writeups.xyz writeups.xyz

InfoSec and Bug Bounty Writeups Directory.

This Website is a collection of Information Security and Bug Bounty writeups that allows you to easily filter writeups by vulnerabilities, programs, authors, and more, making your research and exploration of security issues simpler and more efficient.

Important Note: Please remember that the inclusion of a program or target in this directory does not imply permission to conduct any hacking activities. Always review and adhere to the specific policies of each program before taking any action.

Title Vulnerabilities Programs Authors
Vulnerabilities in Homepage Dashboard
Authorization bypass due to cache misconfiguration
Google AI Studio: LLM-Powered Data Exfiltration Hits Again! Quickly Fixed.
WPML Multilingual CMS Authenticated Contributor+ Remote Code Execution (RCE) via Twig Server-Side Template Injection (SSTI)
From MLOps to MLOops: Exposing the Attack Surface of Machine Learning Platforms
SSRFing the Web with the help of Copilot Studio
The Hunt for ALBeast: A Technical Walkthrough
$4,998 Bounty Awarded and 100,000 WordPress Sites Protected Against Unauthenticated Remote Code Execution Vulnerability Patched in GiveWP WordPress Plugin
How 1 Exposed Honeywell API Gave us Control Over an Internal Engineering System
World of SELECT-only PostgreSQL Injections: (Ab)using the filesystem
$1600 Bounty on a Main Domain
Another 1500$: CR/LF Injection
500$ From Meta by reporting a HTMLi(Accidental Bug)
Forced SSO Session Fixation
Spip Preauth RCE 2024: Part 1, The Feather
2FA Bypass - IDN Mischief
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CVE-2024-38213: Copy2pwn Exploit Evades Windows Web Protections
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
Oops I UDL'd it Again
Account takeover on 8 years old public program
SCCMSecrets.py: Exploiting SCCM Policies Distribution For Credentials Harvesting, Initial Access And Lateral Movement
Vulnerabilities in NodeJS C/C++ add-on extensions
ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts
Breaking the Barrier: Admin Panel Takeover Worth $3500