New Writeup❗️
Date: Mon, 09 Jan 2023 13:27:14 GMT
Title: Hacking Hackers for fun and profit
Link: https://medium.com/p/784e6c7897e8
Date: Mon, 09 Jan 2023 13:27:14 GMT
Title: Hacking Hackers for fun and profit
Link: https://medium.com/p/784e6c7897e8
Medium
Hacking Hackers for fun and profit
This story will be in several parts. In each of the situations, I had to face unexpected results. By and large, these are stories that have…
New Writeup❗️
Date: Fri, 19 Nov 2021 08:02:47 GMT
Title: How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Link: https://medium.com/p/d4ff8e7dbef1
Date: Fri, 19 Nov 2021 08:02:47 GMT
Title: How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Link: https://medium.com/p/d4ff8e7dbef1
Medium
How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud
Below you will learn in detail about the discovered vulnerability that allowed me to get about 15000$ in bounty with all secrets from the…
New Writeup❗️
Date: Tue, 13 Jul 2021 18:52:54 GMT
Title: Credential stuffing in Bug bounty hunting
Link: https://medium.com/p/7168dc1d3153
Date: Tue, 13 Jul 2021 18:52:54 GMT
Title: Credential stuffing in Bug bounty hunting
Link: https://medium.com/p/7168dc1d3153
Medium
Credential stuffing in Bug bounty hunting
Bug hunting is not always about looking for classic vulnerabilities (XSS, SQLi, SSRF, RCE, etc). Sometimes it is a search for a new problem…
New Writeup❗️
Date: Thu, 07 Jan 2021 09:33:09 GMT
Title: $10,000 for a vulnerability that doesn’t exist
Link: https://medium.com/p/9dbc63684e94
Date: Thu, 07 Jan 2021 09:33:09 GMT
Title: $10,000 for a vulnerability that doesn’t exist
Link: https://medium.com/p/9dbc63684e94
Medium
$10,000 for a vulnerability that doesn’t exist
A couple of months ago, an interesting story happened to me. I caught a Path Traversal issue with no chance to reproduce it again.
New Writeup❗️
Date: Wed, 03 Jun 2020 13:17:09 GMT
Title: From CRLF to Account Takeover
Link: https://medium.com/p/a94d7aa0d74e
Date: Wed, 03 Jun 2020 13:17:09 GMT
Title: From CRLF to Account Takeover
Link: https://medium.com/p/a94d7aa0d74e
Medium
From CRLF to Account Takeover
At the beginning of March,while researching one site I discovered the new functionality. The functionality allowed the user to login via…
New Writeup❗️
Date: Fri, 28 May 2021 23:28:53 GMT
Title: The beauty of chaining client-side bugs
Link: https://medium.com/p/759e1091eabf
Date: Fri, 28 May 2021 23:28:53 GMT
Title: The beauty of chaining client-side bugs
Link: https://medium.com/p/759e1091eabf
Medium
The beauty of chaining client-side bugs
This is part of a report of a bug that I sent back in 2020, changing of course the program name for obvious reasons.
New Writeup❗️
Date: Sat, 14 Dec 2019 03:49:41 GMT
Title: Weaponizing BURP to work as an evil SSRF Confluence Server.
Link: https://medium.com/p/e077d71b4ef2
Date: Sat, 14 Dec 2019 03:49:41 GMT
Title: Weaponizing BURP to work as an evil SSRF Confluence Server.
Link: https://medium.com/p/e077d71b4ef2
Medium
Weaponizing BURP to work as an evil SSRF Confluence Server.
I was doing bounty on a private H1 program that interacts with various external services one of them was Atlassian Confluence and Jira.
New Writeup❗️
Date: Fri, 11 Oct 2019 15:45:05 GMT
Title: Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Link: https://medium.com/p/daf7a82673ce
Date: Fri, 11 Oct 2019 15:45:05 GMT
Title: Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Link: https://medium.com/p/daf7a82673ce
Medium
Bypass Uppercase filters like a PRO (XSS Advanced Methods)
While we are not working on Pentesting for companies, we love to Bug Hunting on Hackerone.
New Writeup❗️
Date: Tue, 03 May 2022 19:16:45 GMT
Title: How I got a lousyT-Shirt from the Dutch Goverment.
Link: https://medium.com/p/2a0d13fe7675
Date: Tue, 03 May 2022 19:16:45 GMT
Title: How I got a lousyT-Shirt from the Dutch Goverment.
Link: https://medium.com/p/2a0d13fe7675
Medium
How I got a lousyT-Shirt from the Dutch Goverment.
Hello everyone,
my name is Max. I’m a Computer Science student and ethical hacker from Germany. Today I want to tell you how I hacked the…
my name is Max. I’m a Computer Science student and ethical hacker from Germany. Today I want to tell you how I hacked the…
New Writeup❗️
Date: Fri, 07 Oct 2022 16:37:05 GMT
Title: Insecure Comments
Link: https://medium.com/p/73399193f804
Date: Fri, 07 Oct 2022 16:37:05 GMT
Title: Insecure Comments
Link: https://medium.com/p/73399193f804
Medium
Insecure Comments
Hi All,
New Writeup❗️
Date: Thu, 28 Jul 2022 21:01:19 GMT
Title: Reading Message from Microsoft’s Private Yammer Group
Link: https://medium.com/p/6be844639bca
Date: Thu, 28 Jul 2022 21:01:19 GMT
Title: Reading Message from Microsoft’s Private Yammer Group
Link: https://medium.com/p/6be844639bca
Medium
Reading Message from Microsoft’s Private Yammer Group
Hi All,
New Writeup❗️
Date: Fri, 18 Mar 2022 19:24:09 GMT
Title: Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Link: https://medium.com/p/bed3b45e509
Date: Fri, 18 Mar 2022 19:24:09 GMT
Title: Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Link: https://medium.com/p/bed3b45e509
Medium
Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Hi Everyone,
New Writeup❗️
Date: Wed, 15 Dec 2021 22:06:28 GMT
Title: Broken Access Control
Link: https://medium.com/p/cc6cfd793b15
Date: Wed, 15 Dec 2021 22:06:28 GMT
Title: Broken Access Control
Link: https://medium.com/p/cc6cfd793b15
Medium
Broken Access Control
Part 0x01 | Improper Authorization could allow access to more than 100,000 Microsoft Dynamics 365 for Partner Users
New Writeup❗️
Date: Wed, 31 Aug 2022 11:45:56 GMT
Title: Saving 100,000 websites from a Watering Hole attack
Link: https://medium.com/p/a22f63a37f94
Date: Wed, 31 Aug 2022 11:45:56 GMT
Title: Saving 100,000 websites from a Watering Hole attack
Link: https://medium.com/p/a22f63a37f94
Medium
Saving 100,000 websites from a Watering Hole attack
Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects…
New Writeup❗️
Date: Wed, 20 Oct 2021 03:53:54 GMT
Title: From staging to 0 click account takeover
Link: https://medium.com/p/528a5ecaa3eb
Date: Wed, 20 Oct 2021 03:53:54 GMT
Title: From staging to 0 click account takeover
Link: https://medium.com/p/528a5ecaa3eb
Medium
From staging to 0 click account takeover
Often, as bug bounty hunters or pentesters, while doing our recon on a specific target, we come accross their staging or pre-production…
New Writeup❗️
Date: Thu, 18 Mar 2021 18:20:36 GMT
Title: Chaining bugs for the greater good
Link: https://medium.com/p/664412ae85f8
Date: Thu, 18 Mar 2021 18:20:36 GMT
Title: Chaining bugs for the greater good
Link: https://medium.com/p/664412ae85f8
Medium
Chaining bugs for the greater good
Hello internet hustlers ! After a while of going back and forth with myself, I have finally decided to start publishing some writeups…
New Writeup❗️
Date: Thu, 17 Nov 2022 04:43:09 GMT
Title: Information Exposure — My Fourth Finding on Hackerone!
Link: https://medium.com/p/4fc4461920c4
Date: Thu, 17 Nov 2022 04:43:09 GMT
Title: Information Exposure — My Fourth Finding on Hackerone!
Link: https://medium.com/p/4fc4461920c4
Medium
Information Exposure — My Fourth Finding on Hackerone!
Information Exposure Through Directory Listing — The bug title says everything about it. Find a path or URL on any website that's enable…
New Writeup❗️
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Medium
Improper Access Control — My Third Finding on HackerOne!
Improper Access Control means web application or software functions does not restrict or incorrectly restricts access and usage to any…
New Writeup❗️
Date: Sun, 23 Oct 2022 11:28:54 GMT
Title: Broken Link Hijacking — My Second Finding on Hackerone!
Link: https://medium.com/p/d715b0713fca
Date: Sun, 23 Oct 2022 11:28:54 GMT
Title: Broken Link Hijacking — My Second Finding on Hackerone!
Link: https://medium.com/p/d715b0713fca
Medium
Broken Link Hijacking — My Second Finding on Hackerone!
Broken Link Hijacking (BLH) or Link Takeover, whatever you called it, the concept is very simple. If you get any broken links of any…
New Writeup❗️
Date: Fri, 21 Oct 2022 05:10:56 GMT
Title: Information Disclosure — My First Finding on Hackerone!
Link: https://medium.com/p/e572cc07babb
Date: Fri, 21 Oct 2022 05:10:56 GMT
Title: Information Disclosure — My First Finding on Hackerone!
Link: https://medium.com/p/e572cc07babb
Medium
Information Disclosure — My First Finding on Hackerone!
Information Disclosure is a kind of bug that is not so hard to find but could has huge impact. Some time you could get a very sensitive…