writeups.xyz writeups.xyz / Abdullah Hussam (@Abdulahhusam)

Title Vulnerabilities Programs Authors
Take Advantage of Out-of-Scope Domains in Bug Bounty Programs
Leaking WordPress CSRF Tokens for Fun, $1337 bounty, and CVE-2017-5489
Leaking Amazon.com CSRF Tokens Using Service Worker API
Medium Content Spoofing Leads to XSS
Leak Private Videos [Vimeo Bug Bounty]
Vine Re-auth Bypass [Twitter Bug Bounty]
Medium Full Account Takeover By One Click
How I Hacked [Oculus] OAuth +Ebay +IBM
Cloudflare WAF XSS
One Payload to XSS Them All!
Blind SQL Inejction [Hootsuite]
Flickr XSRF to Change Photo Details