writeups.xyz writeups.xyz

InfoSec and Bug Bounty Writeups Directory.

This Website is a collection of Information Security and Bug Bounty writeups that allows you to easily filter writeups by vulnerabilities, programs, authors, and more, making your research and exploration of security issues simpler and more efficient.

Important Note: Please remember that the inclusion of a program or target in this directory does not imply permission to conduct any hacking activities. Always review and adhere to the specific policies of each program before taking any action.

Title Vulnerabilities Programs Authors
Front-End Frameworks: When Bypassing Built-in Sanitization Might Backfire
CVE-2024-38428 Wget Vulnerability: All you need to know
How I Got $150 on HackerOne for My First Bug
Stored XSS in LibreOffice
How I got my first $13500 bounty through Parameter Polluting (HPP)
How i hacked NASA? at NASA VDP
Bucket Monopoly: Breaching AWS Accounts Through Shadow Resources
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
Git-Syncing into Trouble: Exploring Command Injection Flaws in Kubernetes
Gotta cache 'em all: bending the rules of web cache exploitation
Persistent XSS on Microsoft Bing.com by poisoning Bingbot indexing
Exploring Anti-Phishing Measures in Microsoft 365
Listen to the whispers: web timing attacks that actually work
Living off the VPN — Exploring VPN Post-Exploitation Techniques
Splitting the email atom: exploiting parsers to bypass access controls
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
UnOAuthorized: Privilege Elevation Through Microsoft Applications
Exploiting Lambda Functions for Fun and Profit
Github Actions Exploitation: Dependabot
My First Bug Bounty: CORS Misconfiguration
Race Condition About The User Version and Ignored
Vestaboard: Exploring Broken Access Controls and Privilege Escalation
AI Under Siege: Discovering and Exploiting Vulnerabilities
CSWSH Meets LLM Chatbots
Exploiting authorization by nonce in WordPress plugins