New Writeup❗️
Date: Mon, 10 Oct 2022 06:48:38 GMT
Title: Gcash Vulnerability Walkthrough
Link: https://medium.com/p/c7c938163dfb
Date: Mon, 10 Oct 2022 06:48:38 GMT
Title: Gcash Vulnerability Walkthrough
Link: https://medium.com/p/c7c938163dfb
Medium
Hacking GCash —Philippines Mobile Banking Application
Advisory: Update your Gcash App now to the latest version.
New Writeup❗️
Date: Tue, 04 Oct 2022 11:37:07 GMT
Title: ML Wallet Vulnerability
Link: https://medium.com/p/c956f731dc19
Date: Tue, 04 Oct 2022 11:37:07 GMT
Title: ML Wallet Vulnerability
Link: https://medium.com/p/c956f731dc19
Medium
ML Wallet Vulnerability
Disclaimer: The purpose of this research is to improve and strengthen security all issues discovered in this research are reported to the…
New Writeup❗️
Date: Sun, 25 Sep 2022 05:40:25 GMT
Title: Shopping App Deeplink Arbitrary URLs
Link: https://medium.com/p/91a143a45c11
Date: Sun, 25 Sep 2022 05:40:25 GMT
Title: Shopping App Deeplink Arbitrary URLs
Link: https://medium.com/p/91a143a45c11
Medium
Shopping App Deeplink Arbitrary URLs
In this write-up, I’ll tell you how I was able to launch Arbitrary URLs to the internal web of the shopping application.
New Writeup❗️
Date: Fri, 23 Sep 2022 15:14:59 GMT
Title: Arbitrary File Corruption: End - to - End Encrypted Messaging Application
Link: https://medium.com/p/674963dceef8
Date: Fri, 23 Sep 2022 15:14:59 GMT
Title: Arbitrary File Corruption: End - to - End Encrypted Messaging Application
Link: https://medium.com/p/674963dceef8
Medium
Arbitrary File Corruption: End - to - End Encrypted Messaging Application
In this write-up, I’ll tell you how I was able to Exfiltrate Database and Sandbox Files on End-to-End Encrypted Messaging Application.
New Writeup❗️
Date: Mon, 12 Sep 2022 05:15:33 GMT
Title: PLMUN STUDENT PORTAL HACKED
Link: https://medium.com/p/d2068f7da574
Date: Mon, 12 Sep 2022 05:15:33 GMT
Title: PLMUN STUDENT PORTAL HACKED
Link: https://medium.com/p/d2068f7da574
Medium
PLMUN STUDENT PORTAL HACKED
Disclaimer: The purpose of this research is to improve and strengthen security all issues discovered in this research are reported to the…
New Writeup❗️
Date: Thu, 08 Sep 2022 11:30:32 GMT
Title: StaySafe Philippines Contact Tracing Platform Vulnerability
Link: https://medium.com/p/e479f16727f5
Date: Thu, 08 Sep 2022 11:30:32 GMT
Title: StaySafe Philippines Contact Tracing Platform Vulnerability
Link: https://medium.com/p/e479f16727f5
Medium
StaySafe Philippines Contact Tracing Platform Vulnerability
Disclaimer: The purpose of this research is to improve and strengthen security all issues discovered in this research are reported to the…
New Writeup❗️
Date: Wed, 12 Jan 2022 12:06:40 GMT
Title: Xiaomi Execute Arbitrary JavaScript
Link: https://medium.com/p/327a6f3a9b0e
Date: Wed, 12 Jan 2022 12:06:40 GMT
Title: Xiaomi Execute Arbitrary JavaScript
Link: https://medium.com/p/327a6f3a9b0e
Medium
Xiaomi Execute Arbitrary JavaScript
In this writeup, I’ll tell you how I was able to Execute Arbitrary JavaScript in Xiaomi Browser using HTML Injection.
New Writeup❗️
Date: Tue, 08 Dec 2020 01:57:54 GMT
Title: Facebook Leak Referrer Data
Link: https://medium.com/p/48da5e505cf6
Date: Tue, 08 Dec 2020 01:57:54 GMT
Title: Facebook Leak Referrer Data
Link: https://medium.com/p/48da5e505cf6
Medium
Facebook Leak Referrer Data
While finding a facebook vulnerability I visited this interesting link with a back uri parameter endpoint
New Writeup❗️
Date: Mon, 07 Dec 2020 14:42:37 GMT
Title: Facebook Push Notification Linkshim Bypassed
Link: https://medium.com/p/385fe471516
Date: Mon, 07 Dec 2020 14:42:37 GMT
Title: Facebook Push Notification Linkshim Bypassed
Link: https://medium.com/p/385fe471516
Medium
Facebook Push Notification Linkshim Bypassed
While browsing and finding facebook vulnerability I accidentally found this facebook push notification link
New Writeup❗️
Date: Sat, 05 Dec 2020 07:27:29 GMT
Title: Opera Browser Cross Site Scripting (XSS)
Link: https://medium.com/p/39823a22045d
Date: Sat, 05 Dec 2020 07:27:29 GMT
Title: Opera Browser Cross Site Scripting (XSS)
Link: https://medium.com/p/39823a22045d
Medium
Opera Browser Cross Site Scripting (XSS)
While using opera browser for android I noticed something strange the address bar in opera browser replaced by the reader mode and the web…
New Writeup❗️
Date: Sun, 20 Nov 2022 03:28:45 GMT
Title: Proxying Network Traffic Without a Hostname
Link: https://medium.com/p/24ab399a1d3a
Date: Sun, 20 Nov 2022 03:28:45 GMT
Title: Proxying Network Traffic Without a Hostname
Link: https://medium.com/p/24ab399a1d3a
Medium
Proxying Network Traffic Without a Hostname
Introduction
New Writeup❗️
Date: Mon, 06 Jun 2022 00:21:39 GMT
Title: Behind the Bug: Password reset poisoning
Link: https://medium.com/p/f5a51d890260
Date: Mon, 06 Jun 2022 00:21:39 GMT
Title: Behind the Bug: Password reset poisoning
Link: https://medium.com/p/f5a51d890260
Medium
Behind the Bug: Password reset poisoning
Introduction
New Writeup❗️
Date: Wed, 02 Mar 2022 14:06:42 GMT
Title: IDOR in support.mozilla.org through Code Review
Link: https://medium.com/p/ff2aa8ea1201
Date: Wed, 02 Mar 2022 14:06:42 GMT
Title: IDOR in support.mozilla.org through Code Review
Link: https://medium.com/p/ff2aa8ea1201
Medium
IDOR in support.mozilla.org through Code Review
I was trying to improve my static analysis code, specifically django apps, so i decided to hack a random project in github. And i found…
New Writeup❗️
Date: Mon, 14 Feb 2022 04:48:56 GMT
Title: Bookwyrm Server Side Request Forgery
Link: https://medium.com/p/b1462829d68e
Date: Mon, 14 Feb 2022 04:48:56 GMT
Title: Bookwyrm Server Side Request Forgery
Link: https://medium.com/p/b1462829d68e
Medium
Bookwyrm Server Side Request Forgery
While reading the code of bookwyrm, i encounter this endpoint
New Writeup❗️
Date: Tue, 08 Feb 2022 03:07:49 GMT
Title: Hacking into school management systems. Reflected XSS To RCE
Link: https://medium.com/p/74880c423024
Date: Tue, 08 Feb 2022 03:07:49 GMT
Title: Hacking into school management systems. Reflected XSS To RCE
Link: https://medium.com/p/74880c423024
Medium
Hacking into school management systems. Reflected XSS To RCE
As a hacker, we are asked a million times before if we can hack into their school system and change their grades.
New Writeup❗️
Date: Mon, 07 Feb 2022 09:57:34 GMT
Title: Hacking and reverse engineering il2cpp games with ghidra
Link: https://medium.com/p/5cee894024f2
Date: Mon, 07 Feb 2022 09:57:34 GMT
Title: Hacking and reverse engineering il2cpp games with ghidra
Link: https://medium.com/p/5cee894024f2
Medium
Hacking and reverse engineering il2cpp games with ghidra
Last writeup, we talk about how to hack unity games compiled on mono. This time, we will be hacking unity games compiled in il2cpp. IL2CPP…
New Writeup❗️
Date: Sat, 05 Feb 2022 10:46:27 GMT
Title: Hacking .Net Games With DnSpy
Link: https://medium.com/p/73e1441f81c1
Date: Sat, 05 Feb 2022 10:46:27 GMT
Title: Hacking .Net Games With DnSpy
Link: https://medium.com/p/73e1441f81c1
Medium
Hacking .Net Games With DnSpy
Introduction
New Writeup❗️
Date: Sun, 30 Jan 2022 07:25:52 GMT
Title: How to get started hacking django applications
Link: https://medium.com/p/f407564df9c7
Date: Sun, 30 Jan 2022 07:25:52 GMT
Title: How to get started hacking django applications
Link: https://medium.com/p/f407564df9c7
Medium
How To Get Started Hacking Django Based Applications
Django is a python based web framework. In this writeup, i will teach you how to analyze django based applications . For this writeup, i…
New Writeup❗️
Date: Sun, 09 Jan 2022 07:52:25 GMT
Title: 2FA bypass by reading the documentation
Link: https://medium.com/p/3260a372d8a8
Date: Sun, 09 Jan 2022 07:52:25 GMT
Title: 2FA bypass by reading the documentation
Link: https://medium.com/p/3260a372d8a8
Medium
2FA bypass by reading the documentation
This is a fairly simple and short writeup, but i think is worth sharing, so lets get started.
New Writeup❗️
Date: Fri, 20 Nov 2020 14:43:17 GMT
Title: Turning Blind Error Based SQL Injection Into An Exploitable Boolean One
Link: https://medium.com/p/85d6be3ca23b
Date: Fri, 20 Nov 2020 14:43:17 GMT
Title: Turning Blind Error Based SQL Injection Into An Exploitable Boolean One
Link: https://medium.com/p/85d6be3ca23b
Medium
Turning Blind Error Based SQL Injection Into An Exploitable Boolean One
While I was recently hunting on a promising host target, from my well configured (only checking SQLi) active scan results, I found out a…
🗿1