New Writeup❗️
Date: Tue, 11 Aug 2020 12:40:26 GMT
Title: Hunting for CVE: 2020–3187 , 2020–3452
Link: https://medium.com/p/9f0dcc66f4d8
Date: Tue, 11 Aug 2020 12:40:26 GMT
Title: Hunting for CVE: 2020–3187 , 2020–3452
Link: https://medium.com/p/9f0dcc66f4d8
Medium
Hunting for CVE: 2020–3187 , 2020–3452
Back with another writeup. In this I will be discussing about how easy is to hunt for CVE:2020–3187&, 2020-3452 and what are the steps…
New Writeup❗️
Date: Sat, 06 Mar 2021 18:01:13 GMT
Title: My First Bug Bounty
Link: https://medium.com/p/a011d2d049ce
Date: Sat, 06 Mar 2021 18:01:13 GMT
Title: My First Bug Bounty
Link: https://medium.com/p/a011d2d049ce
Medium
My First Bug Bounty
Hello everyone, this is Prajwol from Nepal. This is an explaination about my first bug bounty.
New Writeup❗️
Date: Sun, 12 Dec 2021 09:14:05 GMT
Title: SVG based Stored XSS
Link: https://medium.com/p/ee6e9b240dee
Date: Sun, 12 Dec 2021 09:14:05 GMT
Title: SVG based Stored XSS
Link: https://medium.com/p/ee6e9b240dee
Medium
SVG based Stored XSS
Hi, hope you guys doing great! Here is a story about me finding a stored XSS using svg files
New Writeup❗️
Date: Fri, 19 Mar 2021 05:49:46 GMT
Title: Browser fingerprinting via Caching
Link: https://medium.com/p/1b2b9eb53551
Date: Fri, 19 Mar 2021 05:49:46 GMT
Title: Browser fingerprinting via Caching
Link: https://medium.com/p/1b2b9eb53551
Medium
Browser fingerprinting via Caching
Introduction
New Writeup❗️
Date: Wed, 09 Feb 2022 07:52:47 GMT
Title: Microsoft Team’s Unpatched URL Spoofing Vulnerability
Link: https://medium.com/p/c58f5949fac8
Date: Wed, 09 Feb 2022 07:52:47 GMT
Title: Microsoft Team’s Unpatched URL Spoofing Vulnerability
Link: https://medium.com/p/c58f5949fac8
Medium
Microsoft Team’s Unpatched URL Spoofing Vulnerability
What is URL Spoofing?
New Writeup❗️
Date: Mon, 13 Feb 2023 21:54:46 GMT
Title: Bypassing CORS configurations to produce an Account Takeover for Fun and Profit
Link: https://medium.com/p/3e50c3f2a124
Date: Mon, 13 Feb 2023 21:54:46 GMT
Title: Bypassing CORS configurations to produce an Account Takeover for Fun and Profit
Link: https://medium.com/p/3e50c3f2a124
Medium
Bypassing CORS configurations to produce an Account Takeover for Fun and Profit
The bug that is being written about here is from an previous bug bounty engagement for a major telecommunication company. This bug consists…
New Writeup❗️
Date: Wed, 03 Feb 2021 02:58:31 GMT
Title: How I was able to Turn a XSS into A Account Takeover
Link: https://medium.com/p/ae0c478640e7
Date: Wed, 03 Feb 2021 02:58:31 GMT
Title: How I was able to Turn a XSS into A Account Takeover
Link: https://medium.com/p/ae0c478640e7
Medium
How I was able to Turn a XSS into a Account Takeover
To begin,this is a vulnerability that I found during a bug bounty engagement.I would split this into two parts, or two separate…
New Writeup❗️
Date: Tue, 17 Nov 2020 23:06:25 GMT
Title: OpenEMR 5.0.1.3 — (Authenticated) Arbitrary File Actions
Link: https://medium.com/p/f7006e636b8c
Date: Tue, 17 Nov 2020 23:06:25 GMT
Title: OpenEMR 5.0.1.3 — (Authenticated) Arbitrary File Actions
Link: https://medium.com/p/f7006e636b8c
Medium
OpenEMR 5.0.1.3 — (Authenticated) Arbitrary File Actions
Back in 2018, a group of security researchers and I decided to try our hands at OpenEMR and find security vulnerabilities.The full report…
New Writeup❗️
Date: Thu, 04 Mar 2021 20:39:46 GMT
Title: Full Account takeOver throught enabled laravel debug mode
Link: https://medium.com/p/54a68156d258
Date: Thu, 04 Mar 2021 20:39:46 GMT
Title: Full Account takeOver throught enabled laravel debug mode
Link: https://medium.com/p/54a68156d258
Medium
Full Account takeOver throught enabled laravel debug mode
hey folks
New Writeup❗️
Date: Thu, 21 Jan 2021 17:19:12 GMT
Title: SSRF exploitation in Spreedsheet to PDF converter
Link: https://medium.com/p/2c7eacdac781
Date: Thu, 21 Jan 2021 17:19:12 GMT
Title: SSRF exploitation in Spreedsheet to PDF converter
Link: https://medium.com/p/2c7eacdac781
Medium
SSRF exploitation in Spreedsheet to PDF converter
hello folks . this is my first writeup about one of my recent finding on a private bug bounty program , i hope you can store a new…
New Writeup❗️
Date: Tue, 29 Dec 2020 10:09:44 GMT
Title: Clickjacking Leads to IDOR at Mola TV
Link: https://medium.com/p/db62c3db50c9
Date: Tue, 29 Dec 2020 10:09:44 GMT
Title: Clickjacking Leads to IDOR at Mola TV
Link: https://medium.com/p/db62c3db50c9
Medium
Clickjacking Leads to IDOR at Mola TV
Hii Now i want to share about “How i got easy Clickjacking and escalated to Idor at Mola TV”
New Writeup❗️
Date: Mon, 28 Dec 2020 09:38:36 GMT
Title: Time Based SQL Injection di Jamtangan.com
Link: https://medium.com/p/73335668217a
Date: Mon, 28 Dec 2020 09:38:36 GMT
Title: Time Based SQL Injection di Jamtangan.com
Link: https://medium.com/p/73335668217a
Medium
Time Based SQL Injection di Jamtangan.com
Halo,
Kali ini saya akan membuat write up tentang “Bagaimana saya mendapatkan Time Based SQL Injection di jamtangan.com”
Kali ini saya akan membuat write up tentang “Bagaimana saya mendapatkan Time Based SQL Injection di jamtangan.com”
☃1
New Writeup❗️
Date: Fri, 27 Nov 2020 07:28:09 GMT
Title: How i got easy $$$ for SQL Injection Bug
Link: https://medium.com/p/7ff622236e4c
Date: Fri, 27 Nov 2020 07:28:09 GMT
Title: How i got easy $$$ for SQL Injection Bug
Link: https://medium.com/p/7ff622236e4c
Medium
How i got easy $$$ for SQL Injection Bug
S
🗿1
New Writeup❗️
Date: Tue, 13 Jul 2021 07:27:52 GMT
Title: Part 2: Dive into Zoom Applications
Link: https://medium.com/p/1b01091345c1
Date: Tue, 13 Jul 2021 07:27:52 GMT
Title: Part 2: Dive into Zoom Applications
Link: https://medium.com/p/1b01091345c1
Medium
Part 2: Dive into Zoom Applications
TL;DR
New Writeup❗️
Date: Wed, 16 Jun 2021 07:19:26 GMT
Title: Part-1 Dive into Zoom Applications
Link: https://medium.com/p/d70f3de53ec5
Date: Wed, 16 Jun 2021 07:19:26 GMT
Title: Part-1 Dive into Zoom Applications
Link: https://medium.com/p/d70f3de53ec5
Medium
Part-1 Dive into Zoom Applications
TL;DR
New Writeup❗️
Date: Thu, 04 Mar 2021 08:50:36 GMT
Title: Low hanging fruits on Facebook Group Room.
Link: https://medium.com/p/b8d17c7ea886
Date: Thu, 04 Mar 2021 08:50:36 GMT
Title: Low hanging fruits on Facebook Group Room.
Link: https://medium.com/p/b8d17c7ea886
Medium
Low hanging fruits on Facebook Group Room.
Unable to remove post on group when post room add with event ($500)
New Writeup❗️
Date: Wed, 08 Sep 2021 11:35:06 GMT
Title: Facebook email disclosure and account takeover
Link: https://medium.com/p/ecdb44ee12e9
Date: Wed, 08 Sep 2021 11:35:06 GMT
Title: Facebook email disclosure and account takeover
Link: https://medium.com/p/ecdb44ee12e9
Medium
Facebook email disclosure and account takeover
I have a preference for apps over web when it comes to hunting, so in January I decided to dive deep into apk endpoints hoping to find…
New Writeup❗️
Date: Fri, 09 Jul 2021 14:01:21 GMT
Title: Facebook Email/phone disclosure using Binary search
Link: https://medium.com/p/d50430758c54
Date: Fri, 09 Jul 2021 14:01:21 GMT
Title: Facebook Email/phone disclosure using Binary search
Link: https://medium.com/p/d50430758c54
Medium
Facebook Email/phone disclosure using Binary search
So in December I decided to hunt on Facebook, and chose to go with the Facebook Android App
New Writeup❗️
Date: Wed, 16 Dec 2020 09:30:06 GMT
Title: JavaScript analysis leading to Admin portal access
Link: https://medium.com/p/ea30f8328c8e
Date: Wed, 16 Dec 2020 09:30:06 GMT
Title: JavaScript analysis leading to Admin portal access
Link: https://medium.com/p/ea30f8328c8e
Medium
JavaScript analysis leading to Admin portal access
I love hunting on small scoped websites cause i can be assured that i have seen every corner and analyzed every endpoint of the that…
New Writeup❗️
Date: Thu, 10 Dec 2020 14:55:01 GMT
Title: How I dumped PII information of customers in an ecommerce site?
Link: https://medium.com/p/237761f813cf
Date: Thu, 10 Dec 2020 14:55:01 GMT
Title: How I dumped PII information of customers in an ecommerce site?
Link: https://medium.com/p/237761f813cf
Medium
How I dumped PII information of customers in an ecommerce site?
Like every website, the most interesting endpoint is always the image upload section.
So I fired my burp and was checking how the images…
So I fired my burp and was checking how the images…