Bug Bounty
@Bug0x
5.5K
subscribers
14
photos
134
links
@HackerOne
Admin :
@Offensive
Download Telegram
Join
Bug Bounty
5.5K subscribers
Bug Bounty
Channel created
Bug Bounty
https://hackerone.com/reports/303061
@BugBounty
Bug Bounty
https://hackerone.com/reports/314518
@BugBounty
HackerOne
LocalTapiola disclosed on HackerOne: Reflected XSS+CSRF on...
##Issue
The reporter was able to misuse a couple of flaws in the system. By using a reflected XSS (due to missing validation) combined with a CSRF the reporter could create open redirects (via...
Bug Bounty
https://hackerone.com/reports/318751
HackerOne
Shopify disclosed on HackerOne: Access to Private Photos of Apps in...
@vijay_kumar1110 reported an Insecure Direct Object Reference vulnerability on our Exchange app. This issue could have allowed an attacker to iterate over the shops' screenshot IDs in order to...
Bug Bounty
https://hackerone.com/reports/300748
HackerOne
Coinbase disclosed on HackerOne: Ethereum account balance manipulation
The researchers noticed an issue with our ETH receiving code when receiving from a contract. This allowed sending of ETH to Coinbase to be credited even if the underlying contract execution failed....
Bug Bounty
https://hackerone.com/reports/311639
HackerOne
Eternal disclosed on HackerOne: Reflected XSS on...
Hello,
I found an XSS issue due to the incorrect handling of the \ character in a <noscript> context, the following link works as a PoC that alerts the location of the...
Bug Bounty
https://hackerone.com/reports/312647
HackerOne
Discourse disclosed on HackerOne: Gaining access to private topics...
## Denoscription
Some topics have limited access to certain groups and users, and while there exists a validation for access on this topic, it can be bypassed by abusing a vulnerability in the...
Bug Bounty
https://hackerone.com/reports/312543
HackerOne
Semrush disclosed on HackerOne: XXE in Site Audit function exposing...
**Summary:**
The Project Site Audit function is vulnerable to XXE when parsing sitemap.xml files.
**Denoscription:**
The Site Audit function spiders a given website and performs analysis on the...
Bug Bounty
https://github.com/sneakerhax/Runbooks?files=1
GitHub
TTPs/ at main · sneakerhax/TTPs
Tactics, Techniques, and Procedures. Contribute to sneakerhax/TTPs development by creating an account on GitHub.
Bug Bounty
https://www.incapsula.com/blog/blocking-session-hijacking-on-gitlab.html
Blog
Discovering a Session Hijacking Vulnerability in GitLab | Imperva
We found a session hijacking vulnerability in the GitLab platform. In this post we describe the vulnerability, the patching process and protection methods.
Bug Bounty
Forwarded from
HackerOne
(
Amir Offensive
)
https://www.youtube.com/watch?v=GnoJJJHegqY
YouTube
nxp.com session hijacking poc by rohit Dalvi Hacker101
Nothing Got Waste Of Time
site :- https://www.nxp.com/
Bug Bounty
https://www.youtube.com/watch?v=GPGLid3RyPc
YouTube
Broken Authorization and CSRF In Paypal lead to account takeover
Using broken authorisation with couple of Cross Site Request Forgeries (CSRFs) to completely take over users’ accounts.
Bug Bounty
http://zhchbin.github.io/2017/08/30/Uber-XSS-via-Cookie/
zhchbin
[BBP系列二] Uber XSS via Cookie
This write up is about part of my latest XSS report to Uber@hackerone. Sorry for my poor English first of all, I will try my best to explain this XSS problem throughly. JSONP RequestSeveral months ago
Bug Bounty
https://hackerone.com/reports/341876
HackerOne
Shopify disclosed on HackerOne: SSRF in Exchange leads to ROOT...
Shopify infrastructure is isolated into subsets of infrastructure. @0xacb reported it was possible to gain root access to any container in one particular subset by exploiting a server side request...
TWeb.init({scrollToPost:'Bug0x/21'});