writeups.xyz writeups.xyz / Jack Whitton (@Fin1te)

Title Vulnerabilities Programs Authors
Messenger.com Site-Wide CSRF
Obtaining Login Tokens for an Outlook, Office or Azure Account
Uber Bug Bounty: Turning Self-XSS into Good-XSS
An XSS on Facebook via PNGs & Wonky Content Types
Bypassing Google Authentication on Periscope's Administration Panel
Abusing CORS for an XSS on Flickr
Instagram's One-Click Privacy Switch
Content Types and XSS: Facebook Studio
Removing Covers Images on Friendship Pages, on Facebook
Hijacking a Facebook Account with SMS
Overwriting Banner Images on Etsy
Stealing Facebook Access Tokens with a Double Submit
Framing, Part 1: Click-Jacking Etsy
Persistent XSS on myworld.ebay.com
My Experience with the PayPal Bug Bounty Programme