PinnedPublished inInfoSec Write-ups1500$: CR/LF InjectionMar 23, 2024A response icon9Mar 23, 2024A response icon9
Email Disclosure via .git Config in project: $500 Bounty BugI’m excited to share a vulnerability I recently discovered a sensitive information disclosure vulnerability in ExaHub that exposed project…Mar 7A response icon2Mar 7A response icon2
Published inInfoSec Write-ups$1,700 IDOR: Unauthorized Modification of Web Hosting ConfigurationHi Everyone! I recently discovered an IDOR (Insecure Direct Object Reference) vulnerability in ExHub that allowed an attacker to modify the…Feb 14A response icon2Feb 14A response icon2
$500 Bounty: Unlocking Premium Job Features with a Simple API Trick!Hi Everyone, I’m excited to share a vulnerability I recently discovered in ExHub (a pseudonym for a private bug bounty program). This flaw…Feb 8A response icon4Feb 8A response icon4
Published inInfoSec Write-upsHow to choose the Correct Severity or CVSS Score for a Bug: A Practical GuideOct 4, 2024Oct 4, 2024
Published inInfoSec Write-upsPlan Ristriction Bypass for Slack Integration: 500$ Improper Validation Check BugSep 28, 2024A response icon1Sep 28, 2024A response icon1
Published inInfoSec Write-ups500$: Open Redirect VulnerabilitySep 21, 2024A response icon2Sep 21, 2024A response icon2
Published inInfoSec Write-upsHow to Write an Effective Bug Bounty Report: Tips, Structure, and ExamplesIn the bug bounty world, the quality of your report can make or break your submission. The finding a bug is the first step but writing a…Sep 13, 2024A response icon3Sep 13, 2024A response icon3
Published inInfoSec Write-ups850$ IDOR:Unauthorized Session Revokation of any userSep 7, 2024A response icon2Sep 7, 2024A response icon2