#연구/#Hacking

[2021년 5월 1주] Bug bounty write-ups #버그바운티 Write-up 모음

every7hing 2021. 5. 14. 17:09
반응형

 

[2021년 5월 1주] Bug bounty write-ups 

#버그바운티  Write-up 모음 

 

Published Date. 2021년 5월 1일

SSRF Through PDF Generation Joshua Martinelle (@J0_mart) SSRF
How I found my first RCE? ipanda (@ipanda915) RCE

 

Published Date. 2021년 5월 2일

Basic recon to RCE Joshua Martinelle (@J0_mart) Insecure deserialization, RCE
Chaining CSRF with XSS to deactivate Mass user accounts by single click Santosh Kumar Sha CSRF, XSS

 

Published Date. 2021년 5월 3일

Deep Dive into Open Source Bug Bounty Ritik Sahni (@ritiksahni22) CSRF
Finding known exploits for bugbounties. ipanda (@ipanda915) RCE

 

Published Date. 2021년 5월 4일

Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida & Exploiting the Source Engine (Part 1) Geebz (@Gbps111) RCE

 

Published Date. 2021년 5월 5일

How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit - RCE
Account takeover of Instagram accounts due to unrestricted permissions of third-party application’s generated tokens Samm0uda (@samm0uda) OAuth flaw, Authorization flaw, Account takeover
How I Found Sql Injection on intensedebate.com (h1) in 5 minute $350 Ahmad A Abdulla (@lu3ky13) SQL injection
XSS Through Parameter Pollution Saajan Bhujel (@saajanbhujel11) Open redirect, XSS, HTTP Parameter Pollution
Injecting Punycode URL Within the Arbitrary Text via Comment Box In Google Photo Sharing Option Divyanshu Shukla (@justm0rph3u5) HTML injection

 

Published Date. 2021년 5월 6일

Identify a Facebook user by his phone number despite privacy settings set Samm0uda (@samm0uda) Privacy issue, Information disclosure
CVE-2021-1815 – MacOS Local Privilege Escalation Via Preferences Offensive Security (@offsectraining) Local Privilege Escalation

 

Published Date. 2021년 5월 7일

Workplace by Facebook | Unauthorized access to companies environment — $27,5k Marcos Ferreira (@mvinni_) Authorization flaw, Logic flaw, IDOR
Apple Bug bounty writeups XSS(2021) Takashi Suzuki XSS

 

Published Date. 2021년 5월 8일

Microsoft bug bounty writeup th3.d1p4k (@DipakPanchal05) Information disclosure

 

[ 다른 글 더 보러가기 ↓ ]

반응형