SYSTEM ONLINE
Security Research & Bug Bounty Writeups
r29k@bugcrowd:~$ cat writeups/index.md
Valid Bugs 400+
Global Rank 164th
Country Rank #1 PK
CVEs Published 3
Hall of Fames 50+
Writeups
01ATO
Account Takeover
02IDOR
Account Takeover via Chained IDORs
03XSS
Privilege Escalation via Stored XSS
04AWS
From AWS S3 Bucket Misconfiguration to Sensitive Data Exposure
05XSS
Self-XSS to Stored XSS
06ATO
Wayback Machine to Account Takeover
07CVE
CVE-2020-28722 / CVE-2021-36695 / CVE-2021-36696 — Stored XSS in Deskpro
08SSTI
SSTI to Local File Read
09CSRF
CSRF + Open Redirect Chained to Account Takeover
10IDOR
IDOR: Unauthorized Access to Support Tickets