New Writeup❗️
Date: Fri, 06 Jan 2023 11:12:28 GMT
Title: Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability
Link: https://medium.com/p/813d2a07a4ed
Date: Fri, 06 Jan 2023 11:12:28 GMT
Title: Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability
Link: https://medium.com/p/813d2a07a4ed
Medium
Identity-Aware Proxy Misconfiguration- Google Cloud Vulnerability
First, we need to know what Identity-Aware Proxy (IAP) is and how it works to exploit it…
New Writeup❗️
Date: Sun, 10 Jan 2021 15:37:35 GMT
Title: Unauthorized Access to OData Entities + $2K Bounty From Microsoft
Link: https://medium.com/p/e070b2ef88c2
Date: Sun, 10 Jan 2021 15:37:35 GMT
Title: Unauthorized Access to OData Entities + $2K Bounty From Microsoft
Link: https://medium.com/p/e070b2ef88c2
Medium
Unauthorized Access to OData Entities + $2K Bounty From Microsoft
Hi, this post is about one of the vulnerabilities I found from Microsoft.
New Writeup❗️
Date: Thu, 02 Mar 2023 07:52:41 GMT
Title: How I was able to get Account Takeover from Broken brute-force protection, multiple credentials per…
Link: https://medium.com/p/b90077e9a52f
Date: Thu, 02 Mar 2023 07:52:41 GMT
Title: How I was able to get Account Takeover from Broken brute-force protection, multiple credentials per…
Link: https://medium.com/p/b90077e9a52f
Medium
How I was able to get Account Takeover from Broken brute-force protection, multiple credentials per…
Hello everyone! Today, I wanna share with you how I was able to perform an Account Takeover through a broken brute-force protection with…
New Writeup❗️
Date: Sun, 18 Dec 2022 02:46:58 GMT
Title: How I was able to steal users credentials via Swagger UI DOM-XSS
Link: https://medium.com/p/e84255eb8c96
Date: Sun, 18 Dec 2022 02:46:58 GMT
Title: How I was able to steal users credentials via Swagger UI DOM-XSS
Link: https://medium.com/p/e84255eb8c96
Medium
How I was able to steal users credentials via Swagger UI DOM-XSS
Hello guys, today I’m gonna explain how i got DOM-XSS from Swagger-UI and exploit it to make HTML and JAVASCRIPT injections to create a…
New Writeup❗️
Date: Thu, 17 Feb 2022 14:55:59 GMT
Title: UP-SOLVING Combination Lock
Link: https://medium.com/p/a2422c22be1a
Date: Thu, 17 Feb 2022 14:55:59 GMT
Title: UP-SOLVING Combination Lock
Link: https://medium.com/p/a2422c22be1a
Medium
UP-SOLVING Combination Lock
Hi my name is Mohamed Reda , I'm a cyber security research, I'm studding stat/computer science at faculty of science Ain Shames university…
New Writeup❗️
Date: Mon, 31 Aug 2020 08:29:04 GMT
Title: A duplicate P1’s story.
Link: https://medium.com/p/89e2995530cb
Date: Mon, 31 Aug 2020 08:29:04 GMT
Title: A duplicate P1’s story.
Link: https://medium.com/p/89e2995530cb
Medium
A duplicate P1’s story.
Introduction
New Writeup❗️
Date: Tue, 25 Aug 2020 08:33:19 GMT
Title: How i found 3 SSRF in one day on different bug bounty targets.
Link: https://medium.com/p/62e91b4268f8
Date: Tue, 25 Aug 2020 08:33:19 GMT
Title: How i found 3 SSRF in one day on different bug bounty targets.
Link: https://medium.com/p/62e91b4268f8
Medium
How i found 3 SSRF in one day on different bug bounty targets
This blog is about how i approach a bug bounty target, and how i got 3 SSRF in 5–6 hours after choosing a target. I hope you will enjoy…
New Writeup❗️
Date: Fri, 14 Sep 2018 14:28:36 GMT
Title: Hacking your own antivirus for fun and profit (Safe browsing gone wrong)
Link: https://medium.com/p/365db9d1d3f7
Date: Fri, 14 Sep 2018 14:28:36 GMT
Title: Hacking your own antivirus for fun and profit (Safe browsing gone wrong)
Link: https://medium.com/p/365db9d1d3f7
Medium
Hacking your own antivirus for fun and profit (Safe browsing gone wrong)
Bullguard has a safe browsing feature to prevent their users from entering websites that contain malware, phishing or other malicious…
New Writeup❗️
Date: Tue, 01 Jan 2019 12:24:58 GMT
Title: A Curious Case From Little To Complete Email Verification Bypass
Link: https://medium.com/p/2c7570040e7e
Date: Tue, 01 Jan 2019 12:24:58 GMT
Title: A Curious Case From Little To Complete Email Verification Bypass
Link: https://medium.com/p/2c7570040e7e
Medium
A Curious Case From Little To Complete Email Verification Bypass
Implementing a secure email verification mechanism is easy to mess up. A slight mistake in validation can lead to minor issues or…
New Writeup❗️
Date: Fri, 12 Jun 2020 19:49:27 GMT
Title: DoS and BugBounties :A series of DoS attacks on HackerOne
Link: https://medium.com/p/9c8316e192c9
Date: Fri, 12 Jun 2020 19:49:27 GMT
Title: DoS and BugBounties :A series of DoS attacks on HackerOne
Link: https://medium.com/p/9c8316e192c9
Medium
DoS and BugBounties :A series of DoS attacks on HackerOne
Greetings, this is my first writeup and I will discuss a very common vulnerability that is so underrated everybody seems to ignore it…
New Writeup❗️
Date: Sun, 19 Feb 2023 07:37:56 GMT
Title: NFS: The Deep Dive into Vulnerability Assessment and Exploitation Techniques
Link: https://medium.com/p/41f19a380217
Date: Sun, 19 Feb 2023 07:37:56 GMT
Title: NFS: The Deep Dive into Vulnerability Assessment and Exploitation Techniques
Link: https://medium.com/p/41f19a380217
Medium
NFS: The Deep Dive into Vulnerability Assessment and Exploitation Techniques
Introduction:
New Writeup❗️
Date: Sun, 22 Jan 2023 13:24:36 GMT
Title: Chasing the Hackers: A Network Forensics Investigation
Link: https://medium.com/p/f0bee9bc34
Date: Sun, 22 Jan 2023 13:24:36 GMT
Title: Chasing the Hackers: A Network Forensics Investigation
Link: https://medium.com/p/f0bee9bc34
Medium
Chasing the Hackers: A Network Forensics Investigation
In this blog, I will be diving deep into the Chase challenge, a network forensic challenge where we uncover the hackers’ trail and gain…
New Writeup❗️
Date: Wed, 18 Jan 2023 19:00:19 GMT
Title: How I identified and reported vulnerabilities in Oracle and the rewards of responsible…
Link: https://medium.com/p/43ee5fea457f
Date: Wed, 18 Jan 2023 19:00:19 GMT
Title: How I identified and reported vulnerabilities in Oracle and the rewards of responsible…
Link: https://medium.com/p/43ee5fea457f
Medium
How I identified and reported vulnerabilities in Oracle and the rewards of responsible disclosure:From Backup Leak to Hall of Fame
Hello folks I hope you are doing well. I’m a Parag Bagul security Researcher and bug bounty hunter.
New Writeup❗️
Date: Sun, 15 Jan 2023 05:27:50 GMT
Title: Penetration Testing XML-RPC: Uncovering the Weaknesses
Link: https://medium.com/p/cda2acd14629
Date: Sun, 15 Jan 2023 05:27:50 GMT
Title: Penetration Testing XML-RPC: Uncovering the Weaknesses
Link: https://medium.com/p/cda2acd14629
Medium
Penetration Testing XML-RPC: Uncovering the Weaknesses
An Introduction to XML-RPC: Understanding the Basics of Remote Procedure Call
New Writeup❗️
Date: Wed, 11 Jan 2023 09:41:21 GMT
Title: Preventing Cross-Site Scripting (XSS) Attacks with the HTML Special Characters Function in PHP
Link: https://medium.com/p/1b9db17bcdb4
Date: Wed, 11 Jan 2023 09:41:21 GMT
Title: Preventing Cross-Site Scripting (XSS) Attacks with the HTML Special Characters Function in PHP
Link: https://medium.com/p/1b9db17bcdb4
Medium
Preventing Cross-Site Scripting (XSS) Attacks with the HTML Special Characters Function in PHP
Introduction:
New Writeup❗️
Date: Sun, 18 Sep 2022 14:17:06 GMT
Title: SSRF ATTACK LEADING TO AWS METADATA
Link: https://medium.com/p/e95155fa6c6f
Date: Sun, 18 Sep 2022 14:17:06 GMT
Title: SSRF ATTACK LEADING TO AWS METADATA
Link: https://medium.com/p/e95155fa6c6f
Medium
SSRF ATTACK LEADING TO AWS METADATA
Hello folks,
New Writeup❗️
Date: Sat, 10 Sep 2022 16:57:34 GMT
Title: How I was able to Bypass Philips Authentication
Link: https://medium.com/p/c3bd3e1df9ff
Date: Sat, 10 Sep 2022 16:57:34 GMT
Title: How I was able to Bypass Philips Authentication
Link: https://medium.com/p/c3bd3e1df9ff
Medium
How I was able to Bypass Philips Authentication
Hello folks I hope you are doing well. I’m a Parag Bagul security Researcher and bug bounty hunter.
New Writeup❗️
Date: Wed, 07 Sep 2022 11:54:06 GMT
Title: How I found Moodle Cross site scripting
Link: https://medium.com/p/459a1c9ad4d5
Date: Wed, 07 Sep 2022 11:54:06 GMT
Title: How I found Moodle Cross site scripting
Link: https://medium.com/p/459a1c9ad4d5
Medium
How I found Moodle Cross site scripting
Hello folks I hope you are doing well. I’m a Parag Bagul security Researcher and bug bounty hunter
New Writeup❗️
Date: Tue, 24 Dec 2019 18:25:16 GMT
Title: GraphQL IDOR leads to information disclosure
Link: https://medium.com/p/175eb560170d
Date: Tue, 24 Dec 2019 18:25:16 GMT
Title: GraphQL IDOR leads to information disclosure
Link: https://medium.com/p/175eb560170d
Medium
GraphQL IDOR leads to information disclosure
Hello World!, I’m Eshan Singh aka R0X4R. I’m here to share my recent findings on GraphQL IDOR (Insecure Direct Object Reference), which…
New Writeup❗️
Date: Wed, 30 Oct 2019 14:50:36 GMT
Title: GraphQL introspection leads to sensitive data disclosure.
Link: https://medium.com/p/714f1d9d9d4a
Date: Wed, 30 Oct 2019 14:50:36 GMT
Title: GraphQL introspection leads to sensitive data disclosure.
Link: https://medium.com/p/714f1d9d9d4a
Medium
GraphQL introspection leads to sensitive data disclosure.
GraphQL is a query language for APIs and a runtime for fulfilling those queries with your existing data. GraphQL provides a complete…