writeups.xyz writeups.xyz

InfoSec and Bug Bounty Writeups Directory.

This Website is a collection of Information Security and Bug Bounty writeups that allows you to easily filter writeups by vulnerabilities, programs, authors, and more, making your research and exploration of security issues simpler and more efficient.

Important Note: Please remember that the inclusion of a program or target in this directory does not imply permission to conduct any hacking activities. Always review and adhere to the specific policies of each program before taking any action.

Title Vulnerabilities Programs Authors
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
Data Theft in Salesforce: Manipulating Public Links
Attacking PowerShell CLIXML Deserialization
Escalating From Reader To Contributor In Azure API Management
Logic Flaw: I Can Block You from Accessing Your Own Account
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
Interesting Story of an Account Takeover Vulnerability
Microsoft Windows MSI Installer - Repair to SYSTEM - A detailed journey
We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
Directory Traversal, SQL Injection and Server-Side Request Forgery
Getting code execution on Veeam through CVE-2023-27532
Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Self-XSS to ATO via Site Features
How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack
SSTI in Bug Bounty Program: The Time I Played with Handlebars and Broke Stuff
Unmasking Harmful Content in a Medical Chatbot: A Red Team Perspective
Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk
Spip Preauth RCE 2024: Part 2, A Big Upload
Zomatoooo! IDOR in Saved Payments
P3 (Medium) : How I Gain Access To NASA's Internal Workspace?!
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
Ghost In The Ppl Part 1: Byovdll
A Story About How I Found XSS in ASUS
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN