writeups.xyz writeups.xyz / Santosh Kumar Sha (@Killmongar1996)

Title Vulnerabilities Programs Authors
How I got access to Essilor International company customer PII INFO by AWS metadata access through SSRF
How I found reflected XSS on IDFC Bank with burp-suite Intruder
Out-Of-Bond Remote code Execution(RCE) on De Nederlandsche Bank N.V. with burp-suite collaborator
Automating reflected XSS with burp-suite Intruder
Exploiting S3 bucket with path folder to Access PII info of A BANK
Finding multiple SSRF with aws metadata access on A BANK system
How I was able Find mass leaked AWS s3 bucket from js File
How Github recon help me to find NINE FULL SSRF Vulnerability with AWS metadata access
Escalating SSRF to Accessing all user PII information by aws metadata
Unauthorized access to Django Admin Dashboard by endpoint leaked on GitHub
Chaining CSRF with XSS to deactivate Mass user accounts by single click
AWS internal metadata accessed through SSRF by Chaining an Open Redirect bug
Unauthorized access to admin setpassword page BY bypassing 403 Forbidden
Chaining an Blind SSRF bug to Get an RCE
Finding Basic Authtoken in JAVASCRIPT file BY Full Automation
Android apk leaks access token to takeover the whole infrastructure
Finding SSRF BY Full Automation
Chaining CORS by Reflected xss to Account takeover #My first Blog