0xspade icon

Write Ups Unfinished

0xspade | PRO | 09/07/19 04:30:56 AM UTC | 0 ⭐ | 520 👁️ | Never ⏰ | []
text |

2.44 KB

|

None

|

0 👍

/

0 👎

WRITE UPS
https://github.com/ngalongc/bug-bounty-reference
 --XSS--
https://blog.innerht.ml/rpo-gadgets/
https://web.archive.org/web/20190407100133/https://whitton.io/articles/uber-turning-self-xss-into-good-xss/
https://web.archive.org/web/20170831053844/https://blog.bugcrowd.com/guest-blog-using-a-braun-shaver-to-bypass-xss-audit-and-waf-by-frans-rosen-detectify
https://web.archive.org/web/20171108050241/https://whitton.io/articles/xss-on-facebook-via-png-content-types/
https://web.archive.org/web/20171108050241/https://whitton.io/articles/xss-on-facebook-via-png-content-types/
https://www.pranav-venkat.com/2016/03/command-injection-which-got-me-6000.html
https://web.archive.org/web/20180307025611/https://www.paulosyibelo.com/2015/12/facebooks-moves-oauth-xss.html
https://klikki.fi/adv/yahoo.html
https://mksben.l0.cm/2016/07/xxn-caret.html
https://labs.detectify.com/2015/06/06/google-xss-turkey/
https://labs.detectify.com/2016/10/24/combining-host-header-injection-and-lax-host-parsing-serving-malicious-data/
https://blog.it-securityguard.com/bugbounty-decoding-a-%F0%9F%98%B1-00000-htpasswd-bounty/
http://www.geekboy.ninja/blog/airbnb-bug-bounty-turning-self-xss-into-good-xss-2/
https://buer.haus/2017/03/08/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-vulnerabilities/
https://hackerone.com/reports/262230
https://blog.blackfan.ru/2017/09/devtwittercom-xss.html
https://web.archive.org/web/20180602160116/http://stamone-bug-bounty.blogspot.com/2017/10/dom-xss-auth_14.html
https://ysx.me.uk/app-maker-and-colaboratory-a-stored-google-xss-double-bill/
https://www.youtube.com/watch?v=d9UEVv3cJ0Q&feature=youtu.be
  --BRUTE FORCE--
https://hackerone.com/reports/127844
https://zseano.com/tutorials/3.html
 --SQL INJECTION--
https://hackerone.com/reports/150156
https://hackerone.com/reports/135288
https://buer.haus/2015/01/15/yahoo-root-access-sql-injection-tw-yahoo-com/
 --STEALING ACCESS TOKEN--
https://hackerone.com/reports/108113
https://hackerone.com/reports/143717
https://blog.innerht.ml/internet-explorer-has-a-url-problem/
http://blog.intothesymmetry.com/2016/11/all-your-paypal-tokens-belong-to-me.html?m=1
https://nbsriharsha.blogspot.com/2016/04/oauth-20-redirection-bypass-cheat-sheet.html
https://medium.com/@lokeshdlk77/bypass-oauth-nonce-and-steal-oculus-response-code-faa9cc8d0d37
  --RCE--
https://nahamsec.com/secure-your-jenkins-instance-or-hackers-will-force-you-to/

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎