hack and bug bounty
@hack_com
21
subscribers
20.9K
links
Download Telegram
Join
hack and bug bounty
21 subscribers
hack and bug bounty
Hunting for Hidden Treasures: Unveiling the 403 Bypass Bug Bounty Adventure ️♂️
Medium
Hunting for Hidden Treasures: Unveiling the 403 Bypass Bug Bounty Adventure
🕵️♂️
💰
Hello there,
hack and bug bounty
CVE-2023–39308: User Feedback <= 1.0.7 — Unauthenticated Stored XSS
Medium
CVE-2023–39308: User Feedback <= 1.0.7 — Unauthenticated Stored XSS
Submit Feedback feature doesn’t filter submitted Text. So, Attacker can submit malicious script.
hack and bug bounty
AirBnb Bug Bounty: Turning Self-XSS into Good-XSS #2
hack and bug bounty
Starting Bug Bounty ? | Bug Bounty Resources
hack and bug bounty
Uber | Exploiting Stored URL Redirect in Password Reset Token
hack and bug bounty
Hijacking tons of Instapage expired users Domains & Subdomains
hack and bug bounty
Privilege Escalation in a Django Application
Bug Bounty Findings by Meals
Privilege Escalation in a Django Application
Attached is the PDF of how I managed to escalate privileges to staff/superuser privileges via a misconfiguration. Django Privilege Escalation – Zero To Superuser
hack and bug bounty
Utilizing SSRF to Pivot Internal Networks
Bug Bounty Findings by Meals
Utilizing SSRF to Pivot Internal Networks
This is from a private bounty. The internal —-private.com domain was out of scope so I was asked to stop testing once I found the bug. SSRF To Pivot Internal Networks
hack and bug bounty
Exploiting Java Deserialization Via JBoss
Bug Bounty Findings by Meals
Exploiting Java Deserialization Via JBoss
Background First off, I would just like to reference the following sites/authors/tools for helping guide me along this route and providing a sweet tool to make this easy: I ran into a JMXInvokerSer…
hack and bug bounty
Getting Hustled by the Yahoo! Bug Bounty Program
Bug Bounty Findings by Meals
Getting Hustled by the Yahoo! Bug Bounty Program
Note: I was at one point the top bug reporter for Yahoo! If they do this to me. They are very likely to do this to you. Yahoo Remote Code Execution CMS Yahoo Response: Hey Sean, Our committee finis…
hack and bug bounty
XXE via SAML
Bug Bounty Findings by Meals
XXE via SAML
This was on a private bounty program. I have redacted all the info related to the program. Enjoy! Out of Band XML External Entity Injection via SAML – redacted
hack and bug bounty
Cisco Edge 340 Series v1.1 LFI as root
Bug Bounty Findings by Meals
Cisco Edge 340 Series v1.1 LFI as root
Originally I just had default administrator credentials then I poked around for less than 10 minutes and found a configuration export which allowed me to export files with root privileges. Attached…
hack and bug bounty
PhpThumb.php SSRF/LFI
Bug Bounty Findings by Meals
PhpThumb.php SSRF/LFI
I initially found this issue on a bounty, however it was marked out of scope on a third party provider. It may be possible to turn this into a RCE. Since I had no reason to escalate since no paymen…
hack and bug bounty
Various Server Side Request Forgery Issues
Bug Bounty Findings by Meals
Various Server Side Request Forgery Issues
SSRF 1 This SSRF allowed me to view local files on the host as well as port scan internal hosts. Reading /etc/passwd using the file protocol. Brute-forcing for log files using BurpSuite Intruder: S…
hack and bug bounty
XSS via Loading Remote SVG
Bug Bounty Findings by Meals
XSS via Loading Remote SVG
This XSS was via embedly which controls the content-type response to image types. Luckily .svg was allowed. I used this blog to help create a .svg that contained XSS. PoC: <?xml version=&…
hack and bug bounty
JFrog Artifactory XXE
Bug Bounty Findings by Meals
JFrog Artifactory XXE
JFrog Artifactory XXE
hack and bug bounty
Instagram App Access Token
These aren't the access_tokens you're looking for
Instagram App Access Token - These aren't the access_tokens you're looking for
In Facebook Graph API as defined by the developer documentation, there are several access tokens, to authenticate against various API endpoints. User Access Tokenmake requests on behalf of the user, normally obtained via OAuth facebook.com/dialog/oauth Page…
hack and bug bounty
Bypass video capture limit on Ray-Ban Stories
These aren't the access_tokens you're looking for
Bypass video capture limit on Ray-Ban Stories - These aren't the access_tokens you're looking for
Meta Rayban Stories has lower-level settings to change via the View (Assistant app) for example enable Assistant change inner LED notification level change volume Since the method for these settings are shared for other options defined in the firmware, it…
hack and bug bounty
View the country of a private Instagram User
These aren't the access_tokens you're looking for
View the country of a private Instagram User - These aren't the access_tokens you're looking for
There is a XController that allows information to be returned about an Instagram user. This feature discloses the country of a private account. Even if this feature is an ad tool, this does not support the privacy of a private account. Additionally the owner…
hack and bug bounty
Access to CrowdTangle Deletion Framework API
These aren't the access_tokens you're looking for
Access to CrowdTangle Deletion Framework API - These aren't the access_tokens you're looking for
There is a root GraphQL query that gives one access to numerous CrowdTangle API calls including one that lists the deleted objects for popular Facebook entities by date. Regular users shouldn’t have access to CrowdTangle this way. The data was of the form…