New Writeup❗️
Date: Thu, 04 Mar 2021 20:39:46 GMT
Title: Full Account takeOver throught enabled laravel debug mode
Link: https://medium.com/p/54a68156d258
Date: Thu, 04 Mar 2021 20:39:46 GMT
Title: Full Account takeOver throught enabled laravel debug mode
Link: https://medium.com/p/54a68156d258
Medium
Full Account takeOver throught enabled laravel debug mode
hey folks
New Writeup❗️
Date: Thu, 21 Jan 2021 17:19:12 GMT
Title: SSRF exploitation in Spreedsheet to PDF converter
Link: https://medium.com/p/2c7eacdac781
Date: Thu, 21 Jan 2021 17:19:12 GMT
Title: SSRF exploitation in Spreedsheet to PDF converter
Link: https://medium.com/p/2c7eacdac781
Medium
SSRF exploitation in Spreedsheet to PDF converter
hello folks . this is my first writeup about one of my recent finding on a private bug bounty program , i hope you can store a new…
New Writeup❗️
Date: Tue, 29 Dec 2020 10:09:44 GMT
Title: Clickjacking Leads to IDOR at Mola TV
Link: https://medium.com/p/db62c3db50c9
Date: Tue, 29 Dec 2020 10:09:44 GMT
Title: Clickjacking Leads to IDOR at Mola TV
Link: https://medium.com/p/db62c3db50c9
Medium
Clickjacking Leads to IDOR at Mola TV
Hii Now i want to share about “How i got easy Clickjacking and escalated to Idor at Mola TV”
New Writeup❗️
Date: Mon, 28 Dec 2020 09:38:36 GMT
Title: Time Based SQL Injection di Jamtangan.com
Link: https://medium.com/p/73335668217a
Date: Mon, 28 Dec 2020 09:38:36 GMT
Title: Time Based SQL Injection di Jamtangan.com
Link: https://medium.com/p/73335668217a
Medium
Time Based SQL Injection di Jamtangan.com
Halo,
Kali ini saya akan membuat write up tentang “Bagaimana saya mendapatkan Time Based SQL Injection di jamtangan.com”
Kali ini saya akan membuat write up tentang “Bagaimana saya mendapatkan Time Based SQL Injection di jamtangan.com”
☃1
New Writeup❗️
Date: Fri, 27 Nov 2020 07:28:09 GMT
Title: How i got easy $$$ for SQL Injection Bug
Link: https://medium.com/p/7ff622236e4c
Date: Fri, 27 Nov 2020 07:28:09 GMT
Title: How i got easy $$$ for SQL Injection Bug
Link: https://medium.com/p/7ff622236e4c
Medium
How i got easy $$$ for SQL Injection Bug
S
🗿1
New Writeup❗️
Date: Tue, 13 Jul 2021 07:27:52 GMT
Title: Part 2: Dive into Zoom Applications
Link: https://medium.com/p/1b01091345c1
Date: Tue, 13 Jul 2021 07:27:52 GMT
Title: Part 2: Dive into Zoom Applications
Link: https://medium.com/p/1b01091345c1
Medium
Part 2: Dive into Zoom Applications
TL;DR
New Writeup❗️
Date: Wed, 16 Jun 2021 07:19:26 GMT
Title: Part-1 Dive into Zoom Applications
Link: https://medium.com/p/d70f3de53ec5
Date: Wed, 16 Jun 2021 07:19:26 GMT
Title: Part-1 Dive into Zoom Applications
Link: https://medium.com/p/d70f3de53ec5
Medium
Part-1 Dive into Zoom Applications
TL;DR
New Writeup❗️
Date: Thu, 04 Mar 2021 08:50:36 GMT
Title: Low hanging fruits on Facebook Group Room.
Link: https://medium.com/p/b8d17c7ea886
Date: Thu, 04 Mar 2021 08:50:36 GMT
Title: Low hanging fruits on Facebook Group Room.
Link: https://medium.com/p/b8d17c7ea886
Medium
Low hanging fruits on Facebook Group Room.
Unable to remove post on group when post room add with event ($500)
New Writeup❗️
Date: Wed, 08 Sep 2021 11:35:06 GMT
Title: Facebook email disclosure and account takeover
Link: https://medium.com/p/ecdb44ee12e9
Date: Wed, 08 Sep 2021 11:35:06 GMT
Title: Facebook email disclosure and account takeover
Link: https://medium.com/p/ecdb44ee12e9
Medium
Facebook email disclosure and account takeover
I have a preference for apps over web when it comes to hunting, so in January I decided to dive deep into apk endpoints hoping to find…
New Writeup❗️
Date: Fri, 09 Jul 2021 14:01:21 GMT
Title: Facebook Email/phone disclosure using Binary search
Link: https://medium.com/p/d50430758c54
Date: Fri, 09 Jul 2021 14:01:21 GMT
Title: Facebook Email/phone disclosure using Binary search
Link: https://medium.com/p/d50430758c54
Medium
Facebook Email/phone disclosure using Binary search
So in December I decided to hunt on Facebook, and chose to go with the Facebook Android App
New Writeup❗️
Date: Wed, 16 Dec 2020 09:30:06 GMT
Title: JavaScript analysis leading to Admin portal access
Link: https://medium.com/p/ea30f8328c8e
Date: Wed, 16 Dec 2020 09:30:06 GMT
Title: JavaScript analysis leading to Admin portal access
Link: https://medium.com/p/ea30f8328c8e
Medium
JavaScript analysis leading to Admin portal access
I love hunting on small scoped websites cause i can be assured that i have seen every corner and analyzed every endpoint of the that…
New Writeup❗️
Date: Thu, 10 Dec 2020 14:55:01 GMT
Title: How I dumped PII information of customers in an ecommerce site?
Link: https://medium.com/p/237761f813cf
Date: Thu, 10 Dec 2020 14:55:01 GMT
Title: How I dumped PII information of customers in an ecommerce site?
Link: https://medium.com/p/237761f813cf
Medium
How I dumped PII information of customers in an ecommerce site?
Like every website, the most interesting endpoint is always the image upload section.
So I fired my burp and was checking how the images…
So I fired my burp and was checking how the images…
New Writeup❗️
Date: Wed, 05 Aug 2020 12:23:09 GMT
Title: How I was able to do Mass Account Takeover[Bug Bounty]
Link: https://medium.com/p/b279af1ce62b
Date: Wed, 05 Aug 2020 12:23:09 GMT
Title: How I was able to do Mass Account Takeover[Bug Bounty]
Link: https://medium.com/p/b279af1ce62b
Medium
How I was able to do Mass Account Takeover[Bug Bounty]
This was one of the interesting bug that i found on a target.
New Writeup❗️
Date: Tue, 06 Jul 2021 12:01:32 GMT
Title: Exploiting Auto-save Functionality To Steal Login Credentials
Link: https://medium.com/p/bf4c7e1594da
Date: Tue, 06 Jul 2021 12:01:32 GMT
Title: Exploiting Auto-save Functionality To Steal Login Credentials
Link: https://medium.com/p/bf4c7e1594da
Medium
Exploiting Auto-save Functionality To Steal Login Credentials
Hi Folks! hope you all doing well it’s being a long time since I do a write-up, so this write-up is all about my tweet Exploiting/Chaining…
New Writeup❗️
Date: Wed, 14 Oct 2020 10:29:13 GMT
Title: Weaponizing XSS For Fun & Profit
Link: https://medium.com/p/a1414f3fcee9
Date: Wed, 14 Oct 2020 10:29:13 GMT
Title: Weaponizing XSS For Fun & Profit
Link: https://medium.com/p/a1414f3fcee9
Medium
Weaponizing XSS For Fun & Profit
Hi Folks! hope you all doing good so I am back with another amazing way of bypassing the WAF which is blocking me from weaponizing the XSS…
New Writeup❗️
Date: Thu, 01 Aug 2019 07:01:05 GMT
Title: Bypassing CORS
Link: https://medium.com/p/13e46987a45b
Date: Thu, 01 Aug 2019 07:01:05 GMT
Title: Bypassing CORS
Link: https://medium.com/p/13e46987a45b
Medium
Bypassing CORS
Hello friends this write-up is about who I bypass the CORS validation. Let assume the website name redact.com simple I login to website…
New Writeup❗️
Date: Tue, 16 Jul 2019 07:16:49 GMT
Title: Bypass CSRF With ClickJacking Worth $1250
Link: https://medium.com/p/6c70cc263f40
Date: Tue, 16 Jul 2019 07:16:49 GMT
Title: Bypass CSRF With ClickJacking Worth $1250
Link: https://medium.com/p/6c70cc263f40
Medium
Bypass CSRF With ClickJacking Worth $1250
Hello friends, I hope you all are doing well, so this write up is all about how I chain the to different vulnerabilities to update the…
New Writeup❗️
Date: Mon, 01 Jul 2019 08:12:50 GMT
Title: Accidental IDOR
Link: https://medium.com/p/8987a2728d4
Date: Mon, 01 Jul 2019 08:12:50 GMT
Title: Accidental IDOR
Link: https://medium.com/p/8987a2728d4
Medium
Accidental IDOR
Hi guys I hope you all are doing good so this write-up is all about the accidental IDOR that I found in the PRIVATE program so let assume…
New Writeup❗️
Date: Thu, 20 Jun 2019 20:11:08 GMT
Title: Self XSS To Evil XSS
Link: https://medium.com/p/bcf2494a82a4
Date: Thu, 20 Jun 2019 20:11:08 GMT
Title: Self XSS To Evil XSS
Link: https://medium.com/p/bcf2494a82a4
Medium
Self XSS To Evil XSS
Hi guy I hope you all are fine this POC is all about how I convert the Self XSS To Evil XSS so let assume the site PRIVATE.COM
New Writeup❗️
Date: Mon, 17 Jun 2019 18:19:51 GMT
Title: SQl Injection
Link: https://medium.com/p/c87a390afdd3
Date: Mon, 17 Jun 2019 18:19:51 GMT
Title: SQl Injection
Link: https://medium.com/p/c87a390afdd3
Medium
SQl Injection
Hy Guy’s this write up is all about my SQL Injection that I found in PRIVATE program running on BugCrowd
🗿1