New Writeup❗️
Date: Thu, 03 Dec 2020 08:17:51 GMT
Title: Leaking Credit card Activity in logs? Yes Sir!
Link: https://medium.com/p/b988bb6c0c2
Date: Thu, 03 Dec 2020 08:17:51 GMT
Title: Leaking Credit card Activity in logs? Yes Sir!
Link: https://medium.com/p/b988bb6c0c2
Medium
Leaking Credit card Activity in logs? Yes Sir!
Hello again, This is the easiest bug you can find while testing an android application. When you report it, you’re gonna be the problem…
New Writeup❗️
Date: Sat, 21 Nov 2020 13:26:21 GMT
Title: Weird (im)possible XSS on error page
Link: https://medium.com/p/a0b943ead41
Date: Sat, 21 Nov 2020 13:26:21 GMT
Title: Weird (im)possible XSS on error page
Link: https://medium.com/p/a0b943ead41
Medium
Weird (im)possible XSS on error page
Hello all,
New Writeup❗️
Date: Mon, 09 Jan 2023 13:27:14 GMT
Title: Hacking Hackers for fun and profit
Link: https://medium.com/p/784e6c7897e8
Date: Mon, 09 Jan 2023 13:27:14 GMT
Title: Hacking Hackers for fun and profit
Link: https://medium.com/p/784e6c7897e8
Medium
Hacking Hackers for fun and profit
This story will be in several parts. In each of the situations, I had to face unexpected results. By and large, these are stories that have…
New Writeup❗️
Date: Fri, 19 Nov 2021 08:02:47 GMT
Title: How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Link: https://medium.com/p/d4ff8e7dbef1
Date: Fri, 19 Nov 2021 08:02:47 GMT
Title: How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Link: https://medium.com/p/d4ff8e7dbef1
Medium
How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Below you will learn in detail about the discovered vulnerability that allowed me to get about 15000$ in bounty with all secrets from the…
New Writeup❗️
Date: Tue, 13 Jul 2021 18:52:54 GMT
Title: Credential stuffing in Bug bounty hunting
Link: https://medium.com/p/7168dc1d3153
Date: Tue, 13 Jul 2021 18:52:54 GMT
Title: Credential stuffing in Bug bounty hunting
Link: https://medium.com/p/7168dc1d3153
Medium
Credential stuffing in Bug bounty hunting
Bug hunting is not always about looking for classic vulnerabilities (XSS, SQLi, SSRF, RCE, etc). Sometimes it is a search for a new problem…
New Writeup❗️
Date: Thu, 07 Jan 2021 09:33:09 GMT
Title: $10,000 for a vulnerability that doesn’t exist
Link: https://medium.com/p/9dbc63684e94
Date: Thu, 07 Jan 2021 09:33:09 GMT
Title: $10,000 for a vulnerability that doesn’t exist
Link: https://medium.com/p/9dbc63684e94
Medium
$10,000 for a vulnerability that doesn’t exist
A couple of months ago, an interesting story happened to me. I caught a Path Traversal issue with no chance to reproduce it again.
New Writeup❗️
Date: Wed, 03 Jun 2020 13:17:09 GMT
Title: From CRLF to Account Takeover
Link: https://medium.com/p/a94d7aa0d74e
Date: Wed, 03 Jun 2020 13:17:09 GMT
Title: From CRLF to Account Takeover
Link: https://medium.com/p/a94d7aa0d74e
Medium
From CRLF to Account Takeover
At the beginning of March,while researching one site I discovered the new functionality. The functionality allowed the user to login via…
New Writeup❗️
Date: Fri, 28 May 2021 23:28:53 GMT
Title: The beauty of chaining client-side bugs
Link: https://medium.com/p/759e1091eabf
Date: Fri, 28 May 2021 23:28:53 GMT
Title: The beauty of chaining client-side bugs
Link: https://medium.com/p/759e1091eabf
Medium
The beauty of chaining client-side bugs
This is part of a report of a bug that I sent back in 2020, changing of course the program name for obvious reasons.
New Writeup❗️
Date: Sat, 14 Dec 2019 03:49:41 GMT
Title: Weaponizing BURP to work as an evil SSRF Confluence Server.
Link: https://medium.com/p/e077d71b4ef2
Date: Sat, 14 Dec 2019 03:49:41 GMT
Title: Weaponizing BURP to work as an evil SSRF Confluence Server.
Link: https://medium.com/p/e077d71b4ef2
Medium
Weaponizing BURP to work as an evil SSRF Confluence Server.
I was doing bounty on a private H1 program that interacts with various external services one of them was Atlassian Confluence and Jira.
New Writeup❗️
Date: Fri, 11 Oct 2019 15:45:05 GMT
Title: Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Link: https://medium.com/p/daf7a82673ce
Date: Fri, 11 Oct 2019 15:45:05 GMT
Title: Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Link: https://medium.com/p/daf7a82673ce
Medium
Bypass Uppercase filters like a PRO (XSS Advanced Methods)
While we are not working on Pentesting for companies, we love to Bug Hunting on Hackerone.
New Writeup❗️
Date: Tue, 03 May 2022 19:16:45 GMT
Title: How I got a lousyT-Shirt from the Dutch Goverment.
Link: https://medium.com/p/2a0d13fe7675
Date: Tue, 03 May 2022 19:16:45 GMT
Title: How I got a lousyT-Shirt from the Dutch Goverment.
Link: https://medium.com/p/2a0d13fe7675
Medium
How I got a lousyT-Shirt from the Dutch Goverment.
Hello everyone,
my name is Max. I’m a Computer Science student and ethical hacker from Germany. Today I want to tell you how I hacked the…
my name is Max. I’m a Computer Science student and ethical hacker from Germany. Today I want to tell you how I hacked the…
New Writeup❗️
Date: Fri, 07 Oct 2022 16:37:05 GMT
Title: Insecure Comments
Link: https://medium.com/p/73399193f804
Date: Fri, 07 Oct 2022 16:37:05 GMT
Title: Insecure Comments
Link: https://medium.com/p/73399193f804
Medium
Insecure Comments
Hi All,
New Writeup❗️
Date: Thu, 28 Jul 2022 21:01:19 GMT
Title: Reading Message from Microsoft’s Private Yammer Group
Link: https://medium.com/p/6be844639bca
Date: Thu, 28 Jul 2022 21:01:19 GMT
Title: Reading Message from Microsoft’s Private Yammer Group
Link: https://medium.com/p/6be844639bca
Medium
Reading Message from Microsoft’s Private Yammer Group
Hi All,
New Writeup❗️
Date: Fri, 18 Mar 2022 19:24:09 GMT
Title: Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Link: https://medium.com/p/bed3b45e509
Date: Fri, 18 Mar 2022 19:24:09 GMT
Title: Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Link: https://medium.com/p/bed3b45e509
Medium
Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Hi Everyone,
New Writeup❗️
Date: Wed, 15 Dec 2021 22:06:28 GMT
Title: Broken Access Control
Link: https://medium.com/p/cc6cfd793b15
Date: Wed, 15 Dec 2021 22:06:28 GMT
Title: Broken Access Control
Link: https://medium.com/p/cc6cfd793b15
Medium
Broken Access Control
Part 0x01 | Improper Authorization could allow access to more than 100,000 Microsoft Dynamics 365 for Partner Users
New Writeup❗️
Date: Wed, 31 Aug 2022 11:45:56 GMT
Title: Saving 100,000 websites from a Watering Hole attack
Link: https://medium.com/p/a22f63a37f94
Date: Wed, 31 Aug 2022 11:45:56 GMT
Title: Saving 100,000 websites from a Watering Hole attack
Link: https://medium.com/p/a22f63a37f94
Medium
Saving 100,000 websites from a Watering Hole attack
Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects…
New Writeup❗️
Date: Wed, 20 Oct 2021 03:53:54 GMT
Title: From staging to 0 click account takeover
Link: https://medium.com/p/528a5ecaa3eb
Date: Wed, 20 Oct 2021 03:53:54 GMT
Title: From staging to 0 click account takeover
Link: https://medium.com/p/528a5ecaa3eb
Medium
From staging to 0 click account takeover
Often, as bug bounty hunters or pentesters, while doing our recon on a specific target, we come accross their staging or pre-production…
New Writeup❗️
Date: Thu, 18 Mar 2021 18:20:36 GMT
Title: Chaining bugs for the greater good
Link: https://medium.com/p/664412ae85f8
Date: Thu, 18 Mar 2021 18:20:36 GMT
Title: Chaining bugs for the greater good
Link: https://medium.com/p/664412ae85f8
Medium
Chaining bugs for the greater good
Hello internet hustlers ! After a while of going back and forth with myself, I have finally decided to start publishing some writeups…
New Writeup❗️
Date: Thu, 17 Nov 2022 04:43:09 GMT
Title: Information Exposure — My Fourth Finding on Hackerone!
Link: https://medium.com/p/4fc4461920c4
Date: Thu, 17 Nov 2022 04:43:09 GMT
Title: Information Exposure — My Fourth Finding on Hackerone!
Link: https://medium.com/p/4fc4461920c4
Medium
Information Exposure — My Fourth Finding on Hackerone!
Information Exposure Through Directory Listing — The bug title says everything about it. Find a path or URL on any website that's enable…
New Writeup❗️
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Medium
Improper Access Control — My Third Finding on HackerOne!
Improper Access Control means web application or software functions does not restrict or incorrectly restricts access and usage to any…