writeups.xyz writeups.xyz / Matthew Bryant (@IAmMandatory)

Title Vulnerabilities Programs Authors
"Zero-Days" Without Incident - Compromising Angular via Expired npm Publisher Email Domains
Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper
Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)
The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability in AWS, Google Cloud, Rackspace and Digital Ocean
Floating Domains – Taking Over 20K DigitalOcean Domains via a Lax Domain Import System
Poisoning the Well – Compromising GoDaddy Customer Support With Blind XSS
ebay bug bounty