writeups.xyz writeups.xyz / Armaan Pathan (@Armaancrockroax)

Title Vulnerabilities Programs Authors
PDFReacter SSRF to ROOT Level Local File Read which led to RCE
Scary Bug in Burp Suite Upstream Proxy Allows Hackers to Hack Hackers
Brute Forcing User IDS via CSRF To Delete all Users with CSRF attack.
Abusing ACL Permissions to Overwrite other User’s Uploaded Files/Videos on s3 Bucket
Chain The Bugs to Pwn an Organisation ( LFI + Unrestricted File Upload = Remote Code Execution )
Chaining Self XSS with UI Redressing is Leading to Session Hijacking (PWN users like a boss)
Bypassing Facebook Profile Picture Guard Security.
Don’t just alert(1) , Because XSS is for fun…!!
Chain the vulnerabilities and take your report impact on the moon (CSRF to HTML INJECTION which results OPEN REDIRECT and could steal USER CREDENTIALS)
Insecure Direct Object Reference In Facebook Events
How i was able to bypass strong xss protection in well known website. (imgur.com)