Some Weird Zero Click Account Takeover Techniques
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…Continue reading on Medium »
Read more...
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…Continue reading on Medium »
Read more...
Medium
Some Weird Zero Click Account Takeover Techniques
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…
How I Earned a $500 Bug Bounty for a P5 Informational Vulnerability
https://medium.com/@swarooppatil3125/how-i-earned-a-500-bug-bounty-for-a-p5-informational-vulnerability-a20e2c68e3d4?source=rss------bug_bounty-5
https://medium.com/@swarooppatil3125/how-i-earned-a-500-bug-bounty-for-a-p5-informational-vulnerability-a20e2c68e3d4?source=rss------bug_bounty-5
Bug bounty hunters often believe that only critical bugs pay.
This write-up proves otherwise.Continue reading on Medium » (https://medium.com/@swarooppatil3125/how-i-earned-a-500-bug-bounty-for-a-p5-informational-vulnerability-a20e2c68e3d4?source=rss------bug_bounty-5)
This write-up proves otherwise.Continue reading on Medium » (https://medium.com/@swarooppatil3125/how-i-earned-a-500-bug-bounty-for-a-p5-informational-vulnerability-a20e2c68e3d4?source=rss------bug_bounty-5)
HTML Injection to Data Exfiltration: Weaponizing CSS
https://infosecwriteups.com/html-injection-to-data-exfiltration-weaponizing-css-88ec1639a0cd?source=rss------bug_bounty-5
https://infosecwriteups.com/html-injection-to-data-exfiltration-weaponizing-css-88ec1639a0cd?source=rss------bug_bounty-5
🐞 Found HTML Injection ? Don’t Stop There.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/html-injection-to-data-exfiltration-weaponizing-css-88ec1639a0cd?source=rss------bug_bounty-5)
Clock Skew - Time Can Change Anything
https://shahjerry33.medium.com/clock-skew-time-can-change-anything-0bb84e9635de?source=rss------bug_bounty-5
https://shahjerry33.medium.com/clock-skew-time-can-change-anything-0bb84e9635de?source=rss------bug_bounty-5
SummaryContinue reading on Medium » (https://shahjerry33.medium.com/clock-skew-time-can-change-anything-0bb84e9635de?source=rss------bug_bounty-5)
Thirdweb bug bounty program: Dishonourable Dealings
https://medium.com/@alexanderwpryor/thirdweb-bug-bounty-program-dishonourable-dealings-b8e03b570c21?source=rss------bug_bounty-5
https://medium.com/@alexanderwpryor/thirdweb-bug-bounty-program-dishonourable-dealings-b8e03b570c21?source=rss------bug_bounty-5
Bug bounty programs exist for a simple reason, to encourage researchers to report security issues responsibly, privately, and in good…Continue reading on Medium » (https://medium.com/@alexanderwpryor/thirdweb-bug-bounty-program-dishonourable-dealings-b8e03b570c21?source=rss------bug_bounty-5)
JWT | Algorithm Confusion Attacks
https://medium.com/@amrsmooke321/jwt-algorithm-confusion-attacks-e0a27f42b42c?source=rss------bug_bounty-5
https://medium.com/@amrsmooke321/jwt-algorithm-confusion-attacks-e0a27f42b42c?source=rss------bug_bounty-5
Algorithm confusion attacks (also known as key confusion attacks or RS256 → HS256 confusion) are one of the most devastating classes of…Continue reading on Medium » (https://medium.com/@amrsmooke321/jwt-algorithm-confusion-attacks-e0a27f42b42c?source=rss------bug_bounty-5)
Passing the CWL Web Red Team Analyst (WEB-RTA) Exam — My Experience 2026
Sharing my experience of passing the WEB-RTA exam, covering the course, labs, tools used, and lessons learned.Continue reading on Medium »
Read more...
Sharing my experience of passing the WEB-RTA exam, covering the course, labs, tools used, and lessons learned.Continue reading on Medium »
Read more...
Medium
Passing the CWL Web Red Team Analyst (WEB-RTA) Exam — My Experience 2026
Sharing my experience of passing the WEB-RTA exam, covering the course, labs, tools used, and lessons learned.
Breaking Into Web Application Security: My WEB-RTA Certification Experience
Hello everyone 👋Continue reading on Medium »
Read more...
Hello everyone 👋Continue reading on Medium »
Read more...
Medium
Breaking Into Web Application Security: My WEB-RTA Certification Experience
Hello everyone 👋
FULL ACCOUNT WILL DIE
From a simple UI bypass to a catastrophic identity collision and total account erasure. A deep dive into a critical P1 logic flawContinue reading on Medium »
Read more...
From a simple UI bypass to a catastrophic identity collision and total account erasure. A deep dive into a critical P1 logic flawContinue reading on Medium »
Read more...
Medium
FULL ACCOUNT WILL DIE
From a simple UI bypass to a catastrophic identity collision and total account erasure. A deep dive into a critical P1 logic flaw
Bug Bounty Isn’t About Speed — It’s About Seeing What Others Ignore
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
Bug Bounty Isn’t About Speed — It’s About Seeing What Others Ignore 👀💡
Hey there!😁