New Writeup❗️
Date: Mon, 05 Apr 2021 12:01:32 GMT
Title: File Upload Leads to Stored XSS
Link: https://medium.com/p/1c0a43b07554
Date: Mon, 05 Apr 2021 12:01:32 GMT
Title: File Upload Leads to Stored XSS
Link: https://medium.com/p/1c0a43b07554
Medium
File Upload Leads to Stored XSS
A while ago I have written a post on “Unrestricted File Upload” by exploiting that bug I was able to upload any extension file, even…
New Writeup❗️
Date: Tue, 12 Jan 2021 03:47:46 GMT
Title: Unrestricted File Upload
Link: https://medium.com/p/e95e1c6fb80
Date: Tue, 12 Jan 2021 03:47:46 GMT
Title: Unrestricted File Upload
Link: https://medium.com/p/e95e1c6fb80
Medium
Unrestricted File Upload
I was testing on a website let’s call it “buggyweb.xyz”. After sometime i found that there was discussion forum which URL was something…
New Writeup❗️
Date: Wed, 18 Nov 2020 07:57:56 GMT
Title: No rate limit on the forgot password field.
Link: https://medium.com/p/bbefab1fdb47
Date: Wed, 18 Nov 2020 07:57:56 GMT
Title: No rate limit on the forgot password field.
Link: https://medium.com/p/bbefab1fdb47
Medium
No rate limit on the forgot password field.
Rate limiting is used to control the rate of requests sent or received and is used to prevent DoS attacks. Nowadays it is most to use the…
New Writeup❗️
Date: Wed, 27 Jan 2021 11:17:53 GMT
Title: $500 For No Rate Limit On Forgot Password Page
Link: https://medium.com/p/d534d1d750db
Date: Wed, 27 Jan 2021 11:17:53 GMT
Title: $500 For No Rate Limit On Forgot Password Page
Link: https://medium.com/p/d534d1d750db
Medium
$500 For No Rate Limit On Forgot Password Page
No Rate Limit on Forget Password page
New Writeup❗️
Date: Mon, 25 Jan 2021 07:14:58 GMT
Title: How Nepali Woman Finds bug in Facebook, Gets Awarded $3000
Link: https://medium.com/p/37f5209c6dec
Date: Mon, 25 Jan 2021 07:14:58 GMT
Title: How Nepali Woman Finds bug in Facebook, Gets Awarded $3000
Link: https://medium.com/p/37f5209c6dec
Medium
How Nepali Woman Finds bug in Facebook, Gets Awarded $3000
Prava Basnet, Nepali bug bounty hunter has been awarded $3,000 after discovering bugs on Facebook. The bugs (security vulnerability) were…
New Writeup❗️
Date: Thu, 08 Jul 2021 18:15:56 GMT
Title: the pen is mightier than the sword. (in bug hunting)
Link: https://medium.com/p/11166beada06
Date: Thu, 08 Jul 2021 18:15:56 GMT
Title: the pen is mightier than the sword. (in bug hunting)
Link: https://medium.com/p/11166beada06
Medium
the pen is mightier than the sword. (in bug hunting)
Hey folks, This is Captain_hook from BC. actually, I started my career about 1 and a half years ago, and I decided to share some things…
New Writeup❗️
Date: Fri, 24 Jun 2022 13:38:46 GMT
Title: Writing your own Burpsuite Extensions: Complete Guide
Link: https://medium.com/p/cb7aba4dbceb
Date: Fri, 24 Jun 2022 13:38:46 GMT
Title: Writing your own Burpsuite Extensions: Complete Guide
Link: https://medium.com/p/cb7aba4dbceb
Medium
Writing your own Burpsuite Extensions: Complete Guide
Recently I had to create some extensions for Burpsuite. I tried finding resources that could help me but couldn’t find much. Most of them…
New Writeup❗️
Date: Sat, 20 Nov 2021 11:00:47 GMT
Title: Peeping through a Web-Socket
Link: https://medium.com/p/936ed55a2c31
Date: Sat, 20 Nov 2021 11:00:47 GMT
Title: Peeping through a Web-Socket
Link: https://medium.com/p/936ed55a2c31
Medium
Peeping through a Web-Socket
Recently, I had found a bug related to web sockets through which I was able to view all the messages being sent to the victim user.
New Writeup❗️
Date: Wed, 26 May 2021 12:51:44 GMT
Title: How I hacked a Target again and again…
Link: https://medium.com/p/6db2e462221f
Date: Wed, 26 May 2021 12:51:44 GMT
Title: How I hacked a Target again and again…
Link: https://medium.com/p/6db2e462221f
Medium
How I hacked a Target again and again…
This all started with a when I was hunting on a private program; I found a few subdomains of almost similar UI and requests but different…
New Writeup❗️
Date: Sat, 06 Mar 2021 17:36:43 GMT
Title: Exploiting a hidden and forgotten Bug
Link: https://medium.com/p/49ce7ad4de39
Date: Sat, 06 Mar 2021 17:36:43 GMT
Title: Exploiting a hidden and forgotten Bug
Link: https://medium.com/p/49ce7ad4de39
Medium
Exploiting a hidden and forgotten Bug
This writeup is about a bug that existed in HTML to PDF generation functionality in a program.
New Writeup❗️
Date: Fri, 26 Feb 2021 18:00:47 GMT
Title: The story of my First Bug
Link: https://medium.com/p/573c4f628bc0
Date: Fri, 26 Feb 2021 18:00:47 GMT
Title: The story of my First Bug
Link: https://medium.com/p/573c4f628bc0
Medium
The story of my First Bug
Just like other newbies, I had been practising on portswigger academy, feeding on writeups day in and day out waiting for my first valid…
New Writeup❗️
Date: Sun, 22 Nov 2020 07:31:59 GMT
Title: Escalating XSS to Account Takeover
Link: https://medium.com/p/ffde08624937
Date: Sun, 22 Nov 2020 07:31:59 GMT
Title: Escalating XSS to Account Takeover
Link: https://medium.com/p/ffde08624937
Medium
Escalating XSS to Account Takeover
Escalating a Reflected XSS to Account Takeover
New Writeup❗️
Date: Tue, 23 Aug 2022 19:30:34 GMT
Title: Making small things BIG
Link: https://medium.com/p/972cf772bb5a
Date: Tue, 23 Aug 2022 19:30:34 GMT
Title: Making small things BIG
Link: https://medium.com/p/972cf772bb5a
Medium
Making small things BIG
Hacking Salesforce sites.
New Writeup❗️
Date: Tue, 23 Aug 2022 12:30:50 GMT
Title: Finding Hidden Gems with Nuclei Templates!
Link: https://medium.com/p/b3125950a5cd
Date: Tue, 23 Aug 2022 12:30:50 GMT
Title: Finding Hidden Gems with Nuclei Templates!
Link: https://medium.com/p/b3125950a5cd
Medium
Finding Hidden Gems with Nuclei Templates!
Lately, I have been thinking about automation.
New Writeup❗️
Date: Fri, 19 Mar 2021 00:13:48 GMT
Title: How to Harpon Big Blue!
Link: https://medium.com/p/c163722638d8
Date: Fri, 19 Mar 2021 00:13:48 GMT
Title: How to Harpon Big Blue!
Link: https://medium.com/p/c163722638d8
Medium
How to Harpon Big Blue!
A story about creating backdoors in IBM’s Websphere Portal! This is a feature I’m told…
New Writeup❗️
Date: Thu, 11 Feb 2021 19:16:04 GMT
Title: The CVE That Will Never Die!
Link: https://medium.com/p/86149b450840
Date: Thu, 11 Feb 2021 19:16:04 GMT
Title: The CVE That Will Never Die!
Link: https://medium.com/p/86149b450840
Medium
The CVE That Will Never Die!
While exploring targets lately on Synack and HackerOne, I keep coming across this old CVE, it’s CVE-2016–0957. For those that don’t recall…
New Writeup❗️
Date: Tue, 14 Dec 2021 16:22:06 GMT
Title: My [CVE-2021–45043] LFI Write-up
Link: https://medium.com/p/441dad30dd7f
Date: Tue, 14 Dec 2021 16:22:06 GMT
Title: My [CVE-2021–45043] LFI Write-up
Link: https://medium.com/p/441dad30dd7f
Medium
My [CVE-2021–45043] LFI Write-up
Hey Hackers & Hunters,
New Writeup❗️
Date: Fri, 03 Dec 2021 15:32:50 GMT
Title: My mindset while hunting on Yandex and my SSRF
Link: https://medium.com/p/e19af20ed4d
Date: Fri, 03 Dec 2021 15:32:50 GMT
Title: My mindset while hunting on Yandex and my SSRF
Link: https://medium.com/p/e19af20ed4d
Medium
My mindset while hunting on Yandex and my SSRF
Hey hunters!
New Writeup❗️
Date: Tue, 30 Nov 2021 18:22:46 GMT
Title: How i was able to bypass Cloudflare WAF for SQLi payload
Link: https://medium.com/p/b9e7a4260026
Date: Tue, 30 Nov 2021 18:22:46 GMT
Title: How i was able to bypass Cloudflare WAF for SQLi payload
Link: https://medium.com/p/b9e7a4260026
Medium
How i was able to bypass Cloudflare WAF for SQLi payload
Bypassing Cloudflare for achieving SQL Injection
🗿1
New Writeup❗️
Date: Tue, 30 Nov 2021 17:22:13 GMT
Title: My write-up in hacking IBM’s administration panel and getting SQLi on it
Link: https://medium.com/p/51404c7bee27
Date: Tue, 30 Nov 2021 17:22:13 GMT
Title: My write-up in hacking IBM’s administration panel and getting SQLi on it
Link: https://medium.com/p/51404c7bee27
Medium
My write-up in hacking IBM’s administration panel and getting SQLi on it
Hi hackers and hunters!