writeups.xyz
/
Dhakal_bibek (@Dhakal__bibek)
Title
Vulnerabilities
Programs
Authors
“2022: A Year of Fascinating Discoveries”
CSRF
SSRF
Blind XSS
Password Reset
Hyperlink Injection
IDOR
Weak Credentials
AWS Misconfiguration
Undisclosed
Dhakal_bibek (@Dhakal__bibek)
Access control worth $2000 (everyone missed this IDOR+Access control between two admins.)
IDOR
Broken Access Control
Undisclosed
Dhakal_bibek (@Dhakal__bibek)
Story about more than 3.5 million PII leakage in Yahoo!!!
IDOR
Information Disclosure
IOS
Yahoo! / Verizon Media
Dhakal_bibek (@Dhakal__bibek)
Page 1 of 1