반응형
[2021년 5월 1주] Bug bounty write-ups
#버그바운티 Write-up 모음
Published Date. 2021년 5월 1일
SSRF Through PDF Generation | Joshua Martinelle (@J0_mart) | SSRF |
How I found my first RCE? | ipanda (@ipanda915) | RCE |
Published Date. 2021년 5월 2일
Basic recon to RCE | Joshua Martinelle (@J0_mart) | Insecure deserialization, RCE |
Chaining CSRF with XSS to deactivate Mass user accounts by single click | Santosh Kumar Sha | CSRF, XSS |
Published Date. 2021년 5월 3일
Deep Dive into Open Source Bug Bounty | Ritik Sahni (@ritiksahni22) | CSRF |
Finding known exploits for bugbounties. | ipanda (@ipanda915) | RCE |
Published Date. 2021년 5월 4일
Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida & Exploiting the Source Engine (Part 1) | Geebz (@Gbps111) | RCE |
Published Date. 2021년 5월 5일
How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit | - | RCE |
Account takeover of Instagram accounts due to unrestricted permissions of third-party application’s generated tokens | Samm0uda (@samm0uda) | OAuth flaw, Authorization flaw, Account takeover |
How I Found Sql Injection on intensedebate.com (h1) in 5 minute $350 | Ahmad A Abdulla (@lu3ky13) | SQL injection |
XSS Through Parameter Pollution | Saajan Bhujel (@saajanbhujel11) | Open redirect, XSS, HTTP Parameter Pollution |
Injecting Punycode URL Within the Arbitrary Text via Comment Box In Google Photo Sharing Option | Divyanshu Shukla (@justm0rph3u5) | HTML injection |
Published Date. 2021년 5월 6일
Identify a Facebook user by his phone number despite privacy settings set | Samm0uda (@samm0uda) | Privacy issue, Information disclosure |
CVE-2021-1815 – MacOS Local Privilege Escalation Via Preferences | Offensive Security (@offsectraining) | Local Privilege Escalation |
Published Date. 2021년 5월 7일
Workplace by Facebook | Unauthorized access to companies environment — $27,5k | Marcos Ferreira (@mvinni_) | Authorization flaw, Logic flaw, IDOR |
Apple Bug bounty writeups XSS(2021) | Takashi Suzuki | XSS |
Published Date. 2021년 5월 8일
Microsoft bug bounty writeup | th3.d1p4k (@DipakPanchal05) | Information disclosure |
[ 다른 글 더 보러가기 ↓ ]
반응형