{"id":27123548,"url":"https://github.com/fardeen-ahmed/Bug-bounty-Writeups","last_synced_at":"2025-04-07T13:01:39.883Z","repository":{"id":39857703,"uuid":"310535612","full_name":"fardeen-ahmed/Bug-bounty-Writeups","owner":"fardeen-ahmed","description":"Repository of Bug-Bounty Writeups","archived":false,"fork":false,"pushed_at":"2025-03-25T17:29:58.000Z","size":3607,"stargazers_count":297,"open_issues_count":0,"forks_count":47,"subscribers_count":10,"default_branch":"main","last_synced_at":"2025-03-25T18:34:35.219Z","etag":null,"topics":["bugbounty","fuzzing","penetration-testing","security-tools"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fardeen-ahmed.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-11-06T08:24:36.000Z","updated_at":"2025-03-25T17:30:01.000Z","dependencies_parsed_at":"2024-04-13T15:14:03.123Z","dependency_job_id":"b5e03890-44b0-440c-bfa2-d3365ac5d29e","html_url":"https://github.com/fardeen-ahmed/Bug-bounty-Writeups","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fardeen-ahmed%2FBug-bounty-Writeups","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fardeen-ahmed%2FBug-bounty-Writeups/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fardeen-ahmed%2FBug-bounty-Writeups/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fardeen-ahmed%2FBug-bounty-Writeups/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fardeen-ahmed","download_url":"https://codeload.github.com/fardeen-ahmed/Bug-bounty-Writeups/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247657273,"owners_count":20974344,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bugbounty","fuzzing","penetration-testing","security-tools"],"created_at":"2025-04-07T13:01:38.158Z","updated_at":"2025-04-07T13:01:39.865Z","avatar_url":"https://github.com/fardeen-ahmed.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"\u003ch1\u003eAwesome BugBounty 👨‍💻 \u003c/h1\u003e\n\u003ca href=\"https://fardeen-ahmed.github.io/\"\u003e\n  \u003cimg src=\"https://github.com/fardeen-ahmed/Bug-bounty-Writeups/blob/main/1.png\" alt=\"None\" align=\"center\" height=\"400\" width=\"1000\"\u003e\n\u003c/a\u003e\n\u003ch4\u003eThis repository can be used as a reference while learning and performing Bug-Bounty hunting \u003c/h4\u003e\u003cbr\u003e\n\n| Basic Tools | Description |\n|-----------|-----|\n| \u003ca href=\"https://github.com/RenwaX23/XSSTRON\"\u003e XSSTRON \u003c/a\u003e  | Electron JS Browser To Find XSS Vulnerabilities Automatically  |\n| \u003ca href=\"https://github.com/mdsecresearch/BurpSuiteSharpener\"\u003e Burpsuite Sharpener \u003c/a\u003e | Extension should add a number of UI and functional features to Burp Suite to make working with it easie |\n| \u003ca href=\"https://medium.com/@calfcrusher/automate-and-finds-the-ip-address-of-a-website-behind-cloudflare-45db99510b4b\"\u003e Automate to find IP address | Automate and finds the IP address of a website behind Cloudflare  |\n| \u003ca href=\"https://github.com/m8r0wn/taser\"\u003e Taser \u003c/a\u003e | Python3 resource library for creating security related tooling\u003c/a\u003e |\n| \u003ca href=\"https://github.com/s0md3v/uro\"\u003e Uro \u003c/a\u003e | Using a URL list for security testing can be painful as there are a lot of URLs that have uninteresting/duplicate content; uro aims to solve that.\u003c/a\u003e | \n| \u003ca href=\"https://github.com/thelicato/fire\"\u003e Fire \u003c/a\u003e | This is a simple tool meant to work in a pipeline of other scripts. It takes domains on stdin and outputs them on stdout if they resolve |\n| \u003ca href=\"https://github.com/quarkslab/pastis\"\u003e PASTIS \u003c/a\u003e | The PASTIS project is a fuzzing framework aiming at combining various software testing techniques within the same workflow to perform collaborative fuzzing also called ensemble fuzzing. |\n| \u003ca href=\"https://slowmist.medium.com/meta-mask-clickjacking-vulnerability-analysis-f3e7c22ff4d9\"\u003e MCVA \u003c/a\u003e | MetaMask Clickjacking Vulnerability Analysis\u003c/a\u003e |\n| \u003ca href=\"https://github.com/tristanlatr/burpa\"\u003e Burp Automator \u003c/a\u003e | A Burp Suite Automation Tool. It provides a high level CLI and Python interfaces to Burp Suite scanner and can be used to setup Dynamic Application Security Testing (DAST) |\n| \u003ca href=\"https://github.com/famasoon/gowhois\"\u003e GoWhois \u003c/a\u003e |  Whois command implemented by golang with awesome whois servers list \u003c/a\u003e |\n| \u003ca href=\"https://github.com/gwen001/related-domains\"\u003e Relateddomains \u003c/a\u003e | Find related domains of a given domain\u003c/a\u003e |\n| \u003ca href=\"https://github.com/Ciphey/Ciphey\"\u003e Ciphey \u003c/a\u003e | Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes.|\n| \u003ca href=\"https://github.com/edoardottt/csprecon\"\u003e CSPRecon \u003c/a\u003e | Discover new target domains using Content Security Policy |\n| \u003ca href=\"https://github.com/iangcarroll/cookiemonster\"\u003e CookieMonster \u003c/a\u003e | This helps you detect and abuse vulnerable implementations of stateless sessions |\n| \u003ca href=\"https://www.securesystems.de/blog/subdomain-enumeration-with-DNSSEC/\"\u003e DNSSEC \u003c/a\u003e | Subdomain Enumeration with DNSSEC |\n| \u003ca href=\"https://medium.com/@kaorrosi/osint-research-with-recon-ng-727661a70ea4\"\u003e ReconNG \u003c/a\u003e | OSINT Research |\n| \u003ca href=\"https://github.com/projectdiscovery/katana\"\u003e Katana \u003c/a\u003e | A nextgeneration crawling and spidering framework. |\n| \u003ca href=\"https://github.com/silentsignal/burp-text4shell\"\u003e BurpText4Shell \u003c/a\u003e | Test4shell scanner for Burp Suite. |\n| \u003ca href=\"https://beinguncommon.medium.com/rust-scan-the-modern-port-scanner-d6d3084e9c82\"\u003e RUSTSCAN \u003c/a\u003e | THE MODERN PORT SCANNER |\n| \u003ca href=\"https://mikekitckchan.medium.com/holy-ffuf-a-beginner-guide-to-fuzz-with-ffuf-4bc6a66b5391\"\u003e Holy FFUF! \u003c/a\u003e | A Beginner Guide to Fuzz with FFUF |\n| \u003ca href=\"https://github.com/swisskyrepo/GraphQLmap\"\u003e GraphQLmap \u003c/a\u003e | This is a scripting engine to interact with a graphql endpoint for pentesting purposes |\n| \u003ca href=\"https://github.com/erev0s/VAmPI\"\u003eVAmPI \u003c/a\u003e | Vulnerable REST API with OWASP top 10 vulnerabilities for security testing |\n| \u003ca href=\"https://github.com/0x4ndy/clif\"\u003e Clif \u003c/a\u003e | This is a commandline interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. |\n| \u003ca href=\"https://github.com/r0oth3x49/ghauri\"\u003e Ghauri \u003c/a\u003e | This is an advanced crossplatform tool that automates the process of detecting and exploiting SQL injection security flaws |\n| \u003ca href=\"https://portswigger.net/blog/introducing-dom-invader\"\u003eDOM Invader \u003c/a\u003e | Introducing DOM Invader, DOM XSS just got a whole lot easier to find |\n| \u003ca href=\"https://github.com/MayankPandey01/Jira-Lens\"\u003eJiraLens \u003c/a\u003e | Fast and customizable vulnerability scanner For JIRA written in Python |\n| \u003ca href=\"https://github.com/rotemreiss/uddup\"\u003e Urls deduplication \u003c/a\u003e | Urls deduplication tool for better recon. |\n| \u003ca href=\"https://github.com/phith0n/zkar\"\u003e ZKar \u003c/a\u003e | This is a Java serialization protocol analysis tool implement in Go. |\n| \u003ca href=\"https://github.com/s0md3v/Smap\"\u003e Smap \u003c/a\u003e | This is a dropin replacement for Nmap powered by shodan.io |\n| \u003ca href=\"https://github.com/Stonzyy/dumpxss\"\u003e DumpXSS \u003c/a\u003e | A scanner tool For XSS Vulnerability |\n| \u003ca href=\"https://github.com/Sh1Yo/x8\"\u003ex8 \u003c/a\u003e | Hidden parameters discovery suite written in Rust |\n| \u003ca href=\"https://github.com/stark0de/nginxpwner\"\u003e Nginxpwner \u003c/a\u003e | This is a simple tool to look for common Nginx misconfigurations and vulnerabilities. |\n| \u003ca href=\"https://github.com/aress31/burpgpt\"\u003e BurpGPT \u003c/a\u003e | A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities, and enables running trafficbased analysis of any type. |\n| \u003ca href=\"https://caido.io/\"\u003e Caido \u003c/a\u003e | Lightweight Web Security Auditing Toolkit |\n| \u003ca href=\"https://securitytrails.com/blog/assetfinder\"\u003e AssetFinder \u003c/a\u003e | A Handy Subdomain and Domain Discovery Tool\u003c/a\u003e\n| \u003ca href=\"https://github.com/punk-security/secret-magpie\"\u003eSecret Magpie \u003c/a\u003e | Secret Detection Tool |\n| \u003ca href=\"https://googleprojectzero.blogspot.com/2021/04/designing-sock-fuzzer-network-syscall.html\"\u003e Designing sockfuzzer \u003c/a\u003e | A network syscall fuzzer for XNU. |\n| \u003ca href=\"https://github.com/kosmosec/proto-find\"\u003eProto Find \u003c/a\u003e | Check if your target is vulnerable for client side prototype pollution |\n| \u003ca href=\"https://github.com/KathanP19/protoscan\"\u003eProtoscan \u003c/a\u003e | Prototype Pollution Scanner made in Golang. |\n| \u003ca href=\"https://github.com/PabloMK7/ENLBufferPwn\"\u003eBufferPwn \u003c/a\u003e | RCE vulnerability in the common network code of several first party Nintendo games since the Nintendo 3DS |\n| \u003ca href=\"https://blog.intigriti.com/2021/10/05/hacker-tools-crlfuzz/\"\u003eCRLFuzz \u003c/a\u003e | Hacker Tools: Injecting CRLF for bounties \u003c/a\u003e\n| \u003ca href=\"https://portswigger.net/daily-swig/new-differential-fuzzing-tool-reveals-novel-http-request-smuggling-techniques\"\u003e NFT \u003c/a\u003e | New differential fuzzing tool reveals novel HTTP request smuggling techniques. |\n| \u003ca href=\"https://github.com/sa7mon/S3Scanner\"\u003eS3Scanner \u003c/a\u003e | Scan for open S3 buckets and dump the contents. |\n| \u003ca href=\"https://crates.io/crates/kurl\"\u003e Kurl \u003c/a\u003e | HTTP Requests for security researchers |\n| \u003ca href=\"https://github.com/dhn/udon\"\u003eUDON \u003c/a\u003e | A simple tool that helps to find assets/domains based on the Google Analytics ID. |\n| \u003ca href=\"https://github.com/projectdiscovery/proxify\"\u003eroxify \u003c/a\u003e | Swiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation, and replay on the go |\n| \u003ca href=\"https://www.revshells.com/\"\u003erevshells \u003c/a\u003e | Online  Reverse Shell Generator |\n| \u003ca href=\"https://github.com/Eilonh/s3crets_scanner\"\u003eS3cret Scanner\u003c/a\u003e | Hunting For Secrets Uploaded To Public S3 Buckets |\n| \u003ca href=\"https://github.com/redhuntlabs/HTTPLoot\"\u003eHTTPLoot \u003c/a\u003e | An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and \"loot\" secrets out of the clientfacing code of sites |\n| \u003ca href=\"https://www.hackingarticles.in/a-detailed-guide-on-cewl/\"\u003eCewl \u003c/a\u003e | A Detailed Guide on Cewl |\n| \u003ca href=\"https://github.com/hakluke/hakoriginfinder\"\u003ehakoriginfinder \u003c/a\u003e | A tool for discovering the origin host behind a reverse proxy. Useful for bypassing WAFs and other reverse proxies |\n| \u003ca href=\"https://github.com/carlospolop/PurplePanda\"\u003e PurplePanda \u003c/a\u003e | Identify privilege escalation paths within and across different clouds |\n| \u003ca href=\"https://github.com/ethicalhackingplayground/TProxer\"\u003e TProxer \u003c/a\u003e | A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF |\n| \u003ca href=\"https://github.com/PalindromeLabs/STEWS\"\u003eSTEWS \u003c/a\u003e | This is a tool suite for security testing of WebSockets |\n| \u003ca href=\"https://github.com/xerohackcom/webrecon\"\u003eWebrecon \u003c/a\u003e |  Automated Web Recon Shell Scripts |\n| \u003ca href=\"https://danielmiessler.com/study/ffuf/\"\u003e ffuf Primer \u003c/a\u003e | More on FFUF |\n| \u003ca href=\"https://github.com/Lu1sDV/wafme0w\"\u003eWafme0w \u003c/a\u003e | A fast and lightweight Web Application Firewall fingerprinting tool. |\n| \u003ca href=\"https://github.com/r0oth3x49/ghauri\"\u003eGhauri \u003c/a\u003e | An advanced crossplatform tool that automates the process of detecting and exploiting SQL injection security flaws |\n| \u003ca href=\"https://github.com/carlospolop/Leakos\"\u003e Leakos \u003c/a\u003e | Search with gitleaks and trufflehog in the responses of the given URLs or in all the repos of an organization and its members. |\n| \u003ca href=\"https://github.com/Anof-cyber/Pycript\"\u003e Pycript \u003c/a\u003e | This is a Burp Suite extension that enables users to encrypt and decrypt requests for manual and automated application penetration testing. |\n| \u003ca href=\"https://github.com/Josue87/gotator\"\u003e Gotator \u003c/a\u003e | This is a tool to generate DNS wordlists through permutations. |\n| \u003ca href=\"https://github.com/michelin/ChopChop\"\u003eChopChop \u003c/a\u003e | This is a CLI to help developers scanning endpoints and identifying exposition of sensitive services/files/folders |\n| \u003ca href=\"https://iosiro.com/blog/baserunner-exploiting-firebase-datastores\"\u003eBaserunner\u003c/a\u003e | This is a tool for exploring and exploiting Firebase datastores |\n| \u003ca href=\"https://github.com/r0075h3ll/Oralyzer\"\u003eOralyzer \u003c/a\u003e | This a simple python script that probes for Open Redirection vulnerability in a website. It does that by fuzzing the URL that is provided in the input |\n| \u003ca href=\"https://github.com/roottusk/vapi\"\u003evAPI \u003c/a\u003e | This is Vulnerable Adversely Programmed Interface which is SelfHostable API that mimics OWASP API Top 10 scenarios in the means of Exercises. |\n| \u003ca href=\"https://github.com/edoardottt/favirecon\"\u003eFIVERECON \u003c/a\u003e | Use favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services. |\n| \u003ca href=\"https://blog.intigriti.com/2022/03/01/hacker-tools-turbo-intruder/\"\u003eTurbo Intruder \u003c/a\u003e | This Hacker Tool is Going faster than ever! |\n| \u003ca href=\"https://gitlab.com/shodanpublic/nrich\"\u003enrich \u003c/a\u003e | A commandline tool to quickly analyze all IPs in a file and see which ones have open ports/ vulnerabilities. Can also be fed data from stdin to be used in a data pipeline. |\n| \u003ca href=\"https://blog.intigriti.com/2022/02/01/hacker-tools-meg/\"\u003eMeg \u003c/a\u003e | Endpoint scan the masses! |\n| \u003ca href=\"https://github.com/d3mondev/puredns\"\u003ePureDNS \u003c/a\u003e | Subdomain bruteforcing tool that improves massdns to accurately handle wildcard subdomains and DNS poisoning. |\n| \u003ca href=\"https://research.nccgroup.com/2022/08/25/tool-release-jwt-reauth/\"\u003eJWTReauth\u003c/a\u003e | A new tool for JWT Reauth issues |\n| \u003ca href=\"https://github.com/0xmoot/s3sec\"\u003eS3Sec \u003c/a\u003e | Check AWS S3 instances for read/write/delete access |\n| \u003ca href=\"https://securitytrails.com/blog/uniscan\"\u003eUniscan \u003c/a\u003e | An RFI, LFI, and RCE Vulnerability Scanner |\n| \u003ca href=\"https://github.com/bcoles/jira_scan\"\u003eJira Scan \u003c/a\u003e | This is a simple remote scanner for Atlassian Jira. |\n| \u003ca href=\"https://spaceraccoon.github.io/webpack-exploder/\"\u003eWebpack Exploder \u003c/a\u003e | Unpack the source code of React and other Webpacked Javascript apps! Check out Expanding the Attack Surface. |\n| \u003ca href=\"https://github.com/DigeeX/raider\"\u003eRaider \u003c/a\u003e | Web authentication testing framework |\n| \u003ca href=\"https://github.com/gokulapap/Reconator\"\u003eReconator \u003c/a\u003e | Automated Recon for Pentesting \u0026 Bug Bounty |\n| \u003ca href=\"https://github.com/whwlsfb/Log4j2Scan\"\u003eLog4j2Scan \u003c/a\u003e | Log4j2 RCE Passive Scanner plugin for BurpSuite |\n| \u003ca href=\"https://github.com/iamnihal/warf\"\u003e WARF \u003c/a\u003e | This is a Web Application Reconnaissance Framework that helps to gather information about the target. |\n| \u003ca href=\"https://github.com/m3n0sd0n4ld/GooFuzz\"\u003eGooFuzz \u003c/a\u003e | GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking). |\n| \u003ca href=\"https://github.com/fingerprintjs/gradejs\"\u003eGradeJS \u003c/a\u003e | This tool analyzes production Webpack bundles without having access to the source code of a website. |\n| \u003ca href=\"https://github.com/xnl-h4ck3r/waymore\"\u003eWaymore \u003c/a\u003e | Find way more from the Wayback Machine! |\n| \u003ca href=\"https://github.com/carlospolop/Pastos\"\u003ePastos \u003c/a\u003e | Search pastes in tens of webs in seconds with GCSE. |\n| \u003ca href=\"https://github.com/gwen001/gitlab-subdomains\"\u003egitlabsubdomains \u003c/a\u003e | Find subdomains on GitLab |\n| \u003ca href=\"https://github.com/glebarez/cero\"\u003e Cero \u003c/a\u003e | Scrape domain names from SSL certificates of arbitrary hosts |\n| \u003ca href=\"https://github.com/s0md3v/Smap\"\u003eSmap \u003c/a\u003e | Passive Nmap like scanner built with shodan.io |\n| \u003ca href=\"https://github.com/merttasci/csrf-poc-generator\"\u003eCSRF Generator \u003c/a\u003e | This html file creates a csrf poc form to any http request. |\n| \u003ca href=\"https://github.com/aquasecurity/trivy\"\u003e Trivy \u003c/a\u003e | A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI |\n| \u003ca href=\"https://github.com/gfek/Lepus\"\u003eLepus \u003c/a\u003e | This is a tool for enumerating subdomains, checking for subdomain takeovers and perform port scans  and boy, is it fast! |\n| \u003ca href=\"https://github.com/elceef/subzuf\"\u003esubzuf \u003c/a\u003e | subzuf is a subdomain bruteforce fuzzer coupled with an immensly simple but effective DNS reponseguided algorithm. |\n| \u003ca href=\"https://github.com/edoardottt/csprecon\"\u003ecsprecon \u003c/a\u003e | Discover new target domains using Content Security Policy |\n| \u003ca href=\"https://github.com/iamthefrogy/frogy/\"\u003eFrogy \u003c/a\u003e | Using the combination of different subdomain enumeration tools and logic this script tries to identify more subdomains and TLDs in recon. |\n| \u003ca href=\"https://github.com/xnl-h4ck3r/xnLinkFinder\"\u003exnLinkFinder \u003c/a\u003e | A python tool used to discover endpoints for a given target |\n| \u003ca href=\"https://github.com/MayankPandey01/BrokenLinkHijacker\"\u003eBLH \u003c/a\u003e | BrokenLinkHijacker is a Fast Broken Link Hijacker Tool written in Python |\n| \u003ca href=\"https://medium.com/@thebugbountyhunter/review-netlasio-for-bugbounty-c062a87b544f\"\u003enetlas.io \u003c/a\u003e | A new search engine for discover, research and monitor any asset. It is so useful for your #bugbounty recon automation. |\n| \u003ca href=\"https://github.com/punk-security/secret-magpie\"\u003eSecretMagpie \u003c/a\u003e | A secret detection tool that hunts out all the secrets hiding in all your repositories. |\n| \u003ca href=\"https://github.com/codingo/bbr\"\u003ebbr \u003c/a\u003e | It is an open source tool to aid in command line driven generation of bug bounty reports based on user provided templates. |\n| \u003ca href=\"https://oweng.medium.com/introducing-packet-streamer-distributed-packet-capture-for-cloud-native-platforms-3e7f9ac57ab1\"\u003ePacketStreamer \u003c/a\u003e | This is a tool for distributed packet capture for cloudnative platforms |\n| \u003ca href=\"https://github.com/hisxo/JSpector\"\u003eJSpector \u003c/a\u003e | It is a Burp Suite extension that passively crawls JavaScript files and automatically creates issues with URLs and endpoints found on the JS files |\n| \u003ca href=\"https://blog.projectdiscovery.io/uncover/\"\u003eUncover \u003c/a\u003e | Quickly discover exposed hosts using multiple search engines |\n| \u003ca href=\"https://blog.projectdiscovery.io/asnmap/\"\u003eASNMap \u003c/a\u003e | A Golang CLI tool for speedy reconnaissance using ASN data |\n| \u003ca href=\"https://github.com/dwisiswant0/go-dork\"\u003eGo Dork \u003c/a\u003e | The fastest dork scanner written in Go |\n| \u003ca href=\"https://github.com/s0md3v/uro\"\u003euro \u003c/a\u003e | Declutters url lists for crawling/pentesting |\n| \u003ca href=\"https://github.com/google/clusterfuzzlite\"\u003eClusterFuzzLite \u003c/a\u003e | Simple continuous fuzzing that runs in CI |\n| \u003ca href=\"https://github.com/carlospolop/Gorks\"\u003eGorks \u003c/a\u003e | Google Dorks finally made easy to run without hiding. |\n| \u003ca href=\"https://github.com/mosajjal/dnsmonster\"\u003ednsmonster \u003c/a\u003e | Passive DNS Capture/Monitoring Framework |\n| \u003ca href=\"https://research.securitum.com/fail2ban-remote-code-execution/\"\u003efail2ban \u003c/a\u003e | Remote Code Execution |\n| \u003ca href=\"https://github.com/dwisiswant0/ppfuzz?tag=v1.0.0\"\u003eppfuzz \u003c/a\u003e | Prototype Pollution Fuzzer |\n| \u003ca href=\"https://github.com/root-tanishq/userefuzz\"\u003euserefuzz \u003c/a\u003e | UserAgent , XForwardedFor and Referer SQLI Fuzzer |\n| \u003ca href=\"https://github.com/Sachin-v3rma/Astra\"\u003eAstra \u003c/a\u003e | Astra finds urls, endpoints, aws buckets, api keys, tokens, etc from a given url/s |\n| \u003ca href=\"https://github.com/projectdiscovery/cloudlist\"\u003e Cloudlist \u003c/a\u003e | This is a tool for listing Assets from multiple Cloud Providers |\n| \u003ca href=\"https://github.com/as0ler/r2flutch\"\u003er2flutch \u003c/a\u003e | A tool to decrypt iOS apps using r2frida |\n| \u003ca href=\"https://shahjerry33.medium.com/shodan-dorks-the-gods-eye-f224f9b3984f\"\u003eShodan Dorks \u003c/a\u003e | The H4CK3R God’s Eye |\n| \u003ca href=\"https://github.com/mqst/gouge\"\u003eGouge \u003c/a\u003e | Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp Suite |\n| \u003ca href=\"https://github.com/musana/mx-takeover\"\u003emxtakeover \u003c/a\u003e | This tool focuses DNS MX records and detects misconfigured MX records. |\n\n\n\n\n\n\n\n# General Writeups\n\n| Description |\n|-----|\n| \u003ca href=\"https://peterjson.medium.com/miracle-one-vulnerability-to-rule-them-all-c3aed9edeea2\"\u003eMiracle  One Vulnerability To Rule Them All\u003c/a\u003e |\n| \u003ca href=\"https://github.com/morpheansec/secure-smart-contract-design-principles\"\u003eSaltzer and Schroeder's 10 secure design principles as applied to solidity smart contracts.\u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/dailyswig/teen-hacker-scoops-4500-bug-bounty-for-facebook-flaw-that-allowed-attackers-to-unmask-page-admins\"\u003eTeen hacker scoops $4,500 bug bounty for Facebook flaw that allowed attackers to unmask page admins\u003c/a\u003e |\n| \u003cA href=\"https://medium.com/@fcwdbrqmr/400-bounty-again-using-google-dorks-6dc8e438f017\"\u003e400$ Bounty again using Google Dorks\u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/research/top-10-web-hacking-techniques-of-2020\"\u003eTop 10 web hacking techniques of 2020 | PortSwigger Research\u003c/a\u003e |\n| \u003ca href=\"https://infosecwriteups.com/how-gopher-works-in-escalating-ssrfs-ce6e5459b630\"\u003eHow Gopher works in escalating SSRFs\u003c/a\u003e |\n| \u003ca href=\"https://cloudsecurityalliance.org/blog/2023/09/01/gcp-cloudsql-vulnerability-leads-to-internal-container-access-and-data-exposure\"\u003eGCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure\u003c/a\u003e |\n| \u003ca href=\"https://labs.detectify.com/2021/08/10/how-to-hack-apis-in-2021/\"\u003eHow to Hack APIs in 2021\u003c/a\u003e |\n| \u003ca href=\"https://akshitainfosec.medium.com/burp-macros-what-why-how-151df8901641\"\u003eBurp Macros: What, Why \u0026 How?\u003c/a\u003e |\n| \u003ca href=\"https://sicks3c.medium.com/set-up-your-private-burp-collaborator-for-ssrf-xxe-fd6cf01c8ca\"\u003eSetup Your Private Burp Collaborator for SSRF/XXE\u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/blog/experience-burp-suite-enterprise-edition-in-a-new-live-demo\"\u003eExperience Burp Suite Enterprise Edition in a new live demo\u003c/a\u003e |\n| \u003cA href=\"https://www.pavel.gr/blog/dll-hijacking-using-spartacus\"\u003eDLL Hijacking using Spartacus, outside of DllMain\u003c/a\u003e |\n| \u003ca href=\"https://github.com/mrh0wl/Cloudmare\"\u003eCloudflare, Sucuri, Incapsula real IP tracker\u003c/a\u003e |\n| \u003ca href=\"https://mikekitckchan.medium.com/a-brief-introduction-to-prototype-pollution-b154c23b40c5\"\u003eA Brief Introduction to Prototype Pollution\u003c/a\u003e |\n| \u003ca href=\"https://devsecopsdocs.com/blog/nuclear-pond/\"\u003eNuclear Pond\u003c/a\u003e |\n| \u003ca href=\"https://blog.securelayer7.net/static-analysis-of-android-application-tools-used-securelayer7/\"\u003eOWASP Top 10: Static Analysis of Android Application \u0026 Tools Used\u003c/a\u003e |\n| \u003ca href=\"https://github.com/iustin24/chameleon\"\u003eChameleon provides better content discovery by using wappalyzer's set of technology fingerprints alongside custom wordlists tailored to each detected technologies\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@murami.ike/working-with-a-scope-using-gowitness-4d338b0321ac\"\u003eWorking with a scope using Gowitness\u003c/a\u003e |\n| \u003ca href=\"https://thexssrat.medium.com/what-the-fuzz-the-truth-behind-content-discovery-77cd0c0756e7\"\u003eWhat the fuzz?! — The truth behind content discovery\u003c/a\u003e |\n| \u003ca href=\"https://security.googleblog.com/2023/05/introducing-new-way-to-buzz-for-ebpf.html\"\u003eIntroducing a new way to buzz for eBPF vulnerabilities\u003c/a\u003e |\n| \u003ca href=\"https://securityboulevard.com/2023/03/remote-code-execution-vulnerability-in-azure-pipelines-can-lead-to-software-supply-chain-attack/\"\u003eRemote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack\u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/daily-swig/security-researcher-earns-plaudits-after-discovering-yandex-ssrf-flaw\"\u003eSecurity researcher earns plaudits after discovering Yandex SSRF flaw\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/pentesternepal/how-i-was-able-to-reveal-page-admin-of-almost-any-page-on-facebook-5a8d68253e0c\"\u003eHow I was able to reveal page admin of almost any page on Facebook\u003c/a\u003e |\n| \u003ca href=\"https://xkurtph.medium.com/shopify-plugin-bypass-using-client-side-injection-thru-api-implementation-vulnerability-710d25105c8f\"\u003eShopify Plugin Bypass using P3 Clientside injection thru API Implementation Vulnerability\u003c/a\u003e |\n| \u003ca href=\"https://github.com/honoki/bugbounty-openvpn-socks\"\u003eRun all your bug bounty VPN profiles in parallel and expose them via multiple local SOCKS proxies.\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/pentesternepal/a-tale-of-zero-click-account-takeover-56b51fdbd7ae\"\u003eA tale of zero click account takeover\u003c/a\u003e |\n| \u003ca href=\"https://hacktus.tech/subdomain-takeover-leading-to-full-account-takeover\"\u003eSubdomain Takeover leading to Full Account Takeover\u003c/a\u003e |\n| \u003ca href=\"https://n00b.sh/posts/aes-killer-mobile-app-demo/\"\u003eDecrypting Mobile App Traffic using AES Killer and Frida\u003c/a\u003e |\n| \u003ca href=\"https://thexssrat.medium.com/csrf-tes-guide-for-bug-bounty-hunters-d14db3462695\"\u003eCSRF Testing Guide For Bug Bounty Hunters\u003c/a\u003e |\n| \u003ca href=\"https://github.com/Hacker0x01/awesome-hacker-api-tools\"\u003eA collection of hacker tools using HackerOne's API\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/414101\"\u003eVulnerabilities in exported activity WebView\u003c/a\u003e |\n| \u003ca href=\"https://offsec.almond.consulting/ghostscript-cve-2023-28879.html\"\u003eShell in the Ghost: Ghostscript CVE202328879 writeup\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@Sm9l/bug-bounty-recon-horizontal-correlation-b7c81a32951a\"\u003eBug Bounty Recon: Horizontal Correlation\u003c/a\u003e |\n| \u003ca href=\"https://infosecwriteups.com/how-i-found-multiple-sql-injection-with-ffuf-and-sqlmap-in-a-few-minutes-2824cd4dfab\"\u003eHow I Found multiple SQL Injection with FFUF and Sqlmap in a few minutes\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@sarafsaransh321/how-i-earned-240-from-a-zero-interface-53d244a231f9\"\u003eHow I earned 240$ from a Zero Interface\u003c/a\u003e |\n| \u003ca href=\"https://rloura.wordpress.com/2020/12/04/reversing-flutter-for-android-wip/\"\u003eReverse engineering Flutter for Android + Doldrums (Doldrums is a reverse engineering tool for Flutter apps) |\n| \u003ca href =\"https://github.com/rscloura/Doldrums\"\u003eTool Link = _Doldrum Tool_\u003c/a\u003e\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/r3dbuck3t/top-10-tips-for-burpsuite-72212d22328f\"\u003eTop 10 Tips for Burp Suite\u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/blog/server-side-prototype-pollution-scanner\"\u003eServerSide Prototype Pollution Scanner\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@dhananjaytupe748/fuff-and-seclists-4599b2677f\"\u003eFUFF and SecLists\u003c/a\u003e |\n| \u003ca href=\"https://www.wiz.io/blog/hells-keychain-supply-chain-attack-in-ibm-cloud-databases-for-postgresql\"\u003eHell’s Keychain: Supplychain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access \u003c/a\u003e |\n| \u003ca href=\"https://www.synacktiv.com/sites/default/files/2023-03/Synacktiv-Grails-Spring-Security-CVE-2022-41923.pdf\"\u003eImproper Privilege Management in Grails Spring Security Core \u003c= 5.1.0 CVE202241923\u003c/a\u003e |\n| \u003ca href=\"https://terjanq.medium.com/waf-bypasses-via-0days-d4ef1f212ec\"\u003eWAF bypasses via 0days\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@querylab/idor-and-api-keys-token-hard-code-exposed-201c73d2d667\"\u003eIDOR and APIkeys🔑Token Hardcode Exposed\u003c/a\u003e |\n| \u003ca href=\"https://www.rcesecurity.com/2022/07/WordPress-Transposh-Exploiting-a-Blind-SQL-Injection-via-XSS/\"\u003eHere's my story about 8 CVEs resulting in a plugin removal and more than $30,000 in bounties!\u003c/a\u003e |\n| \u003ca href=\"https://rashahacks.com/how-i-fuzz-and-hack-api/\"\u003eHow I fuzz and hack APIs?\u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/daily-swig/prototype-pollution-like-bug-variant-discovered-in-python\"\u003ePrototype pollution like bug variant discovered in Python\u003c/a\u003e |\n| \u003ca href=\"https://trufflesecurity.com/blog/ofcors/index.html\"\u003eBypass firewalls with ofCORs and typosquatting\u003c/a\u003e |\n| \u003ca href=\"https://securitylabs.datadoghq.com/articles/iamadmin-cloudtrail-bypass/\"\u003eAWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass\u003c/a\u003e |\n| \u003ca href=\"https://vulncheck.com/blog/cve-2022-47966-payload\"\u003eA Different Payload for CVE202247966\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@Brian.IsMeta/difficulty-of-reproducing-old-exploits-a613da2c2143\"\u003eDifficulty of Reproducing Old Exploits (Part 1)\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@Brian.IsMeta/difficulty-of-reproducing-old-exploits-part-two-3c2db88232e5\"\u003eDifficulty of Reproducing Old Exploits (Part 2)\u003c/a\u003e | \n| \u003ca href=\"https://www.immersivelabs.com/blog/we-discovered-major-vulnerabilities-in-control-web-panel-heres-how-we-found-them/\"\u003eWe discovered major vulnerabilities in Control Web Panel. Here’s how we found them\u003c/a\u003e |\n| \u003ca href=\"https://srcincite.io/blog/2022/08/09/from-shared-dash-to-root-bash-pre-authenticated-rce-in-vmware-vrealize-operations-manager.html\"\u003eFrom Shared Dash to Root Bash :: PreAuthenticated RCE in VMWare vRealize Operations Manager\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@_deshine_/account-takeover-due-to-aws-cognito-misconfiguration-7b092c667ee3\"\u003eAccount Take Over Due To AWS Cognito Misconfiguration\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1439026\"\u003eDiscoverability by phone number/email restriction bypass\u003c/a\u003e |\n| \u003ca href=\"https://slashparity.com/?p=938\"\u003eGCP Pentesting Guide\u003c/a\u003e |\n| \u003ca href=\"https://www.dsecbypass.com/en/centreon-map-vulnerability/\"\u003eCentreon map vulnerability\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@coffeeaddict_exe/500-in-5-minutes-45977e89a337\"\u003e$500 in 5 minutes\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1273292\"\u003eInternal Gitlab Ticket Disclosure via External Slack Channels\u003c/a\u003e |\n| \u003ca href=\"https://labs.detectify.com/2021/09/30/10-types-web-vulnerabilities-often-missed/\"\u003e10 Types of Web Vulnerabilities that are Often Missed\u003c/a\u003e |\n| \u003ca href=\"https://ahmdhalabi.medium.com/ultimate-reconnaissance-roadmap-for-bug-bounty-hunters-pentesters-507c9a5374d\"\u003eUltimate Reconnaissance RoadMap for Bug Bounty Hunters \u0026 Pentesters\u003c/a\u003e |\n| \u003ca href=\"https://www.legitsecurity.com/blog/how-to-continuously-detect-vulnerable-jenkins-pluins-to-avoid-a-software-supply-chain-attack\"\u003eHow to Continuously Detect Vulnerable Jenkins Plugins to Avoid a Software Supply Chain Attack\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@soyelmago/bypassing-a-creation-limit-on-free-accounts-a-race-condition-vulnerability-in-bug-bounty-program-33e69592d36a\"\u003eBypassing a Creation Limit on Free Accounts: A Race Condition Vulnerability in Bug Bounty Program\u003c/a\u003e |\n| \u003ca href=\"https://blog.projectdiscovery.io/implementing-nuclei-into-your-gitlab-ci-cd-pipeline-for-scanning-live-web-applications/\"\u003eImplementing Nuclei into your Bitbucket CI/CD Pipeline for Scanning Live Web Applications\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@akashtesla/how-to-automate-your-initial-recon-and-extend-asm-using-subscout-a52de14a2b6a\"\u003eHow to automate your initial recon and extend ASM using SubScout\u003c/a\u003e |\n| \u003ca href=\"https://research.aurainfosec.io/pentest/pentah0wnage/\"\u003ePentah0wnage: PreAuth RCE in Pentaho Business Analytics Server\u003c/a\u003e |\n| \u003ca href=\"https://omar0x01.medium.com/company-building-takeover-10a422385390\"\u003eFull Company Building Takeover\u003c/a\u003e |\n| \u003ca href=\"https://sector7.computest.nl/post/202301xar/\"\u003eBad things come in large packages: .pkg signature verification bypass on macOS\u003c/a\u003e |\n| \u003ca href=\"https://blog.impalabs.com/2303_advisory_parallelsdesktop_toolgate.html\"\u003eParallels Desktop Toolgate Vulnerability\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/immunefi/aurora-withdrawal-logic-error-bug-fix-review-c5b4e30a9160\"\u003eAurora Withdrawal Logic Error Bugfix Review\u003c/a\u003e |\n| \u003ca href=\"https://blog.protekkt.com/blog/basic-webassembly-buffer-overflow-exploitation-example\"\u003eBasic WebAssembly buffer overflow exploitation\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1501611\"\u003eAn attacker can archive and unarchive any structured scope object on HackerOne\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1295844\"\u003eModify inflight data to payment provider Smart2Pay\u003c/a\u003e |\n| \u003ca href=\"https://arxiv.org/pdf/2110.07450.pdf\"\u003eBugs in our Pockets: The Risks of ClientSide Scanning\u003c/a\u003e |\n| \u003ca href=\"http://ysamm.com/?p=620\"\u003eMake recruiting referrals on behalf of employees ($3000)\u003c/a\u003e |\n| \u003ca href=\"https://blog.assetnote.io/2023/02/01/rce-in-avaya-aura/\"\u003eRCE in Avaya Aura Device Services\u003c/a\u003e |\n| \u003ca href=\"https://jakearchibald.com/2021/cors/\"\u003eHow to win at CORS\u003c/a\u003e |\n| \u003ca href=\"https://blog.abdulrah33m.com/prototype-pollution-in-python/\"\u003ePrototype Pollution in Python\u003c/a\u003e |\n| \u003ca href=\"https://www.wiz.io/blog/attachme-oracle-cloud-vulnerability-allows-unauthorized-cross-tenant-volume-access\"\u003eAttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes \u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@noob.assassin/5k-misconfigured-reset-password-that-leads-to-account-takeover-no-user-interaction-ato-e6a36b8ef183\"\u003eMisconfigured Reset password that leads to Account Takeover (No user Interaction ATO)\u003c/\u003e |\n| \u003ca href=\"https://yogehi.github.io/research/2023/01/04/10-cves-my-personal-thoughts-on-research-and-cves.html\"\u003e10 CVEs! My Personal Thoughts On Research And CVEs\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@Cybervenom/story-about-escalation-of-html-injection-to-ec2-instance-credentials-leak-e2cbd7343a83\"\u003eStory about Escalation of HTML Injection to EC2 Instance credentials leak\u003c/a\u003e |\n| \u003ca href=\"https://tutorialboy24.blogspot.com/2022/09/the-blind-exploits-to-rule-watchguard.html\"\u003eThe Blind Exploits To Rule Watchguard Firewalls Vulnerabilities\u003c/a\u003e |\n| \u003ca href=\"http://ysamm.com/?p=597\"\u003eView orders and financial reports lists for any page shop ($500)\u003c/a\u003e |\n| \u003ca href=\"https://ddosify.com/blog/testing-the-performance-of-user-authentication-flow\"\u003eTesting the Performance of User Authentication Flow\u003c/a\u003e |\n| \u003ca href=\"https://infosecwriteups.com/hunting-for-prototype-pollution-and-its-vulnerable-code-on-js-libraries-5bab2d6dc746\"\u003eHunting for Prototype Pollution and it’s vulnerable code on JS libraries\u003c/a\u003e |\n| \u003ca href=\"https://www.hackerone.com/guest-blog-governments-across-world-are-mandating-vulnerability-disclosure-so-why-are-companies\"\u003eGovernments Across The World Are Mandating Vulnerability Disclosure So Why Are Companies Sitting On Their Hands?\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@shakti.gtp/if-its-a-feature-lets-abuse-it-for-750-19cfb9848d4b\"\u003eIf It’s a Feature!!! Let’s Abuse It for $750\u003c/a\u003e |\n| \u003ca href=\"https://vedanttekale20.medium.com/story-of-my-first-cash-bounty-on-hackerone-acad282ae962\"\u003eStory of my first cash bounty on hackerone\u003c/a\u003e |\n| \u003ca href=\"https://vikaran101.medium.com/how-i-made-it-into-the-united-nations-hall-of-fame-as-i-slept-f567c90be227\"\u003eHow I made it into the United Nations hall of fame as I slept\u003c/a\u003e |\n| \u003ca href=\"https://spaceraccoon.dev/embedding-payloads-bypassing-controls-microsoft-infopath/\"\u003eEmbedding Payloads and Bypassing Controls in Microsoft InfoPath\u003c/a\u003e |\n| \u003ca href=\"https://blog.stazot.com/ssh-key-injection-google-cloud/\"\u003eSSH key injection in Google Cloud Compute Engine (Google VRP)\u003c/a\u003e |\n| \u003ca href=\"https://blog.assetnote.io/2022/09/14/rce-in-bitbucket-server/\"\u003eBreaking Bitbucket: Pre Auth Remote Command Execution (CVE202236804)\u003c/a\u003e |\n| \u003ca href=\"https://shahjerry33.medium.com/http-parameter-pollution-its-contaminated-again-95c75b0295e1\"\u003eHTTP Parameter Pollution  It’s Contaminated Again\u003c/a\u003e |\n| \u003ca href=\"https://chaosdb.wiz.io/\"\u003eCritical Vulnerability in Microsoft Azure Cosmos DB\u003c/a\u003e |\n| \u003ca href=\"https://spyclub.tech/2022/12/14/unusual-cache-poisoning-akamai-s3/\"\u003eUnusual Cache Poisoning between Akamai and S3 buckets\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@sazouki/how-i-hacked-one-of-the-biggest-airline-in-the-world-e7810dc43791\"\u003eHow I hacked one of the biggest Airline in the world\u003c/a\u003e |\n| \u003ca href=\"https://sinsinology.medium.com/bug-bounty-short-tips-as-image-b4075523e4ef\"\u003eBug Bounty Short Tips as image\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/pentesternepal/how-i-found-a-bug-in-apple-within-just-in-5-min-d7357237d7a0\"\u003eHow I found a bug in Apple within just in 5min\u003c/a\u003e |\n| \u003ca href=\"https://www.assetnote.io/resources/research/chaining-vulnerabilities-to-criticality-in-progress-whatsup-gold\"\u003eChaining vulnerabilities to criticality in Progress WhatsUp Gold\u003c/a\u003e |\n| \u003ca href=\"https://blog.nietaanraken.nl/posts/aur-packages-github-repo-jacking\"\u003eHijacking Arch Linux Packages by Repo Jacking GitHub Repositories\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@0x4kd/google-sso-misconfiguration-leading-to-account-takeover-cf9bcf63e76e\"\u003eGoogle SSO misconfiguration leading to Account Takeover\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/techiepedia/how-i-found-my-first-chrome-bug-cve-2021-21210-248a21272248\"\u003eHow I found my first Chrome bug\u003c/a\u003e |\n| \u003ca href=\"https://giraffesecurity.dev/posts/dependabot-confusion/\"\u003eDependabot Confusion: Gaining Access to Private GitHub Repositories using Dependabot\u003c/a\u003e |\n| \u003ca href=\"https://lspace.swyx.io/p/reverse-prompt-eng\"\u003eReverse Prompt Engineering for Fun and (no) Profit\u003c/a\u003e |\n| \u003ca href=\"https://blog.oversecured.com/Two-weeks-of-securing-Samsung-devices-Part-2/\"\u003eThe second part of discovered vulnerabilities in preinstalled apps on Samsung devices\u003c/a\u003e |\n| \u003ca href=\"https://sneakymonkey.net/cloud-credential-abuse/\"\u003eCloud Metadata  AWS IAM Credential Abuse\u003c/a\u003e |\n| \u003ca href=\"https://www.youtube.com/watch?v=ZUXUz22dCiQ\"\u003e$300 Google API key leaked to Public on Live Website\u003c/a\u003e |\n| \u003ca href=\"https://sinsinology.medium.com/expect-the-unexpected-discovering-fresh-zero-day-for-bounty-d074f3175847\"\u003eExpect The Unexpected: Discovering fresh ZeroDay for Bounty\u003c/a\u003e |\n| \u003ca href=\"https://www.sonarsource.com/blog/securing-developer-tools-a-new-supply-chain-attack-on-php/\"\u003eSecuring Developer Tools: A New Supply Chain Attack on PHP\u003c/a\u003e |\n| \u003ca href=\"https://neodyme.io/blog/csgo_from_zero_to_0day/\"\u003eCS:GO : From Zero to 0day \u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@mrempy/how-i-found-a-critical-p1-bug-in-5-minutes-using-a-cellphone-bug-bounty-303ebec3edd6\"\u003eHow I found a critical P1 bug in 5 minutes using a cellphone — Bug Bounty\u003c/a\u003e |\n| \u003ca href=\"https://www.youtube.com/watch?v=zNr43szGs\"\u003eThe DeFi Threat Model\u003c/a\u003e |\n| \u003ca href=\"https://rambo.codes/posts/2022-10-25-sirispy-ios-bug-allowed-apps-to-eavesdrop\"\u003eSiriSpy  iOS bug allowed apps to eavesdrop on your conversations with Siri\u003c/a\u003e |\n| \u003ca href=\"https://haiderm.com/how-i-was-able-to-delete-13k-microsoft-translator-projects/\"\u003eHow I was able to delete 13k+ Microsoft Translator projects\u003c/a\u003e |\n| \u003ca href=\"https://hackeronehackers.affinity.co/\"\u003eLeaked H1's Employees Email addresses,meeting info on private bug bounty program\u003c/a\u003e |\n| \u003ca href=\"https://www.ryanpickren.com/safari-uxss\"\u003eHacking the Apple Webcam (again)\u003c/a\u003e |\n| \u003ca href=\"https://news.sophos.com/en-us/2022/08/30/javascript-bugs-aplenty-in-node-js-ecosystem-found-automatically/\"\u003eJavaScript bugs aplenty in Node.js ecosystem – found automatically\u003c/a\u003e |\n| \u003ca href=\"https://hogarth45.medium.com/bug-bounty-fire-goals-6663a7980984\"\u003eBug Bounty FIRE Goals\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1404612\"\u003eMultiple vulnerability leading to account takeover in TikTok SMB subdomain.\u003c/a\u003e |\n| \u003ca href=\"https://tuhin1729.medium.com/story-of-my-hacking-dutch-government-46b7a3c8b75a\"\u003eStory of my hacking Dutch Government\u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/research/bypassing-csp-with-dangling-iframes\"\u003eBypassing CSP with dangling iframes \u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/blog/finding-client-side-prototype-pollution-with-dom-invader\"\u003eFinding clientside prototype pollution with DOM Invader\u003c/a\u003e |\n| \u003ca href=\"https://scribesecurity.com/blog/github-cache-poisoning/\"\u003eGitHub Cache Poisoning\u003c/a\u003e |\n| \u003ca href=\"https://www.legitsecurity.com/blog/dos-via-software-supply-chain-innumerable-projects-exposed-to-a-markdown-library-vulnerability\"\u003eThe MarkdownTime Vulnerability: How to Avoid This DoS Attack on Business Critical Services\u003c/a\u003e |\n| \u003ca href=\"https://ysamm.com/?p=763\"\u003eMultiple bugs chained to takeover Facebook Accounts which uses Gmail.\u003c/a\u003e |\n| \u003ca href=\"https://secret.club/2022/05/11/fuzzing-solana.html\"\u003eEarn $200K by fuzzing for a weekend: Part 1\u003c/a\u003e |\n| \u003ca href=\"https://secret.club/2022/05/11/fuzzing-solana-2.html\"\u003eEarn $200K by fuzzing for a weekend: Part 2\u003c/a\u003e |\n| \u003ca href=\"https://jhftss.github.io/CVE-2022-26712-The-POC-For-SIP-Bypass-Is-Even-Tweetable/\"\u003eCVE202226712: The POC for SIPBypass Is Even Tweetable\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@nanwinata/a-big-company-admin-panel-takeover-4500-9520a6c83430\"\u003eA Big company Admin Panel takeover $4500\u003c/a\u003e |\n| \u003ca href=\"https://www.sonarsource.com/blog/openemr-remote-code-execution-in-your-healthcare-system/\"\u003eOpenEMR  Remote Code Execution in your Healthcare System\u003c/a\u003e |\n| \u003ca href=\"https://blog.viettelcybersecurity.com/cve-2022-1040-sophos-xg-firewall-authentication-bypass/\"\u003eCVE20221040 Sophos XG Firewall Authentication bypass\u003c/a\u003e |\n| \u003ca href=\"https://spaceraccoon.dev/exploiting-icalendar-properties-enterprise-applications/\"\u003eYou Have One New Appointment: Exploiting iCalendar Properties in Enterprise Applications\u003c/a\u003e |\n| \u003ca href=\"https://maheshbasnet.medium.com/how-fuzzing-can-boost-you-bug-bounty-career-49e499900aa9\"\u003eFuzzing for Bug Bounty Hunting\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/immunefi/hacking-the-blockchain-an-ultimate-guide-4f34b33c6e8b\"\u003eHacking the Blockchain: An Ultimate Guide\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@taniyatesting11/bounty-evaluation-github-15-000-us-dollars-rate-limit-d6c07d73c948\"\u003eBounty Evaluation GitHub = $15,000 US Dollars \u003c/a\u003e |\n| \u003ca href=\"https://starlabs.sg/blog/2022/07-gitlab-project-import-rce-analysis-cve-2022-2185/\"\u003eGitlab Project Import RCE Analysis (CVE20222185)\u003c/a\u003e |\n| \u003ca href=\"https://vulncheck.com/blog/joomla-for-rce\"\u003eJoomla! CVE202323752 to Code Execution\u003c/a\u003e |\n| \u003ca href=\"https://securityintelligence.com/posts/msmq-queuejumper-rce-vulnerability-technical-analysis/\"\u003eMSMQ QueueJumper (RCE Vulnerability): An InDepth Technical Analysis\u003c/a\u003e |\n| \u003ca href=\"https://curtbraz.medium.com/a-konami-code-for-vuln-chaining-combos-1a29d0a27c2a\"\u003eA Konami Code for Vuln Chaining Combos\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@amnotacat/log4shell-in-google-133700-144684269bf8\"\u003eLog4shell in google $1337.00 \u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1377748\"\u003e2 click Remote Code execution in Evernote Android\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1679624\"\u003eRemote Command Execution via Github import\u003c/a\u003e |\n| \u003ca href=\"https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/\"\u003eCacti: Unauthenticated Remote Code Execution\u003c/a\u003e |\n| \u003ca href=\"https://blog.sonatype.com/new-0-day-spring-framework-vulnerability-confirmed\"\u003eNew Spring Framework RCE  Vulnerability Confirmed  What to do?\u003c/a\u003e |\n| \u003ca href=\"https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators\"\u003eSpring Actuator Security, Part 1: Stealing Secrets Using Spring Actuators\u003c/a\u003e |\n| \u003ca href=\"https://blog.maass.xyz/spring-actuator-security-part-2-finding-actuators-using-static-code-analysis-with-semgrep\"\u003eSpring Actuator Security, Part 2: Finding Actuators using Static Code Analysis with semgrep\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@vivekkashyap0707/my-first-rce-from-n-a-to-triaged-cve-2021-3064-acdd0541c664\"\u003eMy First RCE from N/A to Triaged (CVE2021–3064)\u003c/a\u003e |\n| \u003ca href=\"https://snyk.io/blog/gitpod-remote-code-execution-vulnerability-websockets/\"\u003eGitpod remote code execution 0day vulnerability via WebSockets\u003c/a\u003e |\n| \u003ca href=\"https://infosecwriteups.com/how-i-abused-the-file-upload-function-to-get-a-high-severity-vulnerability-in-bug-bounty-7cdcf349080b\"\u003eHow I abused the file upload function to get a high severity vulnerability in Bug Bounty\u003c/a\u003e |\n| \u003ca href=\"https://shahjerry33.medium.com/rce-via-webdav-power-of-put-7e1c06c71e60\"\u003eRCE via WebDav  Power Of PUT\u003c/a\u003e |\n| \u003ca href=\"https://bugcrowd.com/disclosures/7b175e9d8ff047e3bd33a8b1e51aa499/http-desync-attack-request-smuggling-mass-session-hijacking\"\u003eHTTP Desync Attack (Request Smuggling)  Mass Session Hijacking\u003c/a\u003e |\n| \u003ca href=\"https://orwaatyat.medium.com/how-i-found-multiple-bugs-on-facebook-in-1-month-and-a-part-for-my-methodology-tools-58a677a9040c\"\u003eHow I Found Multiple Bugs On FaceBook In 1 Month And a Part For My Methodology \u0026 Tools\u003c/a\u003e |\n| \u003ca href=\"https://www.halborn.com/blog/post/halborn-discovers-zero-day-impacting-dogecoin-and-280-networks\"\u003eHalborn Discovers ZeroDay Impacting Dogecoin and 280+ Networks\u003c/a\u003e |\n| \u003ca href=\"https://speakerdeck.com/patrickwardle/youre-muted-rooted\"\u003eLocal privesc vulnerability in Zoom (for macOS)\u003c/a\u003e |\n| \u003ca href=\"https://tantosec.com/blog/cve-2022-41343/\"\u003eCVE202241343  RCE via Phar Deserialisation (Dompdf)\u003c/a\u003e |\n| \u003ca href=\"https://blog.ankursundara.com/cookie-bugs/\"\u003eCookie Bugs  Smuggling \u0026 Injection\u003c/a\u003e |\n| \u003ca href=\"https://github.com/duc-nt/RCE-0-day-for-GhostScript-9.50\"\u003eRCE 0 day for GhostScript9.50\u003c/a\u003e |\n| \u003ca href=\"https://randyarios.medium.com/low-hanging-fruits-on-facebook-group-room-b8d17c7ea886\"\u003eLow hanging fruits on Facebook Group Room\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1077136\"\u003eDenial of Service via Hyperlinks in Posts\u003c/a\u003e |\n| \u003ca href=\"http://security.googleblog.com/2023/05/google-trust-services-acme-api_0503894189.html\"\u003eGoogle Trust Services ACME API available to all users at no cost\u003c/a\u003e |\n| \u003ca href=\"https://www.securesystems.de/blog/a-fresh-look-at-user-enumeration-in-microsoft-teams/\"\u003eA fresh look at user enumeration in Microsoft Teams\u003c/a\u003e |\n| \u003ca href=\"https://supras.io/how-i-got-access-to-many-piis-through-a-source-code-leak/\"\u003eHow I got access to many PIIs through a source code leak\u003c/a\u003e |\n| \u003ca href=\"https://fourcore.io/blogs/f5-big-ip-cve-2022-1388-unauthenticated-rce-exploited-by-attackers\"\u003eF5 BIGIP Critical Vulnerability Exploited By Attackers To Gain Unauthenticated RCE\u003c/\u003e |\n| \u003ca href=\"https://www.flashback.sh/blog/weekend-destroyer-wd-pr4100-rce\"\u003eWEEKEND DESTROYER  RCE in Western Digital PR4100 NAS\u003c/a\u003e |\n| \u003ca href=\"https://jub0bs.com/posts/2021-01-29-great-samesite-confusion/\"\u003eThe great SameSite confusion\u003c/a\u003e |\n| \u003ca href=\"https://www.synacktiv.com/en/publications/persistent-php-payloads-in-pngs-how-to-inject-php-code-in-an-image-and-keep-it-there.html\"\u003ePersistent PHP payloads in PNGs: How to inject PHP code in an image – and keep it there !\u003c/a\u003e |\n| \u003ca href=\"https://thexssrat.medium.com/how-forgot-password-can-cost-you-your-account-2647454258da\"\u003eHow “Forgot Password” can cost you your account\u003c/a\u003e |\n| \u003ca href=\"https://rhynorater.github.io/postMessage-Braindump\"\u003epostMessage Braindump : a brief postMessage testing methodology\u003c/a\u003e |\n| \u003ca href=\"https://sidxparab.gitbook.io/subdomain-enumeration-guide/\"\u003eSubdomain Enumeration Guide 2021 \u003c/a\u003e |\n| \u003ca href=\"https://www.shockwave.cloud/blog/subdomain-takeover-how-a-misconfigured-dns-record-could-lead-to-a-huge-supply-chain-attack\"\u003eSubdomain Takeover: How a Misconfigured DNS Record Could Lead to a Huge Supply Chain Attack\u003c/a\u003e |\n| \u003ca href=\"https://hector0x.medium.com/broken-authentication-through-referral-code-25cd0e8bccc2\"\u003eFull account takeover through referral code\u003c/a\u003e |\n| \u003ca href=\"https://0xjoyghosh.medium.com/information-gathering-scanning-for-sensitive-information-reloaded-6ff3455e0d4e\"\u003eInformation Gathering\u0026scanning for sensitive information\u003c/a\u003e |\n| \u003ca href=\"https://blog.quarkslab.com/attacking-titan-m-with-only-one-byte.html\"\u003eAttacking Pixel's Titan M with Only One Byte (CVE202220233) and getting 75,000 USD bounty\u003c/a\u003e |\n| \u003ca href=\"https://www.synacktiv.com/en/publications/cicd-secrets-extraction-tips-and-tricks.html\"\u003eCI/CD SECRETS EXTRACTION, TIPS AND TRICKS\u003c/a\u003e |\n| \u003ca href=\"https://ssd-disclosure.com/ssd-advisory-kerio-mailbox-takeover/\"\u003eSSD ADVISORY – KERIO MAILBOX TAKEOVER\u003c/a\u003e |\n| \u003ca href=\"https://3bodymo.medium.com/the-easiest-2500-i-got-it-from-bug-bounty-program-8f47ea4aff22\"\u003eThe easiest $2500 I got it from bug bounty program\u003c/a\u003e |\n| \u003ca href=\"https://amineaboud.medium.com/disclose-leads-form-details-of-any-facebook-business-account-or-facebook-page-bugbounty-7ecae6cff312\"\u003eDisclose leads form details of any Facebook Business Account or Facebook Page\u003c/a\u003e |\n| \u003ca href=\"https://www.ghostccamm.com/blog/multi_strapi_vulns/\"\u003eMultiple Critical Vulnerabilities in Strapi Versions \u003c=4.7.1\u003c/a\u003e |\n| \u003ca href=\"https://eslam.io/posts/ejs-server-side-template-injection-rce/\"\u003eEJS, Server side template injection RCE (CVE202229078)  writeup\u003c/a\u003e |\n| \u003ca href=\"https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/\"\u003eRemote code execution in cdnjs of Cloudflare\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1125425\"\u003eRCE via unsafe inline Kramdown options when rendering certain Wiki pages\u003c/a\u003e |\n| \u003ca href=\"https://blog.sonarsource.com/mybb-remote-code-execution-chain\"\u003eMyBB Remote Code Execution Chain\u003c/a\u003e |\n| \u003ca href=\"https://thehackernews.com/2022/05/critical-gems-takeover-bug-reported-in.html\"\u003eCritical Gems Takeover Bug Reported in RubyGems Package Manager\u003c/a\u003e |\n| \u003ca href=\"https://portswigger.net/research/hunting-evasive-vulnerabilities\"\u003eHunting evasive vulnerabilities\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/928255\"\u003eAbility To Delete User(s) Account Without User Interaction\u003c/a\u003e |\n| \u003ca href=\"http://ysamm.com/?p=603\"\u003eURLs in img tag aren’t safely embedded. ($500)\u003c/a\u003e |\n| \u003ca href=\"https://blog.assetnote.io/2021/08/29/exploiting-graphql/\"\u003eExploiting GraphQL\u003c/a\u003e |\n| \u003ca href=\"https://hackerone.com/reports/1091303\"\u003eLow privilege user can read POS PINs via graphql and elevate his privilege\u003c/a\u003e |\n| \u003ca href=\"https://blog.doyensec.com/2021/05/20/graphql-csrf.html\"\u003eThat single GraphQL issue that you keep missing\u003c/a\u003e |\n| \u003ca href=\"https://www.rapid7.com/blog/post/2022/03/03/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed/\"\u003eCVE20214191: GitLab GraphQL API User Enumeration (FIXED)\u003c/a\u003e |\n| \u003ca href=\"https://medium.com/@rashahacks/idor-in-graphql-query-leaking-private-photos-of-a-million-app-2c12c7e9dea7\"\u003eIDOR in GraphQL Query Leaking Private Photos of a Million $ App\u003c/a\u003e |\n\n\n# OWASP Top 10 WebApplication Issues (Updated)\n\n## Broken Access Control\n\n| Category | Writeup |\n|-----------|-----|\n| ATO | \u003ca href=\"https://hx01.me/Abusing_Data_Protection_Laws_For_D0xing_and_Account_Takeovers.pdf\"\u003e Hx01 Abusing Data Protection Laws For D0xing \u0026 Account Takeovers\u003c/a\u003e |\n| IDOR | \u003ca href=\"http://ysamm.com/?p=606\"\u003eAccess employees files in internal CDNs/ Access users modified/deleted content.($12500)\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://vijetareigns.medium.com/forced-browsing-to-access-admin-panel-214a7defa2a5\"\u003eForced Browsing to Access Admin Panel\u003c/a\u003e | \n| IDOR | \u003ca href=\"https://medium.com/@botami143/i-found-idor-vulnerability-at-microsoft-subdomain-b89b8777bf8d\"\u003eI found IDOR Vulnerability at Microsoft Subdomain\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://medium.com/@tusharsaini484/how-i-found-an-idor-that-led-to-sensitive-information-leak-6055bb121f8\"\u003eHow I found an IDOR that led to sensitive information leak?\u003c/a\u003e |\n| Chained | \u003ca href=\"https://medium.com/@gonzalocarrascosec/fuzzing-idor-admin-takeover-5343bb8f436e\"\u003eFuzzing + IDOR = Admin TakeOver\u003c/a\u003e |\n| ATO | \u003ca href=\"https://medium.com/@evan.connelly/post-account-takeover-account-takeover-of-internal-tesla-accounts-bc720603e67d\"\u003ePost Account Takeover? Account Takeover of Internal Tesla Accounts\u003c/a\u003e |\n| ATO | \u003ca href=\"https://shahjerry33.medium.com/account-takeover-inside-the-tenant-6101a3cafbee\"\u003eAccount Takeover  Inside The Tenanth\u003c/a\u003e |\n| RDP | \u003ca href=\"https://blog.intigriti.com/2023/02/13/file-attachments-size-does-matter/\"\u003eHelping secure BNB Chain through responsible disclosure\u003c/a\u003e |\n| Account Takeover | \u003ca href=\"https://infosecwriteups.com/how-i-was-able-to-takeover-accounts-in-websites-deal-with-github-as-a-sso-provider-294290358e0c\"\u003eHow I was able to take over accounts in websites deal with Github as an SSO provider\u003c/a\u003e |\n| ATO | \u003ca href=\"https://medium.com/@gonzxph/account-takeover-worth-of-2500-e643661f94e9\"\u003eAccount Takeover Worth of $2500\u003c/a\u003e |\n| ATO | \u003ca href=\"https://0xmaruf.medium.com/firing-8-account-takeover-methods-77e892099050\"\u003eFiring 8 Account Takeover Methods\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://r0ckinxj3.wordpress.com/2021/10/24/a-7500-google-sites-idor/\"\u003eA 7500$ Google sites IDOR\u003c/a\u003e |\n| ATO | \u003ca href=\"https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com\"\u003eTraveling with OAuth  Account Takeover on Booking.com\u003c/a\u003e |\n| OAUTH | \u003ca href=\"https://agnihackers.medium.com/otp-bypass-through-response-manipulation-beeb467359d8\"\u003eOTP Bypass Through Response Manipulation\u003c/a\u003e |\n| ATO | \u003ca href=\"https://ysamm.com/?p=783\"\u003eAccount Takeover in Canvas Apps served in Comet due to failure in CrossWindowMessage Origin validation\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://sagarsajeev.medium.com/unsubscribe-any-users-email-notifications-via-idor-2c2e05b79dac\"\u003eUnsubscribe any user’s email notifications via IDOR\u003c/a\u003e |\n| Chained | \u003ca href=\"https://infosecwriteups.com/idor-leads-to-leak-private-details-866563365490\"\u003eIDOR leads to leak Private Details\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://bhansalipratish.medium.com/how-i-found-my-first-bug-idor-9c4e52584454\"\u003eHow I found my first bug (IDOR)\u003c/a\u003e |\n| Auth Bypass | \u003ca href=\"https://medium.com/@h4x0r_dz/23000-for-authentication-bypass-file-upload-arbitrary-file-overwrite-2578b730a5f8\"\u003e23000$ for Authentication Bypass \u0026 File Upload \u0026 Arbitrary File Overwrite\u003c/a\u003e | \n| AI | \u003ca href=\"https://protectai.com/blog/hacking-ai-system-takeover-exploit-in-mlflow\"\u003eHacking AI: System and Cloud Takeover via MLflow Exploit\u003c/a\u003e | \n| API | \u003ca href=\"https://security.googleblog.com/2023/04/announcing-depsdev-api-critical.html\"\u003eAnnouncing the deps.dev API: critical dependency data for secure supply chains\u003c/a\u003e |\n| Chained | \u003ca href=\"https://adityashende17.medium.com/idor-to-information-disclosure-admin-account-takeover-6aa96798c70b\"\u003eIDOR to information disclosure + Admin Account Takeover\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://junoonbro.medium.com/idors-how-to-find-idors-in-ecommerce-sites-d112bd946fcf\"\u003e$$$$ IDOR’s — How to find IDORs in Ecommerce sites?\u003c/a\u003e |\n| ATO | \u003ca href=\"http://ysamm.com/?p=783\"\u003eATO in Canvas Games due to weak cross window message Origin validations ($62,500)\u003c/a\u003e |\n| Chained | \u003ca href=\"https://akashvenky091.medium.com/otp-bypassing-and-vulnerabilities-from-email-fields-a5c326efa605\"\u003eOTP Bypassing and Vulnerabilities from EMail fields.\u003c/a\u003e |\n| Path Traversal | \u003ca href=\"https://kuldeep.io/posts/path-traversal-paradise/\"\u003ePath Traversal Paradise\u003c/a\u003e | \n| RCE | \u003ca href=\"https://sysdig.com/blog/cve-2022-42889-text4shell/\"\u003eDetecting and mitigating CVE202242889 a.k.a. Text4shell\u003c/a\u003e |\n| WAF | \u003ca href=\"https://medium.com/@divyanshsharma2401/bypassing-waf-for-2222-f99b80cfdb9b\"\u003eBypassing WAF for $2222\u003c/a\u003e |\n| Path Traversal | \u003ca href=\"https://yilmazcanyigit.medium.com/cve-2019-6238-apple-xar-directory-traversal-vulnerability-9a32ba8b3b7d\"\u003eCVE2019–6238: Apple XAR directory traversal vulnerability\u003c/a\u003e |\n| Rate Limit | \u003ca href=\"https://medium.com/@manavbankatwala29/unique-rate-limit-bypass-worth-1800-6e2947c7d972\"\u003eUnique Rate limit bypass worth 1800$\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://encodedguy.medium.com/600-for-idor-file-or-folder-download-243166452dad\"\u003e$600 for IDOR (File or Folder Download)\u003c/a\u003e |\n| Podcast | \u003ca href=\"https://dayzerosec.com/podcast/202.html\"\u003e202  A SNIProxy Bug and a Samsung NPU Double Free\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://amitlt.medium.com/a-story-of-idor-which-leads-to-privacy-violation-78c1b4c710fb\"\u003eA Story of IDOR which leads to privacy violation…$$$\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://n1ghtmar3.medium.com/how-i-found-my-first-idor-in-hackerone-5d5f17bb431\"\u003eHow I found my first IDOR in HackerOne\u003c/a\u003e |\n| Access Control | \u003ca href=\"https://medium.com/@mehedishakeel/improper-access-control-my-third-finding-on-hackerone-1455e95b6c8c\"\u003eImproper Access Control — My Third Finding on Hackerone!\u003c/a\u003e |\n| CSRF | \u003ca href=\"https://medium.com/@rajeevranjancom/cross-site-request-forgery-csrf-attack-6949edb9e405\"\u003eCross site request forgery (CSRF) attack\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://psfauzi.medium.com/how-i-get-1350-from-idor-just-less-1-hours-7496bab1a914\"\u003eHow I Get $1350 From IDOR Just Less 1 hours\u003c/a\u003e |\n| Priv Esc | \u003ca href=\"https://junoonbro.medium.com/how-i-earned-9000-with-privilege-escalations-b187d1f8f4fe\"\u003eHow I earned $9000 with Privilege escalations\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://hackerone.com/reports/1372216\"\u003eIDOR in \"external status check\" API leaks data about any status check on the instance\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://medium.com/@nvmeeet/4300-instagram-idor-bug-2022-5386cf492cad\"\u003e4300$ Instagram IDOR Bug (2022)\u003c/a\u003e |\n| Chained | \u003ca href=\"https://medium.com/@webresearcher007/how-i-was-able-to-delete-any-users-oauth-connections-via-idor-bf3a8e8e2269\"\u003eHow I was able to delete any users’ OAUTH connections via IDOR\u003c/a\u003e |\n| Chained | \u003ca href=\"https://www.cobalt.io/blog/cobalt-pentest-case-study-oauth-redirect-to-account-takeover\"\u003eCobalt Pentest Case Study: OAuth Redirect to Account Takeover\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://aidilarf.medium.com/idor-via-get-request-which-can-sold-all-user-products-2f5bc3ea1650\"\u003eIDOR via GET Request which can SOLD all User Products\u003c/a\u003e |\n| CORS | \u003ca href=\"https://blog.snapsec.co/attacking-cors/\"\u003eAttacking CORS Misconfigurations in Modern Web Apps\u003c/a\u003e |\n| ATO | \u003ca href=\"https://youtu.be/5guMYiQrnUo\"\u003eShopify Account Takeover $22,500 Bug Bounty\u003c/a\u003e |\n| Path Traversal | \u003ca href=\"https://blog.intigriti.com/2021/10/13/bug-bytes-142-weird-google-bugs-saml-padding-oracle-apache-path-traversal-continued/\"\u003eWeird Google bugs, SAML padding Oracle \u0026 Apache path traversal continued\u003c/a\u003e |\n| HTTP Smuggle | \u003ca href=\"https://www.intruder.io/research/practical-http-header-smuggling\"\u003ePractical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond\u003c/a\u003e |\n| IDOR | \u003ca href=\"https://www.youtube.com/watch?v=FzT3Z7tgDSQ\"\u003e$5,000 YouTube IDOR  Bug Bounty Reports Explained \u003c/a\u003e |\n\n\n\n## Cryptographic Issues / Bugs\n\n| Category | Writeup |\n|-----------|-----|\n| Chained | \u003ca href=\"https://portswigger.net/research/making-http-header-injection-critical-via-response-queue-poisoning\"\u003eMaking HTTP header injection critical via response queue poisoning\u003c/a\u003e |\n| Cryptographic Failure | \u003ca href=\"https://mouha.be/sha-3-buffer-overflow/\"\u003eSHA3 Buffer Overflow\u003c/a\u003e | \n| Crptographic Failure | \u003ca href=\"https://medium.com/numen-cyber-labs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf\"\u003eTCP/IP Vulnerability CVE2022–34718 PoC Restoration and Analysis\u003c/a\u003e |\n| Cryptographic Failure | \u003ca href=\"https://securitylabs.datadoghq.com/articles/openssl-november-1-vulnerabilities/\"\u003eThe OpenSSL punycode vulnerability (CVE20223602): Overview, detection, exploitation, and remediation\u003c/a\u003e |\n\n\n\n## Injection Issues / Bugs\n\n| Category | Writeup |\n|-----------|-----|\n| HHI | \u003ca href=\"https://m7arman.medium.com/host-header-injection-lead-to-account-takeover-2f025a645d13\"\u003eHost Header Injection Lead To Account Takeover\u003c/a\u003e |\n| Regex-I | \u003ca href=\"https://hackerone.com/reports/1196124\"\u003eRegular Expression Injection\u003c/a\u003e |\n| ESI-I | \u003ca href=\"https://sudhanshur705.medium.com/exploringtheworldofesiinjectionb86234e66f91\"\u003eExploring the World of ESI Injection\u003c/a\u003e |\n| R-XSS | \u003ca href=\"https://medium.com/@sicks3c/taleofxssinangularc5c057a56156\"\u003eTale of XSS in Angular\u003c/a\u003e |\n| Stored-XSS | \u003ca href=\"https://labs.guard.io/xss-vulnerability-found-in-connect-wise-remote-access-platform-with-great-potential-form-is-use-by-scammers-a0773da2aacf\"\u003eXSS Vulnerability Found in ConnectWise Remote Access Platform With Great Potential For Misuse by Scammers\u003c/a\u003e\n| R-XSS |\u003ca href=\"https://medium.com/@sid0krypt/vue-js-reflected-xss-fae04c9872d2\"\u003eVue JS Reflected XSS\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://securitylab.github.com/advisories/GHSL-2022-059_GHSL-2022-060_Owncloud_Android_app/\"\u003eSQL injection vulnerabilities in Owncloud Android app  CVE202324804, CVE202323948\u003c/a\u003e\n| PHP-I |\u003ca href=\"https://karmainsecurity.com/exploiting-an-nday-vbulletin-php-object-injection\"\u003eExploiting an Nday vBulletin PHP Object Injection Vulnerability\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://portswigger.net/research/finding-dom-polyglot-xss-in-paypal-the-easy-way\"\u003eFinding DOM Polyglot XSS in PayPal the Easy Way \u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://lethanhphuc-pk.medium.com/bugbounty-xss-with-markdown-exploit-fix-on-opensource-1baecebe9645\"\u003eXSS with Markdown — Exploit \u0026 Fix on OpenSource\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://bugcrowd.com/disclosures/aac249ea-fe92-4b43-98e9-dda021c0ff4d/postmessage-xss-in-tesla-payment-page\"\u003epostMessage XSS in Tesla Payment page \u003c/a\u003e\n| DOM XSS |\u003ca href=\"https://portswigger.net/daily-swig/html-parser-bug-triggers-chromium-xss-security-flaw\"\u003eHTML parser bug triggers Chromium XSS security flaw\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://medium.com/@haroonhameed_76621/a-775-worth-of-cookies-reflected-dom-based-xss-bug-bounty-poc-3e7720c78fbe\"\u003eA $$$ worth of cookies! | Reflected DOMBased XSS | Bug Bounty POC\u003c/a\u003e\n| Simple XSS |\u003ca href=\"https://portswigger.net/daily-swig/email-platform-zimbra-issues-hotfix-for-xss-vulnerability-under-active-exploitation\"\u003eEmail platform Zimbra issues hotfix for XSS vulnerability under active exploitation\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://omar0x01.medium.com/cve-2022-38627-a-journey-through-sqlite-injection-to-compromise-the-whole-enterprise-building-15cebd072ed6\"\u003eCVE202238627: A journey through SQLite Injection to compromise the whole enterprise building\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://hackerone.com/reports/1196958\"\u003eClipboard DOMbased XSS\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://medium.com/@armaanpathan/exploiting-dom-based-xss-via-misconfigured-postmessage-function-bfc794969a0a\"\u003eExploiting DOM Based XSS via Misconfigured postMessage() Function\u003c/a\u003e\n| R-XSS |\u003ca href=\"https://sl4x0.medium.com/how-i-found-xss-on-admin-page-without-login-fe165a5f89c2\"\u003eHow I found XSS on Admin Page without login!\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://c0nqr0r.medium.com/error-based-sql-injection-with-waf-bypass-manual-exploit-100-bab36b769005\"\u003eError based SQL Injection with WAF bypass manual Exploit 100%\u003c/a\u003e\n| XSS |\u003ca href=\"https://medium.com/@abhijeetbiswas_/xss-cross-site-scripting-via-x-forwarded-host-header-20be114d4254\"\u003eXSS via X-Forwarded-Host header\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://thevillagehacker.medium.com/time-based-sql-injection-to-dumping-the-database-da0e5bcaa9df\"\u003eTimeBased SQL Injection to Dumping the Database\u003c/a\u003e\n| Security Misconfiguration |\u003ca href=\"https://medium.com/@siratsami71/1500-worth-slack-vulnerability-bypass-invite-accept-process-8204e5431d52\"\u003e[1500$ Worth — Slack] vulnerability, bypass invite accept process\u003c/a\u003e\n| C-I |\u003ca href=\"https://medium.com/@omidxrz/command-injection-by-changing-the-logo-2d730887ab6c\"\u003eThe Tale of a Command Injection by Changing the Logo\u003c/a\u003e\n| R-XSS |\u003ca href=\"https://hackerone.com/reports/1367642\"\u003eReflected Cross Site Scripting (XSS) on one.newrelic.com\u003c/a\u003e\n| XSS |\u003ca href=\"https://portswigger.net/research/new-xss-vectors\"\u003eNew XSS vectors\u003c/a\u003e\n| Cypher-I |\u003ca href=\"https://medium.com/@marvelmaniac/the-most-underrated-injection-of-all-time-cypher-injection-fa2018ba0de8\"\u003eThe most underrated injection of all time — CYPHER INJECTION. How I found and exploited it \u0026\u0026 2000$ bounty !\u003c/a\u003e\n| Blind-XSS |\u003ca href=\"https://hackerone.com/reports/1558010\"\u003eBlind XSS in app.pullrequest.com/████████ via /reviews/ratings/{uuid}\u003c/a\u003e\n| Chained |\u003ca href=\"https://blog.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/\"\u003eHacking SwaggerUI  from XSS to account takeovers\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://medium.com/@M0X0101/how-i-was-able-to-steal-users-credentials-via-swagger-ui-dom-xss-e84255eb8c96\"\u003eHow I was able to steal users credentials via Swagger UI DOMXSS\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://spaceraccoon.dev/analyzing-clipboardevent-listeners-stored-xss/\"\u003eI Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://hackerone.com/reports/1212067\"\u003eStored XSS in markdown via the DesignReferenceFilter\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://hackerone.com/reports/977697\"\u003eStoredXSS in merge requests\u003c/a\u003e\n| Rare Case |\u003ca href=\"https://apth3hack3r.medium.com/xss-through-base64-encoded-json-4b0d96e5ccd4\"\u003eXSS through base64 encoded JSON \u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://medium.com/bored-engineer/xss-on-account-leagueoflegends-com-via-easyxdm-2016-75bcf9d582b5\"\u003eXSS on account[dot]leagueoflegends[dot]com via easyXDM [2016]\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://svennergr.github.io/writeups/google/ads_dom_xss/\"\u003eStumbling across a DOM XSS on google.com\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://threatpost.com/xss-bug-seopress-wordpress-plugin/168702/\"\u003eXSS Bug in SEOPress WordPress Plugin Allows Site Takeover\u003c/a\u003e\n| Chained |\u003ca href=\"https://medium.com/tenable-techblog/stored-xss-to-rce-chain-as-system-in-manageengine-servicedesk-plus-493c10f3e444\"\u003eStored XSS to RCE Chain as SYSTEM in ManageEngine ServiceDesk Plus\u003c/a\u003e\n| C-I |\u003ca href=\"https://blog.nietaanraken.nl/posts/github-pages-command-injection/\"\u003eCommand Injection in the GitHub Pages Build Pipeline\u003c/a\u003e\n| Chained |\u003ca href=\"https://hackerone.com/reports/1504410\"\u003eXSS via Mod Log Removed Post\u003c/a\u003e\n| R-XSS |\u003ca href=\"https://infosecwriteups.com/reflected-xss-leads-to-3-000-bug-bounty-rewards-from-microsoft-forms-efe34fc6b261\"\u003eReflected XSS Leads to 3,000$ Bug Bounty Rewards from Microsoft Forms\u003c/a\u003e\n| Chained |\u003ca href=\"https://palant.info/2022/08/24/attack-surface-of-extension-pages/\"\u003eAttack surface of extension pages\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://hackerone.com/reports/1481207\"\u003eStored XSS in Notes (with CSP bypass for gitlab.com)\u003c/a\u003e\n| XSS |\u003ca href=\"https://medium.com/@fpatrik/how-i-found-an-xss-vulnerability-via-using-emojis-7ad72de49209\"\u003eHow I found an XSS vulnerability via using emojis\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://jasminderpalsingh.info/stored-xss-in-google-doubleclick-studio-google-research-grant/\"\u003eStored XSS in Google Doubleclick Studio\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://0xkasper.com/articles/moodle-sql-injection-broken-access-control\"\u003eMoodle: Blind SQL Injection (CVE202136393) and Broken Access Control (CVE202136397)\u003c/a\u003e\n| RCE |\u003ca href=\"https://infosecwriteups.com/orange-arbitrary-command-execution-75ba7f283d53\"\u003eOrange Arbitrary Command Execution\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://infosecwriteups.com/how-i-found-multiple-sql-injections-in-5-minutes-in-bug-bounty-40155964c498\"\u003eHow I Found Multiple SQL Injections in 5 Minutes in Bug Bounty\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://flattsecurity.medium.com/finding-an-unseen-sql-injection-by-bypassing-escape-functions-in-mysqljs-mysql-90b27f6542b4\"\u003eFinding an unseen SQL Injection by bypassing escape functions in mysqljs/mysql\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://www.sonarsource.com/blog/wordpress-stored-xss-vulnerability/\"\u003eWordPress 5.8.2 Stored XSS Vulnerability\u003c/a\u003e\n| Chained |\u003ca href=\"https://octagon.net/blog/2022/03/02/apache-jspwiki-preauth-xss-to-ato/\"\u003eCVE202224948: Apache JSPWiki preauth Stored XSS to ATO\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://sapt.medium.com/stored-xss-non-privileged-user-to-anyone-using-qr-code-dfeb0bd98a5\"\u003eStored XSS: NonPrivileged User to Anyone Using QR Code\u003c/a\u003e\n| Chained |\u003ca href=\"https://jlajara.gitlab.io/Javascript_Hoisting_in_XSS_Scenarios\"\u003eJavascript Hoisting in XSS Scenarios\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://mtechghost.medium.com/stored-xss-vulnerability-in-microsoft-booking-e593de3344e0\"\u003eStored XSS vulnerability in Microsoft booking\u003c/a\u003e\n| XSS |\u003ca href=\"https://palisade.consulting/blog/rarible-vulnerability\"\u003ePalisade identifies Wormable CrossSite Scripting Vulnerability affecting Rarible’s NFT Marketplace\u003c/a\u003e\n| R-XSS |\u003ca href=\"https://gosecure.ai/blog/2022/07/13/tableau-server-leaks-sensitive-information-from-reflected-xss/\"\u003eTableau Server Leaks Sensitive Information From Reflected XSS\u003c/a\u003e\n| CSS-I |\u003ca href=\"https://sanderwind.medium.com/unleashing-the-power-of-css-injection-the-access-key-to-an-internal-api-789b166d0527\"\u003eUnleashing the power of CSS injection: The access key to an internal API\u003c/a\u003e\n| OGNL-I |\u003ca href=\"https://github.com/lleavesl/CVE-2021-26084\"\u003eCVE202126084，Atlassian Confluence OGNL\u003c/a\u003e\n| Redash |\u003ca href=\"https://ian.sh/redash\"\u003eExploiting Redash instances with CVE-2021-41192\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://hamzadzworm.medium.com/5000-for-apple-stored-xss-and-another-blind-xss-still-under-review-e9f6f5a76eb1\"\u003e5000$ for Apple Stored Xss And Another Blind Xss Still under review\u003c/a\u003e\n| Chained |\u003ca href=\"https://hackerone.com/reports/1424094\"\u003eWeb Cache Poisoning leads to Stored XSS\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://hackerone.com/reports/1322104\"\u003eXSS on tiktok.com\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://ysamm.com/?p=779\"\u003eDOM-XSS in Instant Games due to improper verifications ($62,500?)\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://hackerone.com/reports/1087061\"\u003eStored-XSS on wiki pages\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://hackerone.com/reports/1280002\"\u003eStored XSS via Mermaid Prototype Pollution vulnerability\u003c/a\u003e\n| U-XSS |\u003cA href=\"https://fluidattacks.com/blog/uxss-to-account-takeover-rushbet/\"\u003eUXSS to Account Takeover in Rushbet\u003c/a\u003e\n| Stored-XSS |\u003ca href=\"https://maordayanofficial.medium.com/stored-xss-at-trello-com-ef2e3d1ed24b\"\u003eStored XSS at Trello\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://medium.com/@mohameddhanish98/a-story-of-dom-xss-852b6ed3bb5f\"\u003eA Story of DOM XSS\u003c/a\u003e\n| XSS |\u003ca href=\"https://infosecwriteups.com/got-another-xss-using-double-encoding-e6493a9f7368\"\u003eGot Another XSS using Double Encoding\u003c/a\u003e\n| Stored-XSs |\u003ca href=\"https://prashantbhatkal2000.medium.com/svg-based-stored-xss-ee6e9b240dee\"\u003eSVG based Stored XSS\u003c/a\u003e\n| XSS |\u003ca href=\"https://portswigger.net/daily-swig/google-roulette-developer-console-trick-can-trigger-xss-in-chromium-browsers\"\u003eGoogle Roulette: Developer console trick can trigger XSS in Chromium browsers\u003c/a\u003e\n| Creative XSS |\u003ca href=\"https://medium.com/@youghourtaghannei/postmessage-xss-vulnerability-on-private-program-18e773e1a1ba\"\u003ePostMessage Xss vulnerability on private program\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://infosecwriteups.com/how-i-found-dom-based-xss-on-microsoft-msrc-and-how-they-fixed-it-8b71a6020c82\"\u003eHow I found DOMBased XSS on Microsoft MSRC and How they fixed it\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://ysamm.com/?p=779\"\u003eDOMXSS in Instant Games due to improper verification of supplied URLs\u003c/a\u003e\n| DOM-XSS |\u003ca href=\"https://medium.com/@haroonhameed_76621/winning-qr-with-dom-based-xss-bug-bounty-poc-4b4048cf285d\"\u003eWinning QR with DOMBased XSS | Bug Bounty POC\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://hector0x.medium.com/easy-sqli-in-amazon-subsidiary-using-sqlmap-ff469013671b\"\u003eEasy SQLi in Amazon subsidiary using Sqlmap\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://infosecwriteups.com/fun-sql-injection-mod-security-bypass-644b54b0c445\"\u003eFun sql injection — mod_security bypass/a\u003e\n| SQL-I |\u003ca href=\"https://www.techncyber.com/2022/07/sql-injection-at-authorization-token.html\"\u003eExploiting SQL Injection at Authorization token\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/\"\u003eStranger Strings: An exploitable flaw in SQLite\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://medium.com/@touseefgul/a-500-sql-injection-in-ikea-es-my-first-finding-on-hackerone-cf15c4ecd5a6\"\u003eA 500$ SQL Injection Bug in .IKEA.es — My First Finding on Hackerone!\u003c/a\u003e\n| SQL-I |\u003ca href=\"https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws\"\u003eVaronis Threat Labs Discovers SQLi and Access Flaws in Zendesk\u003c/a\u003e\n| Prompt-I |\u003ca href=\"https://www.nccgroup.com/us/research-blog/exploring-prompt-injection-attacks/\"\u003eExploring Prompt Injection Attacks\u003c/a\u003e\n| C-I |\u003ca href=\"https://www.nccgroup.com/us/research-blog/puckungfu-a-netgear-wan-command-injection/\"\u003ePuckungfu: A NETGEAR WAN Command Injection\u003c/a\u003e\n  \n\n\n## Insecure Design \n\n| Category | Writeup |\n|-----------|-----|\n| Chained |\u003ca href=\"https://ahmed8magdy.medium.com/file-upload-to-rce-538bb4128062\"\u003eFile Upload to RCE\u003c/a\u003e\n| Chained |\u003ca href=\"https://sm4rty.medium.com/hunting-for-bugs-in-file-upload-feature-c3b364fb01ba\"\u003eHunting for Bugs in File Upload Feature\u003c/a\u003e\n| Param Tampering |\u003ca href=\"https://portswigger.net/daily-swig/http-request-smuggling-bug-patched-in-mitmproxy\"\u003eHTTP request smuggling bug patched in mitmproxy\u003c/a\u003e\n| Shift-Left Abuse |\u003ca href=\"https://hackerone.com/reports/1372667\"\u003eAble to steal bearer token from deep link\u003c/a\u003e\n| Shell |\u003ca href=\"https://text.tchncs.de/ioi/backdooring-electron-applications\"\u003eBackdooring Electron Applications\u003c/a\u003e\n| Shift-Left Abuse |\u003ca href=\"https://shabarkin.medium.com/unsafe-content-loading-electron-js-76296b6ac028\"\u003eUnsafe content loading [Electron JS]\u003c/a\u003e\n| ATO |\u003ca href=\"https://fluidattacks.com/blog/account-takeover-kayak/\"\u003eAccount Takeover in KAYAK\u003c/a\u003e\n| Chained |\u003ca href=\"https://www.synacktiv.com/en/publications/php-filter-chains-file-read-from-error-based-oracle.html\"\u003ePHP FILTER CHAINS: FILE READ FROM ERRORBASED ORACLE\u003c/a\u003e\n| Shift-Left Abuse |\u003ca href=\"https://joonas.fi/2021/08/saml-is-insecure-by-design/\"\u003eSAML is insecure by design\u003c/a\u003e\n| Shift-Left Abuse |\u003ca href=\"https://blog.trailofbits.com/2023/02/21/vscode-extension-escape-vulnerability/\"\u003eEscaping misconfigured VSCode extensions\u003c/a\u003e\n| Shift-Left Abuse |\u003ca href=\"https://infosecwriteups.com/exploiting-activity-in-medium-android-app-e2e6f3553eef\"\u003eTrigger custom URL in Medium Android app\u003c/a\u003e\n| Chained |\u003ca href=\"https://hackerone.com/reports/1167753\"\u003eAdd new managed stores without permission\u003c/a\u003e\n| Microservices |\u003ca href=\"https://infosecwriteups.com/hacking-microservices-for-fun-and-bounty-5cc302769e94\"\u003eHacking Microservices For Fun and Bounty\u003c/a\u003e\n| LFI |\u003ca href=\"https://blog.snapsec.co/attacking-file-uploads-in-modern-web-applications/\"\u003eAttacking File Uploads in Modern Web Applications\u003c/a\u003e\n| ATO |\u003ca href=\"https://medium.com/@kshunya/full-account-takeover-via-open-redirection-41c167db46\"\u003eFull Account Takeover via Open Redirection \u003c/a\u003e\n| FI Bypass |\u003ca href=\"https://systemweakness.com/bypassing-file-upload-restriction-using-magic-bytes-eb13e801f264\"\u003eBypassing File Upload Restriction using Magic Bytes\u003c/a\u003e\n| Shift-Left failure |\u003ca href=\"https://akashhamal0x01.medium.com/design-flaw-a-tale-of-permanent-dos-a9ef05181083\"\u003eDesign Flaw : A Tale of Permanent DOS (Informative \u003e Triaged)\u003c/a\u003e\n| RCE |\u003ca href=\"https://www.assetnote.io/resources/research/bypass-iis-authorisation-with-this-one-weird-trick-three-rces-and-two-auth-bypasses-in-sitecore-9-3\"\u003eBypass IIS Authorisation with this One Weird Trick  Three RCEs and Two Auth Bypasses in Sitecore 9.3\u003c/a\u003e\n| Chained |\u003ca href=\"https://infosecwriteups.com/oauth-misconfiguration-leads-to-full-account-takeover-22b032cb6732\"\u003eOAUTH Misconfiguration leads to Full Account Takeover\u003c/a\u003e\n| Repo Jacking |\u003ca href=\"https://blog.nietaanraken.nl/posts/gitub-popular-repository-namespace-retirement-bypass/\"\u003eHijacking GitHub Repositories by Deleting and Restoring Them\u003c/a\u003e\n| Stack Attack |\u003ca href=\"https://googleprojectzero.blogspot.com/2022/12/exploiting-CVE-2022-42703-bringing-back-the-stack-attack.html\"\u003eExploiting CVE-2022-42703  Bringing back the stack attack\u003c/a\u003e\n| MFA Bypass |\u003ca href=\"https://medium.com/pentesternepal/two-factor-authentication-bypass-on-facebook-3f4ac3ea139c\"\u003eTwo Factor Authentication Bypass On Facebook\u003c/a\u003e\n| File Corruption |\u003ca href=\"https://nmochea.medium.com/arbitrary-file-corruption-end-to-end-encrypted-messaging-application-674963dceef8\"\u003eArbitrary File Corruption: End  to  End Encrypted Messaging Application\u003c/a\u003e\n| Chained |\u003ca href=\"https://www.exploitsecurity.io/post/cve-2023-33383-authentication-bypass-via-an-out-of-bounds-read-vulnerability\"\u003eCVE-2023-33383 : Authentication Bypass via an outofbounds read vulnerability\u003c/a\u003e\n| Zero-Day |\u003ca href=\"https://www.assetnote.io/resources/research/hacking-a-bank-by-finding-a-0day-in-dotcms\"\u003eHacking a Bank by Finding a 0day in DotCMS\u003c/a\u003e\n| Server-Side |\u003ca href=\"https://blog.orange.tw/posts/2022-08-lets-dance-in-the-cache-destabilizing-hash-table-on-microsoft-iis/\"\u003eLet's Dance in the Cache Destabilizing Hash Table on Microsoft IIS!\u003c/a\u003e\n| Poisoning |\u003ca href=\"https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust\"\u003eNovel Pipeline Vulnerability Discovered; Rust Found Vulnerable\u003c/a\u003e\n| Path Manipulation |\u003ca href=\"https://www.erasec.be/blog/client-side-path-manipulation/\"\u003ePractical Example Of Client Side Path Manipulation\u003c/a\u003e\n| Log4J |\u003ca href=\"https://portswigger.net/daily-swig/finding-nbsp-the-next-log4j-nbsp-openssfs-brian-behlendorf-on-pivoting-to-a-risk-centred-view-of-open-source-development\"\u003eFinding the next Log4j – OpenSSF’s Brian Behlendorf on pivoting to a ‘riskcentred view’ of open source development\u003c/a\u003e\n| ATO |\u003ca href=\"https://ysamm.com/?p=777\"\u003eAccount takeover of Facebook/Oculus accounts due to FirstParty access_token stealing\u003c/a\u003e\n| Shift-Left failure |\u003ca href=\"https://infosecwriteups.com/laravel-8-x-image-upload-bypass-zero-day-852bd806019b\"\u003eLaravel 8.x image upload bypass\u003c/a\u003e\n| Shift-Left failure |\u003ca href=\"https://infosecwriteups.com/how-i-made-15-000-by-hacking-caching-servers-part-1-5541712a61c3\"\u003eHow I Made $16,500 Hacking CDN Caching Servers — Part 1\u003c/a\u003e\n| Shift-Left failure |\u003ca href=\"https://infosecwriteups.com/how-i-made-16-500-hacking-cdn-caching-servers-part-2-4995ece4c6e6\"\u003eHow I Made $16,500 Hacking CDN Caching Servers — Part 2\u003c/a\u003e\n| Shift-Left failure |\u003ca href=\"https://infosecwriteups.com/how-i-made-16-500-hacking-cdn-caching-servers-part-3-91f9d836e046\"\u003eHow I Made $16,500 Hacking CDN Caching Servers — Part 3\u003c/a\u003e\n| Shift-Left failure |\u003ca href=\"https://medium.com/@Kntjrld/bypassing-default-visibility-for-newly-added-email-in-facebook-part-i-submitting-i-d-da78142f032d\"\u003eBypassing default visibility for newlyadded email in Facebook(Part I  Submitting I.D)\u003c/a\u003e\n| Shift-Left failure |\u003ca href=\"https://medium.com/@Kntjrld/bypassing-default-visibility-for-newly-added-email-in-facebook-part-ii-trusted-contacts-36176eeb103\"\u003eBypassing default visibility for newly-added email in Facebook(Part II - Trusted Contacts)\u003c/a\u003e\n| Chained |\u003ca href=\"https://portswigger.net/daily-swig/deserialized-web-security-roundup-twitter-2fa-backlash-godaddy-suffers-years-long-attack-campaign-and-xss-hunter-adds-e2e-encryption\"\u003eDeserialized web security roundup: Twitter 2FA backlash, GoDaddy suffers yearslong attack campaign, and XSS Hunter adds e2e encryption\u003c/a\u003e\n| Shift-Left Abuse |\u003ca href=\"https://hackerone.com/reports/170552\"\u003eSlack integration setup lacks CSRF protection\u003c/a\u003e\n| RCE |\u003ca href=\"https://hackerone.com/reports/1065500\"\u003eMultiple bugs leads to RCE on TikTok for Android\u003c/a\u003e\n| SID |\u003ca href=\"http://ysamm.com/?p=627\"\u003eLeaking Facebook user information to external websites ($2000)\u003c/a\u003e\n\n\n## Security Misconfiguration\n\n| Category | Writeup |\n|-----------|-----|\n| Password | \u003ca href=\"https://infosecwriteups.com/all-about-password-reset-vulnerabilities-3bba86ffedc7\"\u003eAll about Password Reset vulnerabilities\u003c/a\u003e\n| Chained | \u003ca href=\"https://security.humanativaspa.it/nothing-new-under-the-sun/\"\u003eNothing new under the Sun – Discovering and exploiting a CDE bug chain\u003c/a\u003e\n| Subdomain Takeover | \u003ca href=\"https://medium.com/@moSec/how-i-hacked-thousand-of-subdomains-6aa43b92282c\"\u003eHow I hacked thousand of subdomains\u003c/a\u003e\n| S3 Recon |\u003ca href=\"https://github.com/WeAreCloudar/s3-account-search\"\u003eS3 Account Search\u003c/a\u003e\n| RCE |\u003ca href=\"https://medium.com/@nanwinata/old-rce-worth-3362-1af0cd70c459\"\u003eOld RCE worth $3362\u003c/a\u003e\n| Web-Cache |\u003ca href=\"https://yaseenzubair.medium.com/web-cache-poisoning-worth-it-e7c6d88797b1\"\u003eWebCache Poisoning $$$? Worth it?\u003c/a\u003e\n| Misconfiguration |\u003ca href=\"https://infosecwriteups.com/how-i-scored-1k-bounty-using-waybackurls-717d9673ca52\"\u003eHow I Scored 1K Bounty Using Waybackurls\u003c/a\u003e\n| CSRF |\u003ca href=\"https://xcheater.medium.com/all-about-csrf-flaw-7d525be39587\"\u003eAll About CSRF Flaw\u003c/a\u003e\n| Recon + Exploitation |\u003ca href=\"https://samcurry.net/points-com\"\u003eLeaked Secrets and Unlimited Miles: Hacking the Largest Airline and Hotel Rewards Platform\u003c/a\u003e\n| Misconfiguration |\u003ca href=\"https://www.alevsk.com/2022/11/system-misconfiguration-is-the-number-one-vulnerability-at-least-for-mastodon/\"\u003eSystem misconfiguration is the number one vulnerability, at least for Mastodon\u003c/a\u003e\n| Chained |\u003ca href=\"https://medium.com/@levshmelevv/10-000-bounty-for-exposed-git-to-rce-304c7e1f54\"\u003e$10.000 bounty for exposed .git to RCE\u003c/a\u003e\n| Chained |\u003ca href=\"https://medium.com/@mukundbhuva/account-takeover-due-to-cognito-misconfiguration-earns-me-xxxx-3a7b8bb9a619\"\u003eAccount Takeover Due to Cognito Misconfiguration Earns Me €xxxx\u003c/a\u003e\n| Shift-Left |\u003ca href=\"https://pvs-studio.com/en/blog/posts/csharp/1038/\"\u003eConverting string to enum at the cost of 50 GB: let's analyze the CVE-2020-36620 vulnerability\u003c/a\u003e\n| Misconfiguration |\u003ca href=\"https://portswigger.net/research/detecting-web-message-misconfigurations-for-cross-domain-credential-theft\"\u003eDetecting web message misconfigurations for crossdomain credential theft\u003c/a\u003e\n| RCE |\u003ca href=\"https://blog.pksecurity.io/2023/01/16/2022-microsoft-teams-rce.html\"\u003e2022 Microsoft Teams RCE\u003c/a\u003e\n| Chained |\u003ca href=\"https://semgrep.dev/blog/2023/xml-security-in-java/\"\u003eXML Security in Java  Java XML security issues and how to address them\u003c/a\u003e\n| PII |\u003ca href=\"https://www.jhaddix.com/post/the-100-million-person-data-disclosure\"\u003eThe 100+ Million Person Data Disclosure\u003c/a\u003e\n| Misconfiguration |\u003ca href=\"https://ltidi.medium.com/the-untold-sendbird-misconfigurations-1496d252bc69\"\u003eThe Untold SendBird Misconfigurations\u003c/a\u003e  \n| Path Traversal |\u003ca href=\"https://mr-medi.github.io/research/2022/11/04/practical-client-side-path-traversal-attacks.html\"\u003ePRACTICAL CLIENT SIDE PATH TRAVERSAL ATTACKS\u003c/a\u003e\n| Chained |\u003ca href=\"https://tomforb.es/blog/infosys-leak/\"\u003eInfosys leaked Full Admin Access AWS keys on PyPi for over a year\u003c/a\u003e\n| CSRF |\u003ca href=\"\"\u003eCSRF protection bypass in GitHub Enterprise management console\u003c/a\u003e\n| Request Smuggling |\u003ca href=\"https://hackcommander.github.io/posts/2023/05/03/te-te-http-request-smuggling-obfuscating-te-header/\"\u003eTE.TE HTTP request smuggling obfuscating the TE header\u003c/a\u003e\n| Domain Takeover |\u003ca href=\"https://infosecwriteups.com/fastly-subdomain-takeover-2000-217bb180730f\"\u003eFastly Subdomain Takeover $2000\u003c/a\u003e\n| Misconfiguration |\u003ca href=\"https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp\"\u003eStealing passwords from infosec Mastodon  without bypassing CSP\u003c/a\u003e\n| Deserialization |\u003ca href=\"https://www.ambionics.io/blog/vbulletin-unserializable-but-unreachable\"\u003eUNSERIALIZABLE, BUT UNREACHABLE: REMOTE CODE EXECUTION ON VBULLETIN\u003c/a\u003e\n| RCE |\u003ca href=\"https://www.sonarsource.com/blog/openemr-remote-code-execution-in-your-healthcare-system/\"\u003eOpenEMR  Remote Code Execution in your Healthcare System\u003c/a\u003e\n| Chained |\u003ca href=\"https://systemweakness.com/common-nginx-misconfiguration-leads-to-path-traversal-d58701e997bc\"\u003eCommon Nginx Misconfiguration leads to Path Traversal\u003c/a\u003e\n| JAVA XML |\u003ca href=\"https://googleprojectzero.blogspot.com/2022/11/gregor-samsa-exploiting-java-xml.html\"\u003eGregor Samsa: Exploiting Java's XML Signature Verification\u003c/a\u003e\n| Bypass |\u003ca href=\"https://shubhdeepp.medium.com/how-i-got-apple-hall-of-fame-3d86f858c05f\"\u003eHow I got Apple Hall Of Fame !\u003c/a\u003e\n| Prompt Injection |\u003ca href=\"https://simonwillison.net/2023/May/2/prompt-injection-explained/\"\u003ePrompt injection explained, with video, slides, and a transcript\u003c/a\u003e\n| POC |\u003ca href=\"https://github.com/numanturle/CVE-2022-44877\"\u003eCentos Web Panel 7 Unauthenticated Remote Code Execution  CVE202244877\u003c/a\u003e\n| CORS |\u003ca href=\"https://jub0bs.com/posts/2022-02-08-cve-2022-21703-writeup/\"\u003eCVE-2022-21703: crossorigin request forgery against Grafana\u003c/a\u003e\n| Multiple |\u003ca href=\"https://apapedulimu.click/story-of-idor-on-google-product/\"\u003e2 CSRF 1 IDOR on Google Marketing Platform\u003c/a\u003e\n| S.I.D |\u003ca href=\"https://projectdiscovery.io/blog/php-http-server-source-disclosure\"\u003ePHP Development Server \u003c= 7.4.21  Remote Source Disclosure\u003c/a\u003e\n| Functionality Bug |\u003ca href=\"https://hackerone.com/reports/1102764\"\u003eLack of URL normalization renders BlockedPreviews feature ineffectual\u003c/a\u003e\n| Bypass |\u003ca href=\"https://medium.com/@querylab/bypass-premium-account-payment-getpocket-d813b249687c\"\u003eBypass Premium Account Payment (GetPocket)\u003c/a\u003e\n| Chained |\u003ca href=\"https://infosecwriteups.com/manipulating-the-websocket-handshake-to-exploit-vulnerabilities-7f8dc3504e9c\"\u003eManipulating the WebSocket handshake to exploit vulnerabilities\u003c/a\u003e\n| Cloud |\u003ca href=\"https://www.mend.io/blog/aws-targeted-by-a-package-backfill-attack/\"\u003eAWS Targeted by a Package Backfill Attack\u003c/a\u003e\n| SSPP |\u003ca href=\"https://www.intruder.io/research/server-side-prototype-pollution\"\u003eDetecting ServerSide Prototype Pollution\u003c/a\u003e\n| CSRF |\u003ca href=\"https://hackerone.com/reports/1122408\"\u003eCSRF on /api/graphql allows executing mutations through GET requests\u003c/a\u003e\n| SID|\u003ca href=\"https://medium.com/@botami143/i-have-found-microsoft-subdomain-website-database-list-database-username-password-1dab07d0c8ea\"\u003eI have Found Microsoft Subdomain Website database list, database username, password \u003c/a\u003e\n| File Read |\u003ca href=\"https://bugcrowd.com/disclosures/f7ce8504-0152-483b-bbf3-fb9b759f9f89/critical-local-file-read-in-electron-desktop-app\"\u003eCritical Local File Read in Electron Desktop App\u003c/a\u003e\n| Prototype Pollution |\u003ca href=\"https://securityonline.info/cve-2022-46175-json5-prototype-pollution-vulnerability/\"\u003eCVE-2022-46175: JSON5 Prototype Pollution Vulnerability\u003c/a\u003e\n| ATO |\u003ca href=\"https://kongsec.medium.com/hijacking-accounts-with-host-manipulation-using-collaborator-969f3234b29f\"\u003eHijacking accounts with host manipulation using collaborator\u003c/a\u003e\n| Prototype Polllution |\u003ca href=\"https://portswigger.net/research/server-side-prototype-pollution\"\u003eServer-side prototype pollution: Blackbox detection without the DoS\u003c/a\u003e\n| Misconfiguration |\u003ca href=\"https://prajwoldhungana487.medium.com/demographic-misconfiguration-9359910c6fcf\"\u003eDemographic Misconfiguration on Facebook live \u003c/a\u003e\n| RCE |\u003ca href=\"https://www.assetnote.io/resources/research/pre-auth-rce-in-aspera-faspex-case-guide-for-auditing-ruby-on-rails\"\u003ePreAuth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails\u003c/a\u003e\n| Chained |\u003ca href=\"https://threatpost.com/valve-bug-unlimited-funds/168710/\"\u003eCritical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets\u003c/a\u003e\n| Spoof |\u003ca href=\"https://medium.com/@hacxyk/how-we-spoofed-ens-domains-52acea2079f6\"\u003eHow we spoofed ENS domains for $15k\u003c/a\u003e\n| Cloud |\u003ca href=\"https://hackingthe.cloud/aws/general-knowledge/aws_organizations_defaults/\"\u003eAWS Organizations Defaults\u003c/a\u003e\n| Dependency Confusion |\u003ca href=\"https://hackerone.com/reports/1104874\"\u003eBasecamp disclosed on HackerOne: Insecure Bundler configuration\u003c/a\u003e\n| Chained |\u003ca href=\"https://notifybugme.medium.com/exploiting-s3-bucket-with-path-folder-to-access-pii-info-of-a-bank-91d8563cb45\"\u003eExploiting S3 bucket with path folder to Access PII info of A BANK\u003c/a\u003e\n| Chained |\u003ca href=\"https://z3r0tru5t.medium.com/open-redirect-to-account-takeover-f1405cbdf2d\"\u003eOpen Redirect to Account Takeover\u003c/a\u003e  \n| Chained |\u003ca href=\"https://ysamm.com/?p=629\"\u003eEnumerate internal cached URLs which lead to data exposure\u003c/a\u003e\n| Chained |\u003ca href=\"https://ysamm.com/?p=625\"\u003eOpen redirect in Instagram.com ($500)\u003c/a\u003e\n| Redirect |\u003ca href=\"https://g0dl3v3l.com/open-redirect-vulnerability-some-common-payloads-fd1dcd73541c\"\u003eOpen Redirect Vulnerability \u0026 Some Common Payloads\u003c/a\u003e\n| BLH |\u003ca href=\"https://proviesec.medium.com/broken-link-hijacking-what-it-is-and-how-to-get-bounties-with-it-ca64db6a3f74\"\u003eBroken Link hijacking — What it is and how to get bounties with it!\u003c/a\u003e\n| Recon |\u003ca href=\"https://cramppet.github.io/regulator/index.html\"\u003eA unique method of subdomain enumeration\u003c/a\u003e\n| Cloud |\u003ca href=\"https://blog.appsecco.com/exploiting-weak-configurations-in-google-identity-platform-cbddbd0e71e3\"\u003eExploiting weak configurations in Google Cloud Identity Platform\u003c/a\u003e\n| Deserialization |\u003ca href=\"https://talosintelligence.com/vulnerability_reports/TALOS-2022-1587\"\u003eVMware vCenter Server Platform Services Controller Unsafe Deserialization vulnerability\u003c/a\u003e\n| CVE |\u003ca href=\"https://blog.wpsec.com/wordpress-xxe-in-media-library-cve-2021-29447/\"\u003eWordPress XXE Vulnerability in Media Library – CVE-2021-29447 \u003c/a\u003e\n| CVE |\u003ca href=\"https://www.horizon3.ai/attack-research/attack-blogs/veeam-backup-and-replication-cve-2023-27532-deep-dive\"\u003eVeeam Backup and Replication CVE-2023-27532 Deep Dive\u003c/a\u003e\n| Prototype Pollution |\u003ca href=\"https://mikekitckchan.medium.com/a-brief-introduction-to-prototype-pollution-b154c23b40c5\"\u003eA Brief Introduction to Prototype Pollution\u003c/a\u003e\n| CORS |\u003ca href=\"https://mikekitckchan.medium.com/cors-misconfig-that-worths-usd200-4696eda5ab4c\"\u003eCORS misconfig that worths USD200\u003c/a\u003e\n| Insecure Design |\u003ca href=\"https://hackerone.com/reports/1256375\"\u003eBlog posts atom feed of a store with password protection can be accessed by anyone\u003c/a\u003e\n| Critical |\u003ca href=\"https://medium.com/immunefi/enzyme-finance-price-oracle-manipulation-bug-fix-postmortem-4e1f3d4201b5\"\u003eEnzyme Finance Price Oracle Manipulation Bug Fix Postmortem\u003c/a\u003e\n| Prototype Pollution |\u003ca href=\"https://labs.withsecure.com/publications/prototype-pollution-primer-for-pentesters-and-programmers\"\u003ePrototype Pollution Primer for Pentesters and Programmers \u003c/a\u003e\n| XXE |\u003ca href=\"https://rajanagori.medium.com/a-long-story-of-xxe-vulnerability-6a9a33276602\"\u003eA Long Story of XXE Vulnerability!!\u003c/a\u003e\n| Priv Escalation |\u003ca href=\"https://flatt.tech/reports/210401_pwn2own/\"\u003ePwn2Own Local Escalation of Privilege Category\u003c/a\u003e\n| RCE |\u003ca href=\"https://swordbytes.com/blog/security-advisory-overwolf-1-click-remote-code-execution-cve-2021-33501/\"\u003eOverwolf 1Click Remote Code Execution CVE-2021-33501\u003c/a\u003e\n| MFA Bypass |\u003ca href=\"https://www.varonis.com/blog/box-mfa-bypass-totp\"\u003eBypassing Box’s Timebased OneTime Password MFA\u003c/a\u003e\n| AWS |\u003ca href=\"https://securitylabs.datadoghq.com/articles/bypass-cloudtrail-aws-service-catalog-and-other/\"\u003eBypassing CloudTrail in AWS Service Catalog, and Other Logging Research\u003c/a\u003e\n| ATO |\u003ca href=\"https://portswigger.net/daily-swig/add-yourself-as-super-admin-researcher-details-easy-to-exploit-bug-that-exposed-gsuite-accounts-to-full-takeover\"\u003e‘Add yourself as super admin’ – Researcher details easytoexploit bug that exposed GSuite accounts to full takeover\u003c/a\u003e\n| Critical |\u003ca href=\"https://blog.thalium.re/posts/deserialization-bug-through-rdp-smart-card-extension/\"\u003eRemote Deserialization Bug in Microsoft's RDP Client through Smart Card Extension (CVE202138666) Bounty award: $5,000.\u003c/a\u003e\n| Confusion |\u003ca href=\"https://claroty.com/team82/research/exploiting-url-parsing-confusion\"\u003eExploiting URL Parsing Confusion Vulnerabilities\u003c/a\u003e\n| VA |\u003ca href=\"https://medium.com/@cy1337/vulnerability-analysis-with-ghidra-scripting-ccf416cfa56d\"\u003eVulnerability Analysis with Ghidra Scripting\u003c/a\u003e\n| Domain Takeover |\u003ca href=\"https://0xelmalky.medium.com/subdomain-takeover-via-flywheel-447a71d77396\"\u003eSubdomain Takeover Via Flywheel\u003c/a\u003e\n| SID |\u003ca href=\"https://hackerone.com/reports/1087489\"\u003eGithub access token exposure\u003c/a\u003e\n| ATO |\u003ca href=\"https://medium.com/techiepedia/how-i-was-able-to-takeover-any-account-on-foxit-com-7a08efa0144f\"\u003eHow I was able to Takeover Accounts on Foxit.com\u003c/a\u003e\n| Apple |\u003ca href=\"https://blog.infiltrateops.io/hacking-apple-two-successful-exploits-and-positive-thoughts-on-their-bug-bounty-program-963efe7518f6\"\u003eHacking Apple: Two Successful Exploits and Positive Thoughts on their Bug Bounty Program\u003c/a\u003e\n| PP |\u003ca href=\"https://www.mend.io/blog/prototype-pollution-vulnerabilities/\"\u003eThe Complete Guide to Prototype Pollution Vulnerabilities \u003c/a\u003e\n| Chained |\u003ca href=\"https://inakcf.medium.com/2fa-bypass-via-forced-browsing-9e511dfdb8df\"\u003e2FA Bypass via Forced Browsing\u003c/a\u003e\n| Chained |\u003ca href=\"https://sensepost.com/blog/2021/duo-two-factor-authentication-bypass/\"\u003eDuo Twofactor Authentication Bypass\u003c/a\u003e\n| Chained |\u003ca href=\"https://medium.com/@kalvik/account-takeover-a-bonus-vulnerability-3c2dc4e607ea\"\u003eAccount Takeover + A Bonus Vulnerability\u003c/a\u003e\n| Websocket |\u003ca href=\"https://infosecwriteups.com/cross-site-websocket-hijacking-cswsh-ce2a6b0747fc\"\u003eCrossSite WebSocket Hijacking (CSWSH)\u003c/a\u003e\n  \n\n\n## Vulnerable and Outdated Components\n\n| Category | Writeup |\n|-----------|-----|\n| Outdated Package |\u003ca href=\"https://redcanary.com/blog/testing-and-validation/fuzzing/\"\u003eFuzzing Golang msgpack for fun and panic\u003c/a\u003e\n| Session |\u003ca href=\"https://blog.sonarsource.com/zabbix-case-study-of-unsafe-session-storage\"\u003eZabbix  A Case Study of Unsafe Session Storage \u003c/a\u003e\n| CVE |\u003ca href=\"https://github.com/hakivvi/CVE-2022-29464\"\u003eWSO2 RCE (CVE202229464) exploit and writeup\u003c/a\u003e\n| Wireless |\u003ca href=\"https://boschko.ca/tenda_ac1200_router/\"\u003eVulnerabilities in Tenda's W15Ev2 AC1200 Router\u003c/a\u003e\n| CVE |\u003ca href=\"https://googleprojectzero.blogspot.com/2022/12/exploiting-CVE-2022-42703-bringing-back-the-stack-attack.html\"\u003eExploiting CVE202242703  Bringing back the stack attack\u003c/a\u003e\n\n\n\n\n## Identification and Authentication Issues / Bugs\n\n| Category | Writeup |\n|-----------|-----|\n| IAM | \u003ca href=\"https://hackerone.com/reports/921780\"\u003eImproper Authentication  any user can login as other user with otp/logout \u0026 otp/login\u003c/a\u003e\n| JWT |\u003ca href=\"https://systemweakness.com/how-to-test-for-jwt-attacks-513da89abe94\"\u003eHow to test for JWT attacks\u003c/a\u003e\n| Insecure Design |\u003ca href=\"https://infosecwriteups.com/bypassed-the-subscription-and-got-the-certification-27c571c2f383\"\u003eBypassed the subscription and got the certification\u003c/a\u003e\n| BAC |\u003ca href=\"https://systemweakness.com/broken-authentication-login-with-google-b170fbb4b6d0\"\u003eBroken Authentication Login With Google\u003c/a\u003e\n| IAM |\u003ca href=\"https://hackerone.com/reports/1552110\"\u003eOAUTH2 bearer notchecked for connection reuse\u003c/a\u003e\n| Bypass |\u003ca href=\"https://vaibhavgaikwad1712.medium.com/2fa-bypass-using-response-manipulation-29d6c2583936\"\u003e2fa Bypass Using Response Manipulation\u003c/a\u003e\n| OTP Bypass |\u003ca href=\"https://systemweakness.com/brute-forcing-otp-via-bypassing-rate-limit-c5ee6b25c2a8\"\u003eOTP bruteforce via rate limit bypass\u003c/a\u003e\n| Password Flaw |\u003ca href=\"https://anugrahsr.github.io/posts/10-Password-reset-flaws/\"\u003e10 Password Reset Flaws\u003c/a\u003e\n| Chained |\u003ca href=\"https://hackerone.com/reports/1245762\"\u003eAccount Takeover via SMS Authentication Flow\u003c/a\u003e\n| Bypass |\u003ca href=\"https://aravind07.medium.com/bypassing-login-page-in-2-mins-5b773d46f4d\"\u003eBypassing Login Page in 2 Mins\u003c/a\u003e\n| RCE |\u003ca href=\"https://haxolot.com/posts/2021/moodle_pre_auth_shibboleth_rce_part1/\"\u003ePreAuth RCE in Moodle Part I  PHP Object Injection in Shibboleth Module\u003c/a\u003e\n| RCE |\u003ca href=\"https://haxolot.com/posts/2022/moodle_pre_auth_shibboleth_rce_part2/\"\u003ePreAuth RCE in Moodle Part II  Session Hijack in Moodle's Shibboleth\u003c/a\u003e\n| Web-Cache |\u003ca href=\"https://infosecwriteups.com/web-cache-poisoning-a-tale-of-chaining-unkeyed-inputs-6e3cb026bd23\"\u003eWeb Cache Poisoning: A Tale of chaining unkeyed inputs\u003c/a\u003e\n| JWT |\u003ca href=\"https://medium.com/@sajan.dhakate/exploiting-json-web-token-jwt-73d172b5bc02\"\u003eEXPLOITING JSON WEB TOKEN [JWT]\u003c/a\u003e\n| RCE |\u003ca href=\"https://www.onekey.com/resource/security-advisory-remote-command-execution-in-binwalk\"\u003eSecurity Advisory: Remote Command Execution in binwalk\u003c/a\u003e\n| OAuth |\u003ca href=\"https://infosecwriteups.com/oauth-2-0-hacking-67e5d2b9b495\"\u003eOAuth 2.0 Hacking\u003c/a\u003e\n| Bypass |\u003ca href=\"https://thehackernews.com/2022/01/researchers-bypass-sms-based-multi.html\"\u003eResearchers Bypass SMSbased MultiFactor Authentication Protecting Box Accounts\u003c/a\u003e\n| Rate Limit |\u003ca href=\"https://4bdoz.medium.com/trick-to-bypass-rate-limit-of-password-reset-functionality-a9923d3d7c4b\"\u003eTrick to bypass rate limit of password reset functionality\u003c/a\u003e\n| Chained |\u003ca href=\"https://blog.dixitaditya.com/oauth-account-takeover\"\u003eExploiting OAuth: Journey to Account Takeover \u003c/a\u003e\n| Chained |\u003ca href=\"https://infosecwriteups.com/a-tale-of-0-click-account-takeover-and-2fa-bypass-b369cd70e42f\"\u003eA tale of 0Click Account Takeover and 2FA Bypass\u003c/a\u003e\n| Cache Poisoning |\u003ca href=\"https://youst.in/posts/cache-poisoning-at-scale/\"\u003eCache Poisoning at Scale\u003c/a\u003e\n\n\n## Software and Data Integrity Failure\n\n| Category | Writeup |\n|-----------|-----|\n| Software failure |\u003ca href=\"https://blog.dixitaditya.com/pwning-a-server-using-markdown\"\u003ePwning a Server using Markdown\u003c/a\u003e\n| Software failure |\u003ca href=\"https://hackerone.com/reports/1596663\"\u003eAdmin can create a hidden admin account which even the owner can not detect and remove and do administrative actions on the application.\u003c/a\u003e\n| XSS |\u003ca href=\"https://medium.com/pentesternepal/how-i-found-a-bug-in-apple-within-just-in-5min-d7357237d7a0\"\u003eHow I found a bug in Apple within just in 5min\u003c/a\u003e\n| Hypervisor |\u003ca href=\"https://blog.impalabs.com/2212_advisory_huawei-security-hypervisor.html\"\u003eHuawei Security Hypervisor Vulnerability\u003c/a\u003e\n| SAML |\u003ca href=\"https://tutorialboy24.blogspot.com/2022/11/a-brief-introduction-to-saml-security.html\"\u003eA Brief Introduction to SAML Security Vector\u003c/a\u003e\n| Integration failure |\u003ca href=\"https://github.com/httpvoid/writeups/blob/main/Hacking-Google-Drive-Integrations.md\"\u003eHacking Google Drive Integrations\u003c/a\u003e \n| Dependency Confusion |\u003ca href=\"https://dhiyaneshgeek.github.io/web/security/2021/09/04/dependency-confusion/\"\u003eDependency Confusion\u003c/a\u003e\n| Race Condition |\u003ca href=\"https://medium.com/@bababounty99/race-condition-resulted-in-using-the-feature-which-was-supposed-to-be-obtained-after-subscription-2bfe968d358c\"\u003eRace Condition — Resulted in using the feature which was supposed to be obtained after subscription.\u003c/a\u003e\n| RCE |\u003ca href=\"https://shabarkin.medium.com/1-click-rce-in-electron-applications-79b52e1fe8b8\"\u003e1click RCE in Electron Applications\u003c/a\u003e\n| SSCP |\u003ca href=\"https://medium.com/@jacopotediosi/worldwide-server-side-cache-poisoning-on-all-akamai-edge-nodes-50k-bounty-earned-f97d80f3922b\"\u003eWorldwide Serverside Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned)\u003c/a\u003e \n| AWS |\u003ca href=\"https://securitylabs.datadoghq.com/articles/appsync-vulnerability-disclosure/\"\u003eA Confused Deputy Vulnerability in AWS AppSync\u003c/a\u003e\n| AWS |\u003ca href=\"https://portswigger.net/daily-swig/vulnerability-in-aws-appsync-allowed-unauthorized-access-to-cloud-resources\"\u003eVulnerability in AWS AppSync allowed unauthorized access to cloud resources\u003c/a\u003e\n| CMS |\u003ca href=\"https://portswigger.net/daily-swig/melis-platform-cms-patched-for-critical-rce-flaw\"\u003eMelis Platform CMS patched for critical RCE flaw\u003c/a\u003e\n\n\n\n\n## Security Logging and Monitoring\n| Category | Writeup |\n|-----------|-----|  \n| JWT Secret |\u003ca href=\"https://ssd-disclosure.com/ssd-advisory-cisco-secure-manager-appliance-jwt_api_impl-hardcoded-jwt-secret-elevation-of-privilege/\"\u003eSSD Advisory – Cisco Secure Manager Appliance jwt_api_impl Hardcoded JWT Secret Elevation of Privilege\u003c/a\u003e\n| Log Recon |\u003ca href=\"https://beny23.github.io/posts/harvesting_logs_for_fun_and_profit/\"\u003eHarvesting Logs for Fun and Profit\u003c/a\u003e\n\n  \n  \n## Server Side Request Forgery\n| Category | Writeup |\n|-----------|-----| \n| Cloud SSRF |\u003ca href=\"https://bugs.xdavidhu.me/google/2021/12/31/fixing-the-unfixable-story-of-a-google-cloud-ssrf/\"\u003eStory of a Google Cloud SSRF\u003c/a\u003e\n| Bypass SSRF |\u003ca href=\"https://blog.deesee.xyz/fuzzing/security/2021/02/26/ssrf-bypassing-hostname-restrictions-fuzzing.html\"\u003eSSRF: Bypassing hostname restrictions with fuzzing\u003c/a\u003e\n| Chained |\u003ca href=\"https://sirleeroyjenkins.medium.com/just-gopher-it-escalating-a-blind-ssrf-to-rce-for-15k-f5329a974530\"\u003eJust Gopher It: Escalating a Blind SSRF to RCE for $15k\u003c/a\u003e\n| File-based SSRF |\u003ca href=\"https://hackerone.com/reports/1092230\"\u003eFogBugz import attachment full SSRF requiring vulnerability \u003c/a\u003e\n| Blind SSRF |\u003ca href=\"https://blog.assetnote.io/2021/01/13/blind-ssrf-chains/#confluence\"\u003eA Glossary of Blind SSRF Chains\u003c/a\u003e\n| Recon SSRF |\u003ca href=\"https://labs.detectify.com/security-guidance/ssrf-vulnerabilities-and-where-to-find-them/\"\u003eSSRF vulnerabilities and where to find them\u003c/a\u003e\n| Chained |\u003ca href=\"https://www.assetnote.io/resources/research/stealing-administrative-jwts-through-post-auth-ssrf-cve-2021-22056\"\u003eStealing administrative JWT's through post auth SSRF (CVE-2021-22056)\u003c/a\u003e\n| SSRF |\u003ca href=\"https://www.assetnote.io/resources/research/turning-bad-ssrf-to-good-ssrf-websphere-portal-cve-2021-27748\"\u003eTurning bad SSRF to good SSRF: Websphere Portal\u003c/a\u003e\n| SSRF |\u003ca href=\"https://hackerone.com/reports/941178\"\u003eSSRF for kubeapiserver cloudprovider scene\u003c/a\u003e\n| SSRF |\u003ca href=\"https://hackerone.com/reports/1189367\"\u003eFull read SSRF that can leak aws metadata and local file inclusion (www.evernote.com)\u003c/a\u003e\n| SSRF |\u003ca href=\"https://portswigger.net/daily-swig/java-rmi-services-often-vulnerable-to-ssrf-attacks-research\"\u003eJava RMI services often vulnerable to SSRF attacks – research\u003c/a\u003e\n| SSRF |\u003ca href=\"https://www.shielder.com/advisories/cisco-broadworks-commpilot-ssrf/\"\u003eCisco BroadWorks CommPilot Application Software Unauthenticated ServerSide Request Forgery (CVE202220951)\u003c/a\u003e\n| SSRF |\u003ca href=\"https://goteleport.com/blog/ssrf-attacks/\"\u003eSSRF Attack Examples and Mitigations\u003c/a\u003e\n| CSPA |\u003ca href=\"https://thehemdeep.medium.com/cross-site-port-attack-in-wild-9d2f6af36455\"\u003eCross Site Port Attack in Wild\u003c/a\u003e\n| SSRF |\u003ca href=\"https://gccybermonks.com/posts/ssrfvision/\"\u003eAnother vision for SSRF\u003c/a\u003e\n| SSRF |\u003ca href=\"https://medium.com/@rramgattie/securing-pdf-generators-against-ssrf-vulnerabilities-b8f9b061c14b\"\u003eSecuring PDF Generators Against SSRF Vulnerabilities\u003c/a\u003e\n| CMS-SSRF |\u003ca href=\"https://www.sonarsource.com/blog/wordpress-core-unauthenticated-blind-ssrf/\"\u003eWordPress Core  Unauthenticated Blind SSRF\u003c/a\u003e\n| SSRF Recon |\u003ca href=\"https://systemweakness.com/bug-bounty-how-i-found-an-ssrf-reconnaissance-7b1821a1b1fd\"\u003eBug Bounty { How I found an SSRF ( Reconnaissance ) }\u003c/a\u003e\n| Cloud SSRF |\u003ca href=\"https://spidersilk.com/news/cloud-is-more-fun-with-an-ssrf\"\u003eCloud is more fun with an SSRF\u003c/a\u003e\n| SSRF |\u003ca href=\"https://blog.yeswehack.com/talent-development/server-side-prototype-pollution-how-to-detect-and-exploit/\"\u003eServer side prototype pollution, how to detect and exploit\u003c/a\u003e\n| SSRF |\u003ca href=\"https://infosecwriteups.com/ssrf-via-dns-rebinding-cve-2022-4096-b7bf75928bb2\"\u003eSSRF via DNS Rebinding (CVE-2022–4096)\u003c/a\u003e\n\n\n\n\n\n# Chained Issues / Chained Bugs : \n| Category | Writeup |\n|-----------|-----| \n| Chained |\u003ca href=\"https://medium.com/@tushar.tilak.sharma/a-tale-of-open-redirection-to-stored-xss-6ad426ae9d43\"\u003eA Tale of Open Redirection to Stored XSS\u003c/a\u003e\n\n\u003ca href=\"https://medium.com/@faique/storyofa1kbountyssrfd5c4868680f5\"\u003eStory of a $1k bounty — SSRF to leaking access token and other sensitive information\u003c/a\u003e  \n\n\u003ca href=\"https://medium.com/@TutorialBoy24/thestoryof3bugsthatleadtounauthorizedrcepascomsystemsd2dcb0410f3b\"\u003eThe story of 3 bugs that lead to Unauthorized RCE — Pascom Systems\u003c/a\u003e\n\n\u003ca href=\"https://www.ukusormus.com/bypassingcloudflarewafxssviasqlinjection/\"\u003eBypassing Cloudflare WAF: XSS via SQL Injection\u003c/a\u003e\n  \n\u003ca href=\"https://medium.com/@moSec/crlftoaccounttakeoverchainingbugs21a25dfa1cdf\"\u003eCRLF to Account takeover (chaining bugs)\u003c/a\u003e\n\n\u003ca href=\"https://portswigger.net/dailyswig/internetbugbountyhighseverityvulnerabilityinapachehttpservercouldleadtorce\"\u003eInternet Bug Bounty: High severity vulnerability in Apache HTTP Server could lead to RCE\u003c/a\u003e\n  \n\u003ca href=\"https://www.invicti.com/blog/websecurity/ssrfvulnerabilitiescausedbysniproxymisconfigurations/\"\u003eSSRF vulnerabilities caused by SNI proxy misconfigurations\u003c/a\u003e\n  \n\u003ca href=\"https://blog.sonarsource.co","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffardeen-ahmed%2FBug-bounty-Writeups","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffardeen-ahmed%2FBug-bounty-Writeups","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffardeen-ahmed%2FBug-bounty-Writeups/lists"}