السلام عليكم ورحمة الله و بركاتهContinue reading on Medium » (https://medium.com/@amrturboo11/misconfiguration-in-wordpress-wp-cron-php-to-peform-dos-attack-ada4f28c9dfb?source=rss------bug_bounty-5)
How I Discovered 5 broken Access Control Bugs in a Single Web Application
https://medium.com/@0xyz_/how-i-discovered-5-broken-access-control-bugs-in-a-single-web-application-44d95652872f?source=rss------bug_bounty-5
https://medium.com/@0xyz_/how-i-discovered-5-broken-access-control-bugs-in-a-single-web-application-44d95652872f?source=rss------bug_bounty-5
Hi Hunters,Continue reading on Medium » (https://medium.com/@0xyz_/how-i-discovered-5-broken-access-control-bugs-in-a-single-web-application-44d95652872f?source=rss------bug_bounty-5)
How I Turned $3 Into 8 Paid Bugs
https://medium.com/@0xs3fo/how-i-turned-3-into-8-paid-bugs-b81c5384465c?source=rss------bug_bounty-5
https://medium.com/@0xs3fo/how-i-turned-3-into-8-paid-bugs-b81c5384465c?source=rss------bug_bounty-5
بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ
اللَّهُمَّ صَلِّ وَسَلِّمْ وَبَارِكْ عَلَى سَيِّدِنَا مُحَمَّدٍContinue reading on Medium » (https://medium.com/@0xs3fo/how-i-turned-3-into-8-paid-bugs-b81c5384465c?source=rss------bug_bounty-5)
اللَّهُمَّ صَلِّ وَسَلِّمْ وَبَارِكْ عَلَى سَيِّدِنَا مُحَمَّدٍContinue reading on Medium » (https://medium.com/@0xs3fo/how-i-turned-3-into-8-paid-bugs-b81c5384465c?source=rss------bug_bounty-5)
Bypassing 2FA via State Overwrite: A Tale of Logic Flaws and WAF Evasion
How an unprotected API endpoint allowed complete removal of Two-Factor Authentication using a desynchronized state.Continue reading on Medium »
Read more...
How an unprotected API endpoint allowed complete removal of Two-Factor Authentication using a desynchronized state.Continue reading on Medium »
Read more...
Medium
Bypassing 2FA via State Overwrite: A Tale of Logic Flaws and WAF Evasion
How an unprotected API endpoint allowed complete removal of Two-Factor Authentication using a desynchronized state.
Bypassing 2FA via State Overwrite: A Tale of Logic Flaws and WAF Evasion
https://medium.com/@HackerMD/bypassing-2fa-via-state-overwrite-a-tale-of-logic-flaws-and-waf-evasion-7e8c15a76282?source=rss------bug_bounty-5
https://medium.com/@HackerMD/bypassing-2fa-via-state-overwrite-a-tale-of-logic-flaws-and-waf-evasion-7e8c15a76282?source=rss------bug_bounty-5
How an unprotected API endpoint allowed complete removal of Two-Factor Authentication using a desynchronized state.Continue reading on Medium » (https://medium.com/@HackerMD/bypassing-2fa-via-state-overwrite-a-tale-of-logic-flaws-and-waf-evasion-7e8c15a76282?source=rss------bug_bounty-5)
When Logout Isn’t Really Goodbye: A Subtle Data Exposure Bug.
Continue reading on InfoSec Write-ups »
Read more...
Continue reading on InfoSec Write-ups »
Read more...
Medium
When Logout Isn’t Really Goodbye: A Subtle Data Exposure Bug.
When Logout Isn’t Really Goodbye: A Subtle Data Exposure Bug. How a “low severity” simple P4 bug still managed to teach a high-value lesson (and yes… it paid 💰). Beginner …
How I Earned Over $1,000+ from Local Bug Bounty Programs
Hi, my name is Rangga.Continue reading on Medium »
Read more...
Hi, my name is Rangga.Continue reading on Medium »
Read more...
Medium
How I Earned Over $1,000+ from Local Bug Bounty Programs
Hi, my name is Rangga.
The Bugs That Actually Hurt You Aren’t the Fancy Ones
I used to think hacking was about finding something… impressive.Continue reading on Medium »
Read more...
I used to think hacking was about finding something… impressive.Continue reading on Medium »
Read more...
Medium
The Bugs That Actually Hurt You Aren’t the Fancy Ones
I used to think hacking was about finding something… impressive.
JWT & Token Exploitation — Advanced API Attacks (Part 5)
Break authentication, control sessions, and own the APIContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Break authentication, control sessions, and own the APIContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Medium
🔑 JWT & Token Exploitation — Advanced API Attacks (Part 5)
Break authentication, control sessions, and own the API
How I Earned 100 CHF Finding a Real-World Vulnerability
Hi everyone, I found a simple vulnerability through fuzzing.Continue reading on Medium »
Read more...
Hi everyone, I found a simple vulnerability through fuzzing.Continue reading on Medium »
Read more...
Medium
How I Earned 100 CHF Finding a Real-World Vulnerability
Hi everyone, I found a simple vulnerability through fuzzing.
How I Ended Up in the WHO Hall of Fame via Google Dorking
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…Continue reading on Medium »
Read more...
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…Continue reading on Medium »
Read more...
Medium
How I Ended Up in the WHO Hall of Fame via Google Dorking
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…
Copy-Fail (CVE-2026-31431): From Low-Privileged Shell to Root in Seconds
From Foothold to Full Control: Exploiting Copy-Fail (CVE-2026-31431) for Instant Root AccessContinue reading on Medium »
Read more...
From Foothold to Full Control: Exploiting Copy-Fail (CVE-2026-31431) for Instant Root AccessContinue reading on Medium »
Read more...
Medium
🚨 Copy-Fail (CVE-2026-31431): From Low-Privileged Shell to Root in Seconds
From Foothold to Full Control: Exploiting Copy-Fail (CVE-2026-31431) for Instant Root Access
Threat Hunting for Network Based Attacks - LetsDefend [Part 2]
This write-up is based on a training scenario from LetsDefend and is shared for educational purposes only.Continue reading on Medium »
Read more...
This write-up is based on a training scenario from LetsDefend and is shared for educational purposes only.Continue reading on Medium »
Read more...
Medium
Threat Hunting for Network Based Attacks - LetsDefend [Part 2]🔥
This write-up is based on a training scenario from LetsDefend and is shared for educational purposes only.
I Received an Official Bug Bounty Certificate from a Major Payment Platform — Here Is What It Took
Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…Continue reading on Medium »
Read more...
Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…Continue reading on Medium »
Read more...
Medium
I Received an Official Bug Bounty Certificate from a Major Payment Platform — Here Is What It Took
Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…