“Exif Data Exposure” by Shrey Shah (Jerry) https://link.medium.com/v7ZoujA1I3
Medium
Exif Data Exposure
Summary :
“Account Takeover Through Password Reset Poisoning” by Vishal Bharad https://link.medium.com/7Nbald51I3
Medium
Account Takeover Through Password Reset Poisoning
Introduction :
“Readme.com Account Takeover #BugBounty #FullDisclosure” by Ankush Goel https://link.medium.com/aXznAUn2I3
Medium
Readme.com Account Takeover #BugBounty #FullDisclosure #Fixed
Hi Everyone,
“Full Account Takeover Changing Email And Password of any User through API Parameters” by Adesh Kolte https://link.medium.com/8inNnQw2I3
Medium
Full Account Takeover via Changing Email And Password of any User through API Parameters
I’m going to talk about a common and strange password reset system that I have seen many times in Bug Hunting and in many VAPT projects. and in many cases this system opens the door to attacker to…
“How I found the most critical bug in live bug bounty event?” by Lakshay https://link.medium.com/CwfZBZO2I3
Medium
How I found the most critical bug in live bug bounty event?
Hey Folks! Hope you guys are doing great.
“Password Reset Vulnerability — Full Account takeover (Insecure Direct Object Reference)” by Muhammad Asim Shahzad https://link.medium.com/d6BPOQZ2I3
“Two-factor authentication security testing and possible bypasses” by Max https://link.medium.com/vWnWo4H6A3
Medium
Two-factor authentication security testing and possible bypasses
Before I began to comprehend the complex science of information security, it seemed to me that Two-Factor Authentication is a guaranteed…
Dropbox bug bounty program has paid out over $1,000,000
https://blogs.dropbox.com/tech/2020/02/dropbox-bug-bounty-program-has-paid-out-over-1000000/
https://blogs.dropbox.com/tech/2020/02/dropbox-bug-bounty-program-has-paid-out-over-1000000/
Forwarded from h1disclosebot
GitHub Security Lab disclosed a bug submitted by calderpwn: https://t.co/kJySKZdV0Z - Bounty: $1,000 #hackerone… https://t.co/x9GJt0F42A
HackerOne
GitHub Security Lab disclosed on HackerOne: CodeQL query to detect...
Report created by importer