writeups.xyz writeups.xyz

InfoSec and Bug Bounty Writeups Directory.

This Website is a collection of Information Security and Bug Bounty writeups that allows you to easily filter writeups by vulnerabilities, programs, authors, and more, making your research and exploration of security issues simpler and more efficient.

Important Note: Please remember that the inclusion of a program or target in this directory does not imply permission to conduct any hacking activities. Always review and adhere to the specific policies of each program before taking any action.

Title Vulnerabilities Programs Authors
How I Got $250 For My Second Bug on HackerOne
IIS welcome page to source code review to LFI!
The Hunt for XXE to LFI: How I Uncovered CVE-2019–9670 in a Bug Bounty Program
4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection In WhatsUp Gold - CVE-2024-6670
Key and E: A Pentester’s Tale on How a Photo Opened Real Doors
Analysis of CVE-2024-43044 — From file read to RCE in Jenkins through agents
Bypassing airport security via SQL injection
$15k RCE Through Monitoring Debug Mode
3CX Phone System Local Privilege Escalation Vulnerability
CSRF Bypass Using Domain Confusion Leads To ATO
CVE-2024-37079:
[$500] How I was able to give verification badge to any YouTube channel and bypass needed requirements
Back To School - Exploiting A Remote Code Execution Vulnerability In Moodle
“Like” Bypass on Customer Reviews — €500 bounty
Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information
WordPress GiveWP POP to RCE (CVE-2024-5932)
Hitting the jackpot with RCE!
How I got $24000 Bounty from a Log4j RCE in Apple App Store.
How I Got Bugs From Google Dorks
Hidden in Plain Sight: Uncovering RCE on a Forgotten Axis2 Instance
How I can easily get four P1 at NASA using Simple Google Dorking.
NTLM Credential Theft in Python Windows Applications
Traccar 5 Remote Code Execution Vulnerabilities
Instagram and Meta 2FA Bypass by Unprotected Backup Code Retrieval in Accounts Center