Awesome-Bugbounty-Writeups
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
https://github.com/devanshbatham/Awesome-Bugbounty-Writeups
Last synced: 8 days ago
JSON representation
-
2FA related issues
- 2FA Bypass via logical rate limiting Bypass
- Bypass 2FA in a website
- How to bypass 2FA with a HTTP header
- How I hacked 40k user accounts of microsoft using 2FA bypass outlook
- How I abused 2FA to maintain persistence after password recovery change google microsoft instragram
- Bypass hackerone 2FA
- Facebook Bug bounty : How I was able to enumerate instagram accounts who had enabled 2FA
- Weird and simple 2FA bypass
- Instagram account is reactivated without entering 2FA
- How I cracked 2FA with simple factor bruteforce
- How I hacked 40k user accounts of microsoft using 2FA bypass outlook
- Bypass hackerone 2FA
-
Android Pentesting
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
- Android Pentesting Lab (Step by Step guide for beginners!)
-
Authentication Bypass
- Authentication bypass on UBER's SSO
- Authentication bypass on SSO ubnt.com
- Touch ID authentication Bypass on evernote and dropbox iOS apps
- Oauth authentication bypass on airbnb acquistion using wierd 1 char open redirect
- Two factor authentication bypass
- Authentication bypass in nodejs application
- Authentication bypass in CISCO meraki
- Oauth authentication bypass on airbnb acquistion using wierd 1 char open redirect
- Instagram multi factor authentication bypass
- Symantec authentication Bypass
- Slack SAML authentocation bypass
- Authentication Bypass on airbnb via oauth tokens theft
- Inspect element leads to stripe account lockout authentication Bypass
- Oauth authentication bypass on airbnb acquistion using wierd 1 char open redirect
- Oauth authentication bypass on airbnb acquistion using wierd 1 char open redirect
-
Buffer Overflow Writeups
- Buffer Overflow Attack Book pdf
- Stack-Based Buffer Overflow Attacks: Explained and Examples
- How Buffer Overflow Attacks Work
- Binary Exploitation: Buffer Overflows
- WHAT IS A BUFFER OVERFLOW? LEARN ABOUT BUFFER OVERRUN VULNERABILITIES, EXPLOITS & ATTACKS
- Github Repository on Buffer Overflow Attack
- How Buffer Overflow Attacks Work
-
Clickjacking (UI redressing attack)
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- 12000 intersection betwen clickjacking XSS and denial of service
- Steam fire and paste : a story of uxss via DOM XSS and Clickjacking in steam inventory helper
- Bypass CSRF with clickjacking on Google org
- Google Bug bounty Clickjacking on Google payment
- Google APIs Clickjacking worth 1337$
- 1800 worth Clickjacking
- Account takeover with clickjacking
- Clickjacking on google CSE
- How I accidentally found clickjacking in Facebook
- Clickjacking on google myaccount worth 7500
- Clickjacking in google docs and void typing feature
- binary.com clickjacking vulnerability exploiting HTML5 security features
- Yet another Google Clickjacking
- Redressing instagram leaking application tokens via instagram clickjacking vulnerability
- Microsoft Yammer clickjacking exploiting HTML5 security features
- Firefox find my device clickjacking
- Whatsapp Clickjacking vulnerability
- Telegram WEB client clickjacking vulnerability
- Facebook Clickjacking : how we put a new dress on facebook UI
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Redressing instagram leaking application tokens via instagram clickjacking vulnerability
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Whatsapp Clickjacking vulnerability
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Reflected DOM XSS and Clickjacking
- Clickjacking on google CSE
- Microsoft Yammer clickjacking exploiting HTML5 security features
- Telegram WEB client clickjacking vulnerability
- Firefox find my device clickjacking
- Facebook Clickjacking : how we put a new dress on facebook UI
-
Contributing
-
CORS related issues
- CORS to CSRF attack
- CORS bug on google's 404 page (rewarded)
- CORS misconfiguration leading to private information disclosure
- CORS misconfiguration account takeover out of scope to grab items in scope
- Chrome CORS
- Bypassing CORS
- An unexploited CORS misconfiguration reflecting further issues
- Think outside the scope advanced cors exploitation techniques
- Think outside the scope advanced cors exploitation techniques
- A simple CORS misconfiguration leaked private post of twitter facebook instagram
- Full account takeover through CORS with connection sockets
- Exploiting insecure CORS API api.artsy.net
- Pre domain wildcard CORS exploitation
- Pre domain wildcard CORS exploitation
- Exploiting misconfigured CORS on popular BTC site
- Think outside the scope advanced cors exploitation techniques
- Explpoiting CORS misconfiguration
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- Think outside the scope advanced cors exploitation techniques
- Pre domain wildcard CORS exploitation
- CORS bug on google's 404 page (rewarded)
- CORS misconfiguration leading to private information disclosure
Programming Languages
Categories
Cross Site Scripting (XSS)
2,111
Remote Code Execution (RCE)
429
Subdomain Takeover
316
Cross Site Request Forgery (CSRF)
163
Denial of Service (DOS)
127
SQL Injection(SQLI)
110
CORS related issues
98
Local File Inclusion (LFI)
71
Server Side Request Forgery (SSRF)
60
Clickjacking (UI redressing attack)
54
Android Pentesting
19
Race Condition
19
Authentication Bypass
15
2FA related issues
12
Buffer Overflow Writeups
7
Insecure Direct Object Reference (IDOR)
4
Maintainers
2
Contributing
1
Sub Categories