writeups.xyz writeups.xyz / Harsh Bothra (@Harshbothra_)

Title Vulnerabilities Programs Authors
4,500 of the Top 1 Million Websites Leaked Source Code, Secrets
Evading Filters to perform the Arbitrary URL Redirection Attack
Accidental Observation to Critical IDOR
Misconfigured S3 Bucket Access Controls to Critical Vulnerability
Let’s Bypass CSRF Protection & Password Confirmation to Takeover Victim Accounts :D
XSS to Database Credential Leakage & Database Access — Story of total luck!
Weak Cryptography in Password Reset to Full Account Takeover
Recon to Sensitive Information Disclosure in Minutes
From Recon to P1 (Critical) — An Easy Win