Open in app

Sign In

Write

Sign In

Lev Shmelev
Lev Shmelev

594 Followers

Home

About

Pinned

$10.000 bounty for exposed .git to RCE

Recently i participated in one of the private bugbounty programs where I managed to find RCE through the open .git directory on four hosts for which I received a record $10,000 and it would be a crime not to share it. …

Bug Bounty

4 min read

$10.000 bounty for exposed .git to RCE
$10.000 bounty for exposed .git to RCE
Bug Bounty

4 min read


May 16

Hardcore RCE in leaked PHP source code for $3.000

This writeup could be considered a continuation of my previous findings for $10,000. Previously, I was able to access the source code through an exposed .git directory where the RCE vulnerability was located. After I explored the vulnerability, I continued to examine the code in search of other vulnerabilities. Luckily…

Bug Bounty

6 min read

Hardcore RCE in leaked PHP source code for $3.000
Hardcore RCE in leaked PHP source code for $3.000
Bug Bounty

6 min read

Lev Shmelev

Lev Shmelev

594 Followers

Cybersecurity consultant | Penetration tester | OSWE | OSWP

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams