Category: bugbounty-poc
From Staging to Full Admin Control In Prod: A Breakdown of Critical Authentication Flaws
In this blog, I explore a real-world case of an Admin Panel Takeover caused by broken authentication and insecure configurations. By exploiting a misconfigured JWT token from a sta…
AI Hijack: How I Took Control of an AI Assistant
A simple API key leak led to the complete takeover of an AI assistant in production. Allowing to change AI's Instructions.
Finding Hidden Threats: How I Found Leaked AWS Credentials in an Android App API Using DAST
Found a critical vulnerability involving leaked AWS credentials within an Android App API during a bug bounty hunt. by utilizing Dynamic Application Security Testing (DAST) and the…
How I Manipulated My Rank on the Bugcrowd Platform
In recent years, Bug Bounties have gained significant popularity as a growing number of companies rely on crowdsourcing platforms to identify vulnerabilities within their systems. …
Hacking 100k+ Loyalty Programs for Fun and Profit!
This blog post is about how a hacker could have Hacked 100k+ Loyalty Programs to get free points & redeem them for free stuff or coupons.
Hacking Subscription Plans for free service.
The blog post describes how I was able to bypass subscription plans to get access to paid services for free.
Using Inspect Element to Bypass Security restrictions | Bug Bounty POC
Hey guys so this blog post is how I was able to Bypass Security restrictions by using inspect element and use Paid Features.
Playing with JSON Web Tokens for Fun and Profit
JSON Web Token (JWT) is an open standard (RFC 7519) that defines a compact and self-contained way for securely transmitting information between parties.
Microsoft Apache Solr RCE Velocity Template | Bug Bounty POC
Hey guys so this blog post is about RCE issue reported to Microsoft bug bounty program, Remote Code execution issue existed in microsoft.com subdomain running Apache Solr.
Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC
This blog post is about static analysis of Android App & due to insecure storage of SMS API credentials I was able to Takeover the SMS API.
Exploiting Insecure Firebase Database!
this blog post is about Exploiting Insecure Firebase Databases, due to Improper set security rules one can write data to the database in certain conditions here’s a Short POC tutor…
Improper Input Validation | Add Custom Text and URLs In SMS send by Snapchat | Bug Bounty POC
Hey guys so this blog post is about an Issue in Snapchat's Website, due to Improper Input Validation one can add custom text & urls in SMS send by Snapchat here's a Short POC of th…
User Account Takeover via Signup Feature | Bug Bounty POC
This blog is about an Account Takeover issue i found in a web app where creating a new account on already existing email will give access to users account,
Hacking a Company Through help desk - Ticket Trick | Bug Bounty POC
This Blog is about how i found & used Ticket Trick issue to Hack a Comapnies Help Center and access other users support tickets
P1 Like a Boss | Information Disclosure via Github leads to Employee Account Takeover | Bug Bounty POC
This Blog is About an issue i found in a site where a .js filke on Github contains a valid Email & Password of an Employee that leads to Help center access.
Subdomain Takeover via Unsecured S3 Bucket Connected to the Website
This Blog is about an issue i found in a web where an Unsecured S3 Bucket connected to the website gave way to Takeover teh Subdoamin.
IDOR User Account Takeover By Connecting My Facebook Account with victims Account
Blog about an IDOR issue i found in a web where changing user id in FB auth callback request connects my FB account with victims Web Account
Authentication Bypass Using SQL Injection AutoTrader Webmail - Bug Bounty POC
Simple Short POC about an Issue I discovered in AutoTrader Webmail panel that allows Login Bypass and gave me Webmail Admin Panel Access
ZOL Zimbabwe Authentication Bypass to XSS & SQLi Vulnerability - Bug Bounty POC
This Post is About an issues I found in ZOL Zimbabwe Website that was Authentication bypass follwong with XSS and SQLi and could lead to Database Takeover.
SQL Injection Vulnerability bootcamp.nutanix.com | Bug Bounty POC
SQL Injection Vulnerability that i found inbootcamp.nutanix.com and how i exploited it - Bug Bounty POC Security Breached Blog
RCE Unsecure Jenkins Instance | Bug Bounty POC
RCE in Jenkins Insecure Instance of Dosomething.org and What can an attacker do with an RCE in an Insecure Jenkins Instance.
Edmodo official number for custom text messages to any number around the world!
Hello 1337s, I hope you all are doing good and hunting websites. Today I'm going to tell you about a very interesting finding which was very simple and I never expected that it cou…
IOS 11.4 Siri Auth Bypass | CVE-2018-4238
IOS 11.2.6 IOS 11.4 Siri Authentication | CVE-2018-4238
How I was able to get subscription of $120/year For Free | Bug Bounty POC
How I was able to get subscription of $120/year For Free WeTransfer Bug Bounty How i found The issue in Wetransfer and reported it via Zerocopter
Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1)
This is my first Blog post and i am starting with IDOR Vulnerability. In this Post you will know about many endpoints to test IDOR vulnerability! Hope you will like it.
How I was able to Download Any file from Web server!
I tried to open the file but then I came to know that the file is only downloadable :/ WTF. You can't open it on web server. But I don't give up coz i have an other option that was…
KNOXSS for Dummies! A new Detailed Guide to use KNOXSS Pro in real world
Hello to all my brothers and friends.
Unrestricted File Upload to RCE | Bug Bounty POC
How I bypassed image upload functionality on a project to gain RCE,
HOW I WAS ABLE TO TAKEOVER FACEBOOK ACCOUNT | Bug Bounty Poc
hey all here is ameer hamza, Facebook has recently introduced login with phone functionality if you have forgotten your password. however I was able to exploit it which leads to a…
UBER Wildcard Subdomain Takeover | BugBounty POC
one of ubers domain was vulnerable to Wildcard subdomain takeover, Basically as heroku wildcard is Opened and i can register any subdomain & takeover it.
Accessing Localhost via Vhost | VIRTUAL HOST ENUMERATION | BugBounty POC
The Blog post is about what are Virtual Host, how U can Enumerate them and get access to the vulnerable system, including POC of resent BugBounty Report.
Exploiting Insecure Cross Origin Resource Sharing ( CORS ) | api.artsy.net
How to find & Exploit Insecure Cross Origin Resource Sharing ( CORS ), inspired by geekboy & I successfully exploit the issue in a Bug Bounty program
Bugcrowd’s Domain & Subdomain Takeover vulnerability!
Bugcrowd's Domain & Subdomain takeover vulnerability Due to Expired/Misconfigured Fastly & Pantheon Services.. A small writeup about how i did it?
Subdomain Takeover Through Expired Cloudfront Distribution | live.lamborghini.com
I found an Expired Cloudfront distribution on one of the lamborghini.com Subdomains! The Post explains how easy it is to takeover a subdomain!
SQLi & XSS Vulnerabilities in a Popular Airlines Website!
SQL injection & XSS vulnerabilities in a popular Airlines Websites That can cause complete compromisation of the database and System! Here are the details


















