New Writeup❗️
Date: Sat, 17 Apr 2021 22:29:08 GMT
Title: (POC) Update business fyi message as Facebook page analyst
Link: https://medium.com/p/d36170fdede2
Date: Sat, 17 Apr 2021 22:29:08 GMT
Title: (POC) Update business fyi message as Facebook page analyst
Link: https://medium.com/p/d36170fdede2
Medium
(POC) Update business fyi message as Facebook page analyst
Description / Impact
New Writeup❗️
Date: Sat, 17 Apr 2021 20:10:00 GMT
Title: (POC) Remove any Facebook’s live video ($14,000 bounty)
Link: https://medium.com/p/70c8135b7b4c
Date: Sat, 17 Apr 2021 20:10:00 GMT
Title: (POC) Remove any Facebook’s live video ($14,000 bounty)
Link: https://medium.com/p/70c8135b7b4c
Medium
(POC) Remove any Facebook’s live video ($14,000 bounty)
Description / Impact
New Writeup❗️
Date: Tue, 22 Oct 2019 18:41:36 GMT
Title: (POC) Disclose members in any closed Facebook group
Link: https://medium.com/p/259783fa4bf
Date: Tue, 22 Oct 2019 18:41:36 GMT
Title: (POC) Disclose members in any closed Facebook group
Link: https://medium.com/p/259783fa4bf
Medium
(POC) Disclose members in any closed Facebook group
Description / Impact
New Writeup❗️
Date: Tue, 23 Feb 2021 02:53:52 GMT
Title: Privilege Escalation from Improper Access Control [Medium] — $700
Link: https://medium.com/p/51c44a3cb53f
Date: Tue, 23 Feb 2021 02:53:52 GMT
Title: Privilege Escalation from Improper Access Control [Medium] — $700
Link: https://medium.com/p/51c44a3cb53f
Medium
Privilege Escalation from Improper Access Control [Medium] — $700
I will be discussing how I was able to leverage an Improper Access Control Vulnerability to a Privilege Escalation Vulnerability on one…
New Writeup❗️
Date: Mon, 08 Feb 2021 16:39:32 GMT
Title: Strict Rate Limiting Policy Leads to Massive DoS
Link: https://medium.com/p/268b20d354c8
Date: Mon, 08 Feb 2021 16:39:32 GMT
Title: Strict Rate Limiting Policy Leads to Massive DoS
Link: https://medium.com/p/268b20d354c8
Medium
Strict Rate Limiting Policy Leads to Massive DoS
I will be discussing an interesting observation on how policies implemented on Auth Endpoint could backfire and turn into massive DoS…
New Writeup❗️
Date: Wed, 06 Jan 2021 23:37:23 GMT
Title: Stored XSS on Product Description [HIGH] — $400
Link: https://medium.com/p/2f078fd70fd2
Date: Wed, 06 Jan 2021 23:37:23 GMT
Title: Stored XSS on Product Description [HIGH] — $400
Link: https://medium.com/p/2f078fd70fd2
New Writeup❗️
Date: Mon, 21 Feb 2022 15:59:02 GMT
Title: Finding an unseen SQL Injection by bypassing escape functions in mysqljs/mysql
Link: https://medium.com/p/90b27f6542b4
Date: Mon, 21 Feb 2022 15:59:02 GMT
Title: Finding an unseen SQL Injection by bypassing escape functions in mysqljs/mysql
Link: https://medium.com/p/90b27f6542b4
Medium
Finding an unseen SQL Injection by bypassing escape functions in mysqljs/mysql
It was found that unexpected behaviors in the query’s escape function could cause a SQL injection in mysqljs/mysql
New Writeup❗️
Date: Mon, 21 Jun 2021 14:55:57 GMT
Title: CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Link: https://medium.com/p/e946bd69177a
Date: Mon, 21 Jun 2021 14:55:57 GMT
Title: CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Link: https://medium.com/p/e946bd69177a
Medium
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Hello, I’m Shiga( @Ga_ryo_ ), a security engineer at Flatt Security Inc.
New Writeup❗️
Date: Mon, 21 Jun 2021 06:34:48 GMT
Title: CVE-2020–15702 Race Condition vulnerability in handling of PID by apport
Link: https://medium.com/p/4047f2e00a67
Date: Mon, 21 Jun 2021 06:34:48 GMT
Title: CVE-2020–15702 Race Condition vulnerability in handling of PID by apport
Link: https://medium.com/p/4047f2e00a67
Medium
CVE-2020–15702 Race Condition vulnerability in handling of PID by apport
Note) It’s just an English version of previous post.
New Writeup❗️
Date: Tue, 24 Nov 2020 12:09:20 GMT
Title: How images on Github will leak your private information
Link: https://medium.com/p/88f3b563e7d9
Date: Tue, 24 Nov 2020 12:09:20 GMT
Title: How images on Github will leak your private information
Link: https://medium.com/p/88f3b563e7d9
Medium
How images on Github will leak your private information
I was browsing a github repository where a guy posted its food travel pictures and while the pics were very appetizing, my mind wondered…
New Writeup❗️
Date: Tue, 25 Jun 2019 19:01:01 GMT
Title: How I found my first bug bounty
Link: https://medium.com/p/f49463e9c2e4
Date: Tue, 25 Jun 2019 19:01:01 GMT
Title: How I found my first bug bounty
Link: https://medium.com/p/f49463e9c2e4
Medium
How I found my first bug bounty
A story about how not to search for bug bounties
New Writeup❗️
Date: Fri, 18 Jun 2021 05:09:19 GMT
Title: Breaking Application Logic To RCE
Link: https://medium.com/p/3292a69e006b
Date: Fri, 18 Jun 2021 05:09:19 GMT
Title: Breaking Application Logic To RCE
Link: https://medium.com/p/3292a69e006b
Medium
Breaking Application Logic To RCE
Hello Friends, My name is Ranjeet Singh and today I am going to share one of the interesting case of RCE.
New Writeup❗️
Date: Thu, 28 Jan 2021 09:18:42 GMT
Title: Host Header Injection To Account Takeover || How I have found and earned $$$$ with POC image
Link: https://medium.com/p/53c29b33e4d2
Date: Thu, 28 Jan 2021 09:18:42 GMT
Title: Host Header Injection To Account Takeover || How I have found and earned $$$$ with POC image
Link: https://medium.com/p/53c29b33e4d2
Medium
Host Header Injection To Account Takeover || How I have found and earned $$$$ with POC image
Hello Friends,My name is Ranjeet Singh and today I am going to explain what is host header injection, how you can find it and how I have…
New Writeup❗️
Date: Fri, 22 Jan 2021 04:58:06 GMT
Title: OAuth Misconfiguration | Working of OAuth | Types of vulnerabilities in it and how you can exploit…
Link: https://medium.com/p/38bbe566c468
Date: Fri, 22 Jan 2021 04:58:06 GMT
Title: OAuth Misconfiguration | Working of OAuth | Types of vulnerabilities in it and how you can exploit…
Link: https://medium.com/p/38bbe566c468
Medium
OAuth Misconfiguration | Working of OAuth | Types of vulnerabilities in it and how you can exploit…
Hello Security Researchers, My name is Ranjeet Singh and today I am going to explain what is OAuth, how you can find misconfiguration in…
New Writeup❗️
Date: Sun, 17 Jan 2021 10:26:11 GMT
Title: Strange Admin Panel Bypass Story | | Bug Bounty
Link: https://medium.com/p/5e618099baaf
Date: Sun, 17 Jan 2021 10:26:11 GMT
Title: Strange Admin Panel Bypass Story | | Bug Bounty
Link: https://medium.com/p/5e618099baaf
Medium
Strange Admin Panel Bypass Story | | Bug Bounty
Hello Friends, My name is Ranjeet Singh and currently I am pursuing B-Tech from LPU and a part time bug hunter. I am doing bug hunting…
New Writeup❗️
Date: Sat, 03 Jul 2021 02:19:25 GMT
Title: View Other User Private Livestream Data
Link: https://medium.com/p/e30a0acb5972
Date: Sat, 03 Jul 2021 02:19:25 GMT
Title: View Other User Private Livestream Data
Link: https://medium.com/p/e30a0acb5972
Medium
View Other User Private Livestream Data
بِسْمِ للَّٰهِ لرَّحْمَٰنِ لرَّحِيمِ
New Writeup❗️
Date: Sun, 28 Feb 2021 12:01:49 GMT
Title: Join Facebook Group With Unpublish Page
Link: https://medium.com/p/cb649a20fb0e
Date: Sun, 28 Feb 2021 12:01:49 GMT
Title: Join Facebook Group With Unpublish Page
Link: https://medium.com/p/cb649a20fb0e
Medium
Join Facebook Group With Unpublish Page
Publish a page without publishing it
New Writeup❗️
Date: Wed, 06 Apr 2022 18:10:39 GMT
Title: How i got access to 1600k Users PII Data $$$$
Link: https://medium.com/p/64a27a540963
Date: Wed, 06 Apr 2022 18:10:39 GMT
Title: How i got access to 1600k Users PII Data $$$$
Link: https://medium.com/p/64a27a540963
Medium
How i got access to 1600k Users PII Data $$$$
Hello Guys 👋 I am Gokul, Python developer, Cyber security researcher, Part time Bug hunter and Open source tool maker, Studying 3rd year…
New Writeup❗️
Date: Sun, 24 Jan 2021 07:37:53 GMT
Title: Sql Injection via hidden parameter
Link: https://medium.com/p/6da7699248fc
Date: Sun, 24 Jan 2021 07:37:53 GMT
Title: Sql Injection via hidden parameter
Link: https://medium.com/p/6da7699248fc
Medium
Sql Injection via hidden parameter
Hello Everyone, I am Rutvik Hajare and I am new in the cyber field.This is my first write-up on one of critical findings. usually i hate…
🗿1
New Writeup❗️
Date: Thu, 29 Dec 2022 15:11:15 GMT
Title: How I got a Bug At Apple that lead’s to takeover accounts of any user who view my profile
Link: https://medium.com/p/913c8704f6cd
Date: Thu, 29 Dec 2022 15:11:15 GMT
Title: How I got a Bug At Apple that lead’s to takeover accounts of any user who view my profile
Link: https://medium.com/p/913c8704f6cd
Medium
How I got a Bug At Apple that lead’s to takeover accounts of any user who view my profile
Hi Team Iam Abdelkader Mouaz my pseudo is Hamzadzworm today i will share with you a Bug That Lead To Takeover account of any user just if…