Archive 2020
Using Inspect Element to Bypass Security restrictions | Bug Bounty POC
Hey guys so this blog post is how I was able to Bypass Security restrictions by using inspect element and use Paid Features.
Playing with JSON Web Tokens for Fun and Profit
JSON Web Token (JWT) is an open standard (RFC 7519) that defines a compact and self-contained way for securely transmitting information between parties.
Microsoft Apache Solr RCE Velocity Template | Bug Bounty POC
Hey guys so this blog post is about RCE issue reported to Microsoft bug bounty program, Remote Code execution issue existed in microsoft.com subdomain running Apache Solr.
Getting Started in Android Apps Pen-testing (Part-1)
Pen-testing android apps require different methodologies than web applications. The difference is that you have to figure out by different methods.
Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC
This blog post is about static analysis of Android App & due to insecure storage of SMS API credentials I was able to Takeover the SMS API.
Exploiting Insecure Firebase Database!
this blog post is about Exploiting Insecure Firebase Databases, due to Improper set security rules one can write data to the database in certain conditions here’s a Short POC tutor…
Improper Input Validation | Add Custom Text and URLs In SMS send by Snapchat | Bug Bounty POC
Hey guys so this blog post is about an Issue in Snapchat's Website, due to Improper Input Validation one can add custom text & urls in SMS send by Snapchat here's a Short POC of th…
User Account Takeover via Signup Feature | Bug Bounty POC
This blog is about an Account Takeover issue i found in a web app where creating a new account on already existing email will give access to users account,







