From Accessing Restricted Functionality via URL Found in .js File, to...
The Story of How Allah Allowed Us to Obtain Super Admin Access Through a Chain of Vulnerabilities (Including the Use of a Data Leak Monitoring Platform). In the name of Allah, the Most Gracious, the...
View ArticleThe Unexpected “0” Master ID for Account Data Manipulation
A simple story when Allah allowed me to successfully achieve P1 through a broken access control issue using an unexpected master ID of “0”. In the name of Allah, the Most Gracious, the Most Merciful....
View ArticleFrom Recon via Censys and DNSdumpster, to Getting P1 by Login Using Weak...
A simple story when Allah allowed me to get P1 by combining several issues, one of which was related to “weak credentials”. In the name of Allah, the Most Gracious, the Most Merciful. As usual, I will...
View ArticleOptimizing Hunting Results in VDP for use in Bug Bounty Programs - From...
A story when Allah willed me to tried to optimize my findings in the Points-Only program to be able to get 6 paid P1 issues in the bounty program. In the name of Allah, the Most Gracious, the Most...
View ArticleFrom Recon to Bypassing MFA Implementation in OWA by Using EWS Misconfiguration
A story about how I Finally could use an AD account that unenrolled to MFA, by using an EWS Misconfiguration to Access Email Inbox and (Having the Ability) to Dump the Global Address List. In the name...
View ArticleFrom 3,99 to 1,650 USD (Part I) – Simple Vertical Privilege Escalation by...
A story about how I got several simple bugs (1 P2, 1 P3, and 2 P4s) on a target (that just allow Specific Country Code to Register) by using Premium Phone Number. In the name of Allah, the Most...
View ArticleFrom Recon to Optimizing RCE Results – Simple Story with One of the Biggest...
How I Finally could Got into an Internal Network (and could accessing all of their internal assets) at One of the Biggest ICT company in the World – by Using Various Vulnerabilities. In the name of...
View ArticleOppo – Reflected XSS at Activation Link via Base64 Value
In the name of Allah, the Most Gracious, the Most Merciful. Description: an Reflected XSS issue at Activation Link that could be triggered via Base64 Encoding. PoC Video:
View ArticleOppo – Open URL Redirection at Activation Link via Base64
In the name of Allah, the Most Gracious, the Most Merciful. Description: an Open URL Redirection issue at Activation Link that could be triggered via Base64 Encoding. PoC Video:
View ArticleRace Condition that could Result to RCE – (A story with an App that temporary...
In the name of Allah, the Most Gracious, the Most Merciful. – Part I from (hopefully) IV Parts – Update I: Added a “Reference” Section.Update II: “We” at this series of article will refer to Faisal...
View ArticleIDOR (at Private Bug Bounty Program) that could Leads to Personal Data Leaks
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release in simple:[English Version] IDOR (at Private Bug Bounty Program) that...
View ArticleRibose – IDOR with Simple CSRF Bypass – Unrestricted Changes and Deletion to...
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release in simple:[English Version] Ribose — IDOR with Simple CSRF Bypass —...
View ArticleBypassing the Current Password Protection at PayPal Tech-Support
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release (December, 2017 Article):[English Version] PayPal — Bypassing the...
View ArticleInformation Disclosure at PayPal and Xoom (PayPal Acquisition) via Simple...
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release:[English Version] PayPal – Information Disclosure at PayPal and Xoom...
View ArticleTurning Self-XSS into non-Self Stored-XSS via Authorization Issue at “PayPal...
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release:[English Version] PayPal — Turning Self-XSS into non-Self Stored-XSS...
View ArticleFortiNet – Unrestricted Deletion to All Other Sub Account via IDOR at Support...
In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release in simple:[English Version] FortiNet – Unrestricted Deletion to other...
View ArticleTokopedia – Converting Content Injection to Reflected Cross Site Scripting...
In the name of Allah, the Most Gracious, the Most Merciful. I. ABSTRACT Provision of information for activating a new-registered account is one of the features that could be seen by the user (in...
View ArticleRace Condition that could Result to RCE – (A story with an App that temporary...
RCE Result from Race Condition In the name of Allah, the Most Gracious, the Most Merciful. I. INTRODUCTION 1.1. Few Words about this Write-Up As an information, this simple write-up talks about a...
View ArticleIDOR (at Private Bug Bounty Program) that could Leads to Personal Data Leaks
IDOR Response In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release in simple: [English Version] IDOR (at Private Bug...
View ArticleRibose – IDOR with Simple CSRF Bypass – Unrestricted Changes and Deletion to...
Team Ribose’s Connections (Friend List) In the name of Allah, the Most Gracious, the Most Merciful. Please kindly visit this simple paper directly to looking this release in simple: [English Version]...
View Article