New Writeup❗️
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Date: Wed, 02 Nov 2022 04:36:34 GMT
Title: Improper Access Control — My Third Finding on Hackerone!
Link: https://medium.com/p/1455e95b6c8c
Medium
Improper Access Control — My Third Finding on HackerOne!
Improper Access Control means web application or software functions does not restrict or incorrectly restricts access and usage to any…
New Writeup❗️
Date: Sun, 23 Oct 2022 11:28:54 GMT
Title: Broken Link Hijacking — My Second Finding on Hackerone!
Link: https://medium.com/p/d715b0713fca
Date: Sun, 23 Oct 2022 11:28:54 GMT
Title: Broken Link Hijacking — My Second Finding on Hackerone!
Link: https://medium.com/p/d715b0713fca
Medium
Broken Link Hijacking — My Second Finding on Hackerone!
Broken Link Hijacking (BLH) or Link Takeover, whatever you called it, the concept is very simple. If you get any broken links of any…
New Writeup❗️
Date: Fri, 21 Oct 2022 05:10:56 GMT
Title: Information Disclosure — My First Finding on Hackerone!
Link: https://medium.com/p/e572cc07babb
Date: Fri, 21 Oct 2022 05:10:56 GMT
Title: Information Disclosure — My First Finding on Hackerone!
Link: https://medium.com/p/e572cc07babb
Medium
Information Disclosure — My First Finding on Hackerone!
Information Disclosure is a kind of bug that is not so hard to find but could has huge impact. Some time you could get a very sensitive…
New Writeup❗️
Date: Wed, 05 Oct 2022 20:59:28 GMT
Title: Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
Link: https://medium.com/p/99b4a1723051
Date: Wed, 05 Oct 2022 20:59:28 GMT
Title: Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
Link: https://medium.com/p/99b4a1723051
Medium
Found XSS & Open Redirect Vulnerability in CrazyHD Torrent Website — Don’t Miss The Starting Story!
CrazyHD is one of the famous torrent website in Bangladesh and India. People get pirated movies , paid courses , softwares and more in…
New Writeup❗️
Date: Tue, 30 Aug 2022 11:03:42 GMT
Title: Found SQL Injection Vulnerability on Government Organization Website!
Link: https://medium.com/p/3eb33c0c49a4
Date: Tue, 30 Aug 2022 11:03:42 GMT
Title: Found SQL Injection Vulnerability on Government Organization Website!
Link: https://medium.com/p/3eb33c0c49a4
Medium
Found SQL Injection Vulnerability on Government Organization Website!
Last night before going to sleep i make a quick search on google a dork to find vulnerable websites and found some interesting result and…
🗿1
New Writeup❗️
Date: Tue, 07 Dec 2021 23:05:25 GMT
Title: Introduction : Who am I ?
Link: https://medium.com/p/f6bbcc6cf201
Date: Tue, 07 Dec 2021 23:05:25 GMT
Title: Introduction : Who am I ?
Link: https://medium.com/p/f6bbcc6cf201
Medium
Introduction : Who am I ?
Hey there, everyone! 👋 I’m Mehedi Shakeel, an IT security professional hailing from Bangladesh. With a solid background in ethical…
New Writeup❗️
Date: Mon, 07 Nov 2022 19:09:38 GMT
Title: How we ‘hacked’ Telenet’s cybersecurity quiz
Link: https://medium.com/p/958c1d3ee2ba
Date: Mon, 07 Nov 2022 19:09:38 GMT
Title: How we ‘hacked’ Telenet’s cybersecurity quiz
Link: https://medium.com/p/958c1d3ee2ba
Medium
How we ‘hacked’ Telenet’s cybersecurity quiz
Not so long ago, Telenet Business ran a quiz to find the smartest cyber specialist. The quiz consisted out of 20 questions and your score…
New Writeup❗️
Date: Fri, 03 Jun 2022 19:52:46 GMT
Title: Poppin’ shell with MSDT & PowerPoint
Link: https://medium.com/p/3fce5588e236
Date: Fri, 03 Jun 2022 19:52:46 GMT
Title: Poppin’ shell with MSDT & PowerPoint
Link: https://medium.com/p/3fce5588e236
Medium
Poppin’ shell with MSDT & PowerPoint
I’m assuming if you clicked, you’ve already heard about CVE-2022–30190. I won’t get into the details of it, but it’s a recent zero-day…
New Writeup❗️
Date: Thu, 13 Oct 2022 02:08:11 GMT
Title: Code flaws leads to Org/Admin Account Takeover
Link: https://medium.com/p/ad9515a96eab
Date: Thu, 13 Oct 2022 02:08:11 GMT
Title: Code flaws leads to Org/Admin Account Takeover
Link: https://medium.com/p/ad9515a96eab
Medium
Code flaws leads to Org/Admin Account Takeover
Hello Everyone, I’m Saransh Saraf and I’m back with another unique account takeover idea, so let’s just dive into it :)
New Writeup❗️
Date: Fri, 02 Sep 2022 04:20:07 GMT
Title: The Database Handover | A Dumb Mistake | Critical BUG
Link: https://medium.com/p/f73c99e72e40
Date: Fri, 02 Sep 2022 04:20:07 GMT
Title: The Database Handover | A Dumb Mistake | Critical BUG
Link: https://medium.com/p/f73c99e72e40
Medium
The Database Handover | A Dumb Mistake | Critical BUG
Hi hackers & Security Enthusiasts, I’m Saransh Saraf and this a simple bug with a critical Impact. I hope you’ll enjoy it and learn…
New Writeup❗️
Date: Tue, 14 Jun 2022 17:48:32 GMT
Title: The Upstox Fraud !! Cheating with Security Researchers
Link: https://medium.com/p/183cd7206640
Date: Tue, 14 Jun 2022 17:48:32 GMT
Title: The Upstox Fraud !! Cheating with Security Researchers
Link: https://medium.com/p/183cd7206640
Medium
The Upstox Fraud !! Cheating with Security Researchers
Hi Hackers, I’m Saransh Saraf and today I’m gonna expose upstox fraud. (Note: I’ve read the NDA of Upstox bug bounty program and it is not…
New Writeup❗️
Date: Fri, 03 Jun 2022 04:58:15 GMT
Title: How it Started and How it is going (Full Path for Beginners)
Link: https://medium.com/p/a59611a31536
Date: Fri, 03 Jun 2022 04:58:15 GMT
Title: How it Started and How it is going (Full Path for Beginners)
Link: https://medium.com/p/a59611a31536
Medium
How it Started and How it is going (Full Path for Beginners)
Hi Hacking Aspirants, I am Saransh Saraf and this is my story (some_part), which will help you to become a good hacker and get a job…
New Writeup❗️
Date: Fri, 15 Apr 2022 10:09:44 GMT
Title: Crazy Simple Insecure Design & 300$ Bounty!
Link: https://medium.com/p/16a2b8e80522
Date: Fri, 15 Apr 2022 10:09:44 GMT
Title: Crazy Simple Insecure Design & 300$ Bounty!
Link: https://medium.com/p/16a2b8e80522
Medium
Crazy Simple Insecure Design & 300$ Bounty!
Hi guys, I’m Saransh Saraf, An Indian Bug Bounty hunter & Security Researcher (I’ve also done LAMP Stack Development)and this will be a…
New Writeup❗️
Date: Mon, 07 Feb 2022 01:54:15 GMT
Title: How Google [ Security Team ] cheated ME!
Link: https://medium.com/p/e0cf61632f05
Date: Mon, 07 Feb 2022 01:54:15 GMT
Title: How Google [ Security Team ] cheated ME!
Link: https://medium.com/p/e0cf61632f05
Medium
How Google [ Security Team ] cheated ME!
Timeline:
New Writeup❗️
Date: Sat, 05 Feb 2022 04:58:04 GMT
Title: I Hacked Every Single Staff Account on AirIndia within 1.5 Minutes :)
Link: https://medium.com/p/f0c96b01efab
Date: Sat, 05 Feb 2022 04:58:04 GMT
Title: I Hacked Every Single Staff Account on AirIndia within 1.5 Minutes :)
Link: https://medium.com/p/f0c96b01efab
Medium
I Hacked Every Single Staff Account on AirIndia within 1.5 Minutes :)
Hello Beautiful creative people, hope you’re doing great.
New Writeup❗️
Date: Thu, 30 Dec 2021 12:14:40 GMT
Title: The Password Bypass Leads to Full-Account-Takeover
Link: https://medium.com/p/9aefa7e3a9dd
Date: Thu, 30 Dec 2021 12:14:40 GMT
Title: The Password Bypass Leads to Full-Account-Takeover
Link: https://medium.com/p/9aefa7e3a9dd
Medium
The Password Bypass Leads to Full-Account-Takeover
Hola Hackers, I’m Saransh Saraf aka MR23R0
New Writeup❗️
Date: Mon, 13 Dec 2021 15:15:11 GMT
Title: How I earned +240$ from a Zero Interface✌
Link: https://medium.com/p/53d244a231f9
Date: Mon, 13 Dec 2021 15:15:11 GMT
Title: How I earned +240$ from a Zero Interface✌
Link: https://medium.com/p/53d244a231f9
Medium
How I earned +240$ from a Zero Interface✌
bonjour Hackers, I’m Saransh Saraf AKA MR23R0.
New Writeup❗️
Date: Mon, 27 Dec 2021 11:36:09 GMT
Title: OSINT Series … Part-1
Link: https://medium.com/p/7d00f3526295
Date: Mon, 27 Dec 2021 11:36:09 GMT
Title: OSINT Series … Part-1
Link: https://medium.com/p/7d00f3526295
Medium
OSINT Series … Part-1
What is OSINT ?
New Writeup❗️
Date: Tue, 19 Oct 2021 10:09:20 GMT
Title: How I found a Command injection bug
Link: https://medium.com/p/80c2e1592aeb
Date: Tue, 19 Oct 2021 10:09:20 GMT
Title: How I found a Command injection bug
Link: https://medium.com/p/80c2e1592aeb
Medium
How I found a Command injection bug
Hey, guys today I want to show you how I was able to find a command injection bug through fuzzing. So let's get started
New Writeup❗️
Date: Tue, 19 Oct 2021 08:50:49 GMT
Title: Remote code execution (RCE)
Link: https://medium.com/p/702af040e247
Date: Tue, 19 Oct 2021 08:50:49 GMT
Title: Remote code execution (RCE)
Link: https://medium.com/p/702af040e247
Medium
Remote code execution (RCE)
What is an RCE attack?