반응형
[2021년 5월 1주] Bug bounty write-ups
#버그바운티 Write-up 모음
Published Date. 2021년 5월 1일
| SSRF Through PDF Generation | Joshua Martinelle (@J0_mart) | SSRF |
| How I found my first RCE? | ipanda (@ipanda915) | RCE |
Published Date. 2021년 5월 2일
| Basic recon to RCE | Joshua Martinelle (@J0_mart) | Insecure deserialization, RCE |
| Chaining CSRF with XSS to deactivate Mass user accounts by single click | Santosh Kumar Sha | CSRF, XSS |
Published Date. 2021년 5월 3일
| Deep Dive into Open Source Bug Bounty | Ritik Sahni (@ritiksahni22) | CSRF |
| Finding known exploits for bugbounties. | ipanda (@ipanda915) | RCE |
Published Date. 2021년 5월 4일
| Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida & Exploiting the Source Engine (Part 1) | Geebz (@Gbps111) | RCE |
Published Date. 2021년 5월 5일
| How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit | - | RCE |
| Account takeover of Instagram accounts due to unrestricted permissions of third-party application’s generated tokens | Samm0uda (@samm0uda) | OAuth flaw, Authorization flaw, Account takeover |
| How I Found Sql Injection on intensedebate.com (h1) in 5 minute $350 | Ahmad A Abdulla (@lu3ky13) | SQL injection |
| XSS Through Parameter Pollution | Saajan Bhujel (@saajanbhujel11) | Open redirect, XSS, HTTP Parameter Pollution |
| Injecting Punycode URL Within the Arbitrary Text via Comment Box In Google Photo Sharing Option | Divyanshu Shukla (@justm0rph3u5) | HTML injection |
Published Date. 2021년 5월 6일
| Identify a Facebook user by his phone number despite privacy settings set | Samm0uda (@samm0uda) | Privacy issue, Information disclosure |
| CVE-2021-1815 – MacOS Local Privilege Escalation Via Preferences | Offensive Security (@offsectraining) | Local Privilege Escalation |
Published Date. 2021년 5월 7일
| Workplace by Facebook | Unauthorized access to companies environment — $27,5k | Marcos Ferreira (@mvinni_) | Authorization flaw, Logic flaw, IDOR |
| Apple Bug bounty writeups XSS(2021) | Takashi Suzuki | XSS |
Published Date. 2021년 5월 8일
| Microsoft bug bounty writeup | th3.d1p4k (@DipakPanchal05) | Information disclosure |
[ 다른 글 더 보러가기 ↓ ]
반응형