Archive 2018
How I was Able To Bypass Email Verification
Hello Masters and Learner I hope you are doing well and always put your efforts to secure the world so that no can get benefits unethically. the main reason why i am writing this …
Hacking a Company Through help desk - Ticket Trick | Bug Bounty POC
This Blog is about how i found & used Ticket Trick issue to Hack a Comapnies Help Center and access other users support tickets
P1 Like a Boss | Information Disclosure via Github leads to Employee Account Takeover | Bug Bounty POC
This Blog is About an issue i found in a site where a .js filke on Github contains a valid Email & Password of an Employee that leads to Help center access.
Privilege Escalation like a Boss
[gist]afe596e6eb02612562216da7b0636661[/gist]
Subdomain Takeover via Unsecured S3 Bucket Connected to the Website
This Blog is about an issue i found in a web where an Unsecured S3 Bucket connected to the website gave way to Takeover teh Subdoamin.
IDOR User Account Takeover By Connecting My Facebook Account with victims Account
Blog about an IDOR issue i found in a web where changing user id in FB auth callback request connects my FB account with victims Web Account
Authentication Bypass Using SQL Injection AutoTrader Webmail - Bug Bounty POC
Simple Short POC about an Issue I discovered in AutoTrader Webmail panel that allows Login Bypass and gave me Webmail Admin Panel Access
ZOL Zimbabwe Authentication Bypass to XSS & SQLi Vulnerability - Bug Bounty POC
This Post is About an issues I found in ZOL Zimbabwe Website that was Authentication bypass follwong with XSS and SQLi and could lead to Database Takeover.
SQL Injection Vulnerability bootcamp.nutanix.com | Bug Bounty POC
SQL Injection Vulnerability that i found inbootcamp.nutanix.com and how i exploited it - Bug Bounty POC Security Breached Blog
RCE Unsecure Jenkins Instance | Bug Bounty POC
RCE in Jenkins Insecure Instance of Dosomething.org and What can an attacker do with an RCE in an Insecure Jenkins Instance.
Edmodo official number for custom text messages to any number around the world!
Hello 1337s, I hope you all are doing good and hunting websites. Today I'm going to tell you about a very interesting finding which was very simple and I never expected that it cou…
IOS 11.4 Siri Auth Bypass | CVE-2018-4238
IOS 11.2.6 IOS 11.4 Siri Authentication | CVE-2018-4238
How I was able to get subscription of $120/year For Free | Bug Bounty POC
How I was able to get subscription of $120/year For Free WeTransfer Bug Bounty How i found The issue in Wetransfer and reported it via Zerocopter
How I found IDOR on Twitter's Acquisition - Mopub.com
Hello everyone, Jay Jani noob here with another noobish finding. As 2k18 has started, I thought to hunt down Twitter for gaining reputation on HackerOne. I tried to find a bug on t…
Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1)
This is my first Blog post and i am starting with IDOR Vulnerability. In this Post you will know about many endpoints to test IDOR vulnerability! Hope you will like it.
How I was able to Bypass XSS Protection on HackerOne's Private Program
Hello friends, This is Jay Jani here and First of all frankly I would like to tell you all that I am completely a noob so I did some noobish things here. Please forgive me for my n…
How I was able to Download Any file from Web server!
I tried to open the file but then I came to know that the file is only downloadable :/ WTF. You can't open it on web server. But I don't give up coz i have an other option that was…
KNOXSS for Dummies! A new Detailed Guide to use KNOXSS Pro in real world
Hello to all my brothers and friends.




