writeups.xyz writeups.xyz / Aidil Arief

Title Vulnerabilities Programs Authors
How do I Bypass Payment when a Subscription ends so I don’t have to pay for my subscription
Bypassing SSO Authentication from the Login Without Password Feature Lead to Account Takeover
Stored XSS at https://www.tiktok.com/ the name of the attacker’s account carrying XSS payload will be triggered when the victim Send Video
XSS Blind Stored at 2 Assets TikTok
XSS Blind Stored at Asset Domain Android Apps TikTok
First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft
IDOR Vulnerability In GraphQL Api On Website
($380) XSS STORED in Bigo Bug Bounty Program