writeups.xyz writeups.xyz / Gal Nagli (@Naglinagli)

Title Vulnerabilities Programs Authors
Subdomain Takeover: How a Misconfigured DNS Record Could Lead to a Huge Supply Chain Attack
Shockwave Identifies Web Cache Deception and Account Takeover Vulnerability affecting OpenAI's ChatGPT
Hacking 6.5+ million websites => CVE-2022-29455 (Elementor)
Exploiting Redash instances with CVE-2021-41192
WordPress Plugin Confusion: How an update can get you pwned
Mass Assignment exploitation in the wild - Escalating privileges in style
Poisoning your Cache for 1000$ - Approach to Exploitation Walkthrough
Broken Access Control on samsung.com subdomain leads to Mass Account Takeover of Samsung employees application accounts
How i could take over any Account on a USA Department of Defense Website due to a simple IDOR