New Writeup❗️
Date: Fri, 18 Mar 2022 19:24:09 GMT
Title: Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Link: https://medium.com/p/bed3b45e509
Date: Fri, 18 Mar 2022 19:24:09 GMT
Title: Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Link: https://medium.com/p/bed3b45e509
Medium
Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Hi Everyone,
New Writeup❗️
Date: Wed, 15 Dec 2021 22:06:28 GMT
Title: Broken Access Control
Link: https://medium.com/p/cc6cfd793b15
Date: Wed, 15 Dec 2021 22:06:28 GMT
Title: Broken Access Control
Link: https://medium.com/p/cc6cfd793b15
Medium
Broken Access Control
Part 0x01 | Improper Authorization could allow access to more than 100,000 Microsoft Dynamics 365 for Partner Users
New Writeup❗️
Date: Wed, 31 Aug 2022 11:45:56 GMT
Title: Saving 100,000 websites from a Watering Hole attack
Link: https://medium.com/p/a22f63a37f94
Date: Wed, 31 Aug 2022 11:45:56 GMT
Title: Saving 100,000 websites from a Watering Hole attack
Link: https://medium.com/p/a22f63a37f94
Medium
Saving 100,000 websites from a Watering Hole attack
Watering hole is a computer attack strategy in which an attacker guesses or observes which websites an organization often uses and infects…
New Writeup❗️
Date: Wed, 20 Oct 2021 03:53:54 GMT
Title: From staging to 0 click account takeover
Link: https://medium.com/p/528a5ecaa3eb
Date: Wed, 20 Oct 2021 03:53:54 GMT
Title: From staging to 0 click account takeover
Link: https://medium.com/p/528a5ecaa3eb
Medium
From staging to 0 click account takeover
Often, as bug bounty hunters or pentesters, while doing our recon on a specific target, we come accross their staging or pre-production…
New Writeup❗️
Date: Thu, 18 Mar 2021 18:20:36 GMT
Title: Chaining bugs for the greater good
Link: https://medium.com/p/664412ae85f8
Date: Thu, 18 Mar 2021 18:20:36 GMT
Title: Chaining bugs for the greater good
Link: https://medium.com/p/664412ae85f8
Medium
Chaining bugs for the greater good
Hello internet hustlers ! After a while of going back and forth with myself, I have finally decided to start publishing some writeups…
New Writeup❗️
Date: Thu, 17 Nov 2022 04:43:09 GMT
Title: Information Exposure — My Fourth Finding on Hackerone!
Link: https://medium.com/p/4fc4461920c4
Date: Thu, 17 Nov 2022 04:43:09 GMT
Title: Information Exposure — My Fourth Finding on Hackerone!
Link: https://medium.com/p/4fc4461920c4
Medium
Information Exposure — My Fourth Finding on Hackerone!
Information Exposure Through Directory Listing — The bug title says everything about it. Find a path or URL on any website that's enable…
New Writeup❗️
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Medium
Improper Access Control — My Third Finding on HackerOne!
Improper Access Control means web application or software functions does not restrict or incorrectly restricts access and usage to any…
New Writeup❗️
Date: Sun, 23 Oct 2022 11:28:54 GMT
Title: Broken Link Hijacking — My Second Finding on Hackerone!
Link: https://medium.com/p/d715b0713fca
Date: Sun, 23 Oct 2022 11:28:54 GMT
Title: Broken Link Hijacking — My Second Finding on Hackerone!
Link: https://medium.com/p/d715b0713fca
Medium
Broken Link Hijacking — My Second Finding on Hackerone!
Broken Link Hijacking (BLH) or Link Takeover, whatever you called it, the concept is very simple. If you get any broken links of any…
New Writeup❗️
Date: Fri, 21 Oct 2022 05:10:56 GMT
Title: Information Disclosure — My First Finding on Hackerone!
Link: https://medium.com/p/e572cc07babb
Date: Fri, 21 Oct 2022 05:10:56 GMT
Title: Information Disclosure — My First Finding on Hackerone!
Link: https://medium.com/p/e572cc07babb
Medium
Information Disclosure — My First Finding on Hackerone!
Information Disclosure is a kind of bug that is not so hard to find but could has huge impact. Some time you could get a very sensitive…
New Writeup❗️
Date: Wed, 05 Oct 2022 20:59:28 GMT
Title: Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
Link: https://medium.com/p/99b4a1723051
Date: Wed, 05 Oct 2022 20:59:28 GMT
Title: Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
Link: https://medium.com/p/99b4a1723051
Medium
Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
CrazyHD is one of the famous torrent website in Bangladesh and India. People get pirated movies , paid courses , softwares and more in…
New Writeup❗️
Date: Tue, 30 Aug 2022 11:03:42 GMT
Title: Found SQL Injection Vulnerability on Government Organization Website!
Link: https://medium.com/p/3eb33c0c49a4
Date: Tue, 30 Aug 2022 11:03:42 GMT
Title: Found SQL Injection Vulnerability on Government Organization Website!
Link: https://medium.com/p/3eb33c0c49a4
Medium
Found SQL Injection Vulnerability on Government Organization Website!
Last night before going to sleep i make a quick search on google a dork to find vulnerable websites and found some interesting result and…
🗿1
New Writeup❗️
Date: Tue, 07 Dec 2021 23:05:25 GMT
Title: Introduction : Who am I ?
Link: https://medium.com/p/f6bbcc6cf201
Date: Tue, 07 Dec 2021 23:05:25 GMT
Title: Introduction : Who am I ?
Link: https://medium.com/p/f6bbcc6cf201
Medium
Introduction : Who am I ?
Hey there, everyone! 👋 I’m Mehedi Shakeel, an IT security professional hailing from Bangladesh. With a solid background in ethical…
New Writeup❗️
Date: Mon, 07 Nov 2022 19:09:38 GMT
Title: How we ‘hacked’ Telenet’s cybersecurity quiz
Link: https://medium.com/p/958c1d3ee2ba
Date: Mon, 07 Nov 2022 19:09:38 GMT
Title: How we ‘hacked’ Telenet’s cybersecurity quiz
Link: https://medium.com/p/958c1d3ee2ba
Medium
How we ‘hacked’ Telenet’s cybersecurity quiz
Not so long ago, Telenet Business ran a quiz to find the smartest cyber specialist. The quiz consisted out of 20 questions and your score…
New Writeup❗️
Date: Fri, 03 Jun 2022 19:52:46 GMT
Title: Poppin’ shell with MSDT & PowerPoint
Link: https://medium.com/p/3fce5588e236
Date: Fri, 03 Jun 2022 19:52:46 GMT
Title: Poppin’ shell with MSDT & PowerPoint
Link: https://medium.com/p/3fce5588e236
Medium
Poppin’ shell with MSDT & PowerPoint
I’m assuming if you clicked, you’ve already heard about CVE-2022–30190. I won’t get into the details of it, but it’s a recent zero-day…
New Writeup❗️
Date: Thu, 13 Oct 2022 02:08:11 GMT
Title: Code flaws leads to Org/Admin Account Takeover
Link: https://medium.com/p/ad9515a96eab
Date: Thu, 13 Oct 2022 02:08:11 GMT
Title: Code flaws leads to Org/Admin Account Takeover
Link: https://medium.com/p/ad9515a96eab
Medium
Code flaws leads to Org/Admin Account Takeover
Hello Everyone, I’m Saransh Saraf and I’m back with another unique account takeover idea, so let’s just dive into it :)
New Writeup❗️
Date: Fri, 02 Sep 2022 04:20:07 GMT
Title: The Database Handover | A Dumb Mistake | Critical BUG
Link: https://medium.com/p/f73c99e72e40
Date: Fri, 02 Sep 2022 04:20:07 GMT
Title: The Database Handover | A Dumb Mistake | Critical BUG
Link: https://medium.com/p/f73c99e72e40
Medium
The Database Handover | A Dumb Mistake | Critical BUG
Hi hackers & Security Enthusiasts, I’m Saransh Saraf and this a simple bug with a critical Impact. I hope you’ll enjoy it and learn…
New Writeup❗️
Date: Tue, 14 Jun 2022 17:48:32 GMT
Title: The Upstox Fraud !! Cheating with Security Researchers
Link: https://medium.com/p/183cd7206640
Date: Tue, 14 Jun 2022 17:48:32 GMT
Title: The Upstox Fraud !! Cheating with Security Researchers
Link: https://medium.com/p/183cd7206640
Medium
The Upstox Fraud !! Cheating with Security Researchers
Hi Hackers, I’m Saransh Saraf and today I’m gonna expose upstox fraud. (Note: I’ve read the NDA of Upstox bug bounty program and it is not…
New Writeup❗️
Date: Fri, 03 Jun 2022 04:58:15 GMT
Title: How it Started and How it is going (Full Path for Beginners)
Link: https://medium.com/p/a59611a31536
Date: Fri, 03 Jun 2022 04:58:15 GMT
Title: How it Started and How it is going (Full Path for Beginners)
Link: https://medium.com/p/a59611a31536
Medium
How it Started and How it is going (Full Path for Beginners)
Hi Hacking Aspirants, I am Saransh Saraf and this is my story (some_part), which will help you to become a good hacker and get a job…
New Writeup❗️
Date: Fri, 15 Apr 2022 10:09:44 GMT
Title: Crazy Simple Insecure Design & 300$ Bounty!
Link: https://medium.com/p/16a2b8e80522
Date: Fri, 15 Apr 2022 10:09:44 GMT
Title: Crazy Simple Insecure Design & 300$ Bounty!
Link: https://medium.com/p/16a2b8e80522
Medium
Crazy Simple Insecure Design & 300$ Bounty!
Hi guys, I’m Saransh Saraf, An Indian Bug Bounty hunter & Security Researcher (I’ve also done LAMP Stack Development)and this will be a…
New Writeup❗️
Date: Mon, 07 Feb 2022 01:54:15 GMT
Title: How Google [ Security Team ] cheated ME!
Link: https://medium.com/p/e0cf61632f05
Date: Mon, 07 Feb 2022 01:54:15 GMT
Title: How Google [ Security Team ] cheated ME!
Link: https://medium.com/p/e0cf61632f05
Medium
How Google [ Security Team ] cheated ME!
Timeline: