on HackerOne
Link: https://medium.com/p/9c8316e192c9
Medium
DoS and BugBounties :A series of DoS attacks on HackerOne
Greetings, this is my first writeup and I will discuss a very common vulnerability that is so underrated everybody seems to ignore it…
New Writeup❗️
Date: Sun, 19 Feb 2023 07:37:56 GMT
Title: NFS: The Deep Dive into Vulnerability Assessment and Exploitation Techniques
Link: https://medium.com/p/41f19a380217
Date: Sun, 19 Feb 2023 07:37:56 GMT
Title: NFS: The Deep Dive into Vulnerability Assessment and Exploitation Techniques
Link: https://medium.com/p/41f19a380217
Medium
NFS: The Deep Dive into Vulnerability Assessment and Exploitation Techniques
Introduction:
New Writeup❗️
Date: Sun, 22 Jan 2023 13:24:36 GMT
Title: Chasing the Hackers: A Network Forensics Investigation
Link: https://medium.com/p/f0bee9bc34
Date: Sun, 22 Jan 2023 13:24:36 GMT
Title: Chasing the Hackers: A Network Forensics Investigation
Link: https://medium.com/p/f0bee9bc34
Medium
Chasing the Hackers: A Network Forensics Investigation
In this blog, I will be diving deep into the Chase challenge, a network forensic challenge where we uncover the hackers’ trail and gain…
New Writeup❗️
Date: Wed, 18 Jan 2023 19:00:19 GMT
Title: How I identified and reported vulnerabilities in Oracle and the rewards of responsible…
Link: https://medium.com/p/43ee5fea457f
Date: Wed, 18 Jan 2023 19:00:19 GMT
Title: How I identified and reported vulnerabilities in Oracle and the rewards of responsible…
Link: https://medium.com/p/43ee5fea457f
Medium
How I identified and reported vulnerabilities in Oracle and the rewards of responsible disclosure:From Backup Leak to Hall of Fame
Hello folks I hope you are doing well. I’m a Parag Bagul security Researcher and bug bounty hunter.
New Writeup❗️
Date: Sun, 15 Jan 2023 05:27:50 GMT
Title: Penetration Testing XML-RPC: Uncovering the Weaknesses
Link: https://medium.com/p/cda2acd14629
Date: Sun, 15 Jan 2023 05:27:50 GMT
Title: Penetration Testing XML-RPC: Uncovering the Weaknesses
Link: https://medium.com/p/cda2acd14629
Medium
Penetration Testing XML-RPC: Uncovering the Weaknesses
An Introduction to XML-RPC: Understanding the Basics of Remote Procedure Call
New Writeup❗️
Date: Wed, 11 Jan 2023 09:41:21 GMT
Title: Preventing Cross-Site Scripting (XSS) Attacks with the HTML Special Characters Function in PHP
Link: https://medium.com/p/1b9db17bcdb4
Date: Wed, 11 Jan 2023 09:41:21 GMT
Title: Preventing Cross-Site Scripting (XSS) Attacks with the HTML Special Characters Function in PHP
Link: https://medium.com/p/1b9db17bcdb4
Medium
Preventing Cross-Site Scripting (XSS) Attacks with the HTML Special Characters Function in PHP
Introduction:
New Writeup❗️
Date: Sun, 18 Sep 2022 14:17:06 GMT
Title: SSRF ATTACK LEADING TO AWS METADATA
Link: https://medium.com/p/e95155fa6c6f
Date: Sun, 18 Sep 2022 14:17:06 GMT
Title: SSRF ATTACK LEADING TO AWS METADATA
Link: https://medium.com/p/e95155fa6c6f
Medium
SSRF ATTACK LEADING TO AWS METADATA
Hello folks,
New Writeup❗️
Date: Sat, 10 Sep 2022 16:57:34 GMT
Title: How I was able to Bypass Philips Authentication
Link: https://medium.com/p/c3bd3e1df9ff
Date: Sat, 10 Sep 2022 16:57:34 GMT
Title: How I was able to Bypass Philips Authentication
Link: https://medium.com/p/c3bd3e1df9ff
Medium
How I was able to Bypass Philips Authentication
Hello folks I hope you are doing well. I’m a Parag Bagul security Researcher and bug bounty hunter.
New Writeup❗️
Date: Wed, 07 Sep 2022 11:54:06 GMT
Title: How I found Moodle Cross site scripting
Link: https://medium.com/p/459a1c9ad4d5
Date: Wed, 07 Sep 2022 11:54:06 GMT
Title: How I found Moodle Cross site scripting
Link: https://medium.com/p/459a1c9ad4d5
Medium
How I found Moodle Cross site scripting
Hello folks I hope you are doing well. I’m a Parag Bagul security Researcher and bug bounty hunter
New Writeup❗️
Date: Tue, 24 Dec 2019 18:25:16 GMT
Title: GraphQL IDOR leads to information disclosure
Link: https://medium.com/p/175eb560170d
Date: Tue, 24 Dec 2019 18:25:16 GMT
Title: GraphQL IDOR leads to information disclosure
Link: https://medium.com/p/175eb560170d
Medium
GraphQL IDOR leads to information disclosure
Hello World!, I’m Eshan Singh aka R0X4R. I’m here to share my recent findings on GraphQL IDOR (Insecure Direct Object Reference), which…