IDOR on API endpoints.
https://link.medium.com/slMkuL4Yn5
GraphQL — Common vulnerabilities & how to exploit them
https://link.medium.com/nz0Qt5S8p5
XSS WAF & Character limitation bypass like a boss
https://link.medium.com/J37WN7her5
Bypassing CSRF Protection
https://link.medium.com/FUhzdNker5
#bugbounty,#bugbountytips
https://link.medium.com/slMkuL4Yn5
GraphQL — Common vulnerabilities & how to exploit them
https://link.medium.com/nz0Qt5S8p5
XSS WAF & Character limitation bypass like a boss
https://link.medium.com/J37WN7her5
Bypassing CSRF Protection
https://link.medium.com/FUhzdNker5
#bugbounty,#bugbountytips
Medium
IDOR on API endpoints.
Hey guys,
I’m here to share my recent finding on a website which pulls me to pen down my first post. I can not disclose the name of the…
I’m here to share my recent finding on a website which pulls me to pen down my first post. I can not disclose the name of the…
RCE reports
1. https://hackerone.com/reports/591295
2.https://hackerone.com/reports/470520
3.https://hackerone.com/reports/181879
4.https://hackerone.com/reports/351014
5.https://hackerone.com/reports/658013
6.https://hackerone.com/reports/403417
7.https://hackerone.com/reports/631956
1. https://hackerone.com/reports/591295
2.https://hackerone.com/reports/470520
3.https://hackerone.com/reports/181879
4.https://hackerone.com/reports/351014
5.https://hackerone.com/reports/658013
6.https://hackerone.com/reports/403417
7.https://hackerone.com/reports/631956
HackerOne
X / xAI disclosed on HackerOne: Potential pre-auth RCE on Twitter VPN
Thanks Twitter Security Team again :) The details can be found here!
* [Attacking SSL VPN - Part 3: The Golden Pulse Secure SSL VPN RCE Chain, with Twitter as Case...
* [Attacking SSL VPN - Part 3: The Golden Pulse Secure SSL VPN RCE Chain, with Twitter as Case...
#XSS on twitter
https://medium.com/bugbountywriteup/making-an-xss-triggered-by-csp-bypass-on-twitter-561f107be3e5
15.9k views
-
XSS on a big bank's payment gateway
https://medium.com/bugbountywriteup/cross-site-scripting-on-a-big-banks-payment-gateway-a986a2ba5d7
5.7k views
-
why i am banned from hackerone
https://medium.com/@kenanistaken/why-im-banned-from-hackerone-a6d8cffe2286
6.1k views
-
Sop Bypass
https://medium.com/bugbountywriteup/sop-bypass-ecae7f4a5c00
https://medium.com/bugbountywriteup/making-an-xss-triggered-by-csp-bypass-on-twitter-561f107be3e5
15.9k views
-
XSS on a big bank's payment gateway
https://medium.com/bugbountywriteup/cross-site-scripting-on-a-big-banks-payment-gateway-a986a2ba5d7
5.7k views
-
why i am banned from hackerone
https://medium.com/@kenanistaken/why-im-banned-from-hackerone-a6d8cffe2286
6.1k views
-
Sop Bypass
https://medium.com/bugbountywriteup/sop-bypass-ecae7f4a5c00
Medium
Making an XSS triggered by CSP bypass on Twitter.
Hi there,