writeups.xyz writeups.xyz / Can1337 (@Canmustdie)

Title Vulnerabilities Programs Authors
Bypassing email verification of high-profile tech company ($$$)
Bypass Apple’s redirection process with the dot (“.”) character
Break the Logic: 5 Different Perspectives in Single Page (€1500)
Break the Logic: Insecure Parameters (€300)
Multiple bugs in one program leads to 1500€
I mean, IDOR is NOT only about others ID
How Did I Leak 5.2k Customer Data From a Large Company? (via Broken Access Control)
SONY Hunting I: Discovering Hidden Parameters (5x SWAG)
What is BOLA? 3-digit bounty from Topcoder ($$$)
Reflected Cross Site Scripting on REDACTED Program (Bounty: 750$)