writeups.xyz writeups.xyz

InfoSec and Bug Bounty Writeups Directory.

This Website is a collection of Information Security and Bug Bounty writeups that allows you to easily filter writeups by vulnerabilities, programs, authors, and more, making your research and exploration of security issues simpler and more efficient.

Important Note: Please remember that the inclusion of a program or target in this directory does not imply permission to conduct any hacking activities. Always review and adhere to the specific policies of each program before taking any action.

Title Vulnerabilities Programs Authors
Jailbreak of Meta AI (Llama -3.1) revealing configuration details
Zeroday on Github Copilot
ElasticSearch Smash & Grab
Leaking All Users Google Drive Files
Gudifu: Guided Differential Fuzzing for HTTP Request Parsing Discrepancies
Hacking Moodle Apps Via External Functions
Path Traversal and Code Execution in CSLA.NET (CVE-2024-28698)
Repo Jacking: The Great Source-code Swindle
Anyone can Access Deleted and Private Repository Data on GitHub
ConfusedFunction: A Privilege Escalation Vulnerability Impacting GCP Cloud Functions
Exploiting Broken Authentication Control In GraphQL
Recursive Amplification Attacks: Botnet-as-a-Service
Studying 0days: How we hacked Anki, the world's most popular flashcard app
3 ways to get Remote Code Execution in Kafka UI
Canary Token OSS Security Audit Report (Q2 2024)
How Almost Sacrificing a University Group Project led to a Microsoft Bug Bounty
Injecting Java In-memory Payloads For Post-exploitation
NO_WILDCARD: How I discovered the Organization ID of any AWS Account
I hacked a card printer software (CVE-2024-34329)
JNDI Injection Remote Code Execution via Path Manipulation in MemoryUserDatabaseFactory
Exploiting GCP Cloud Build for Privilege Escalation
Information Disclosure that made me $2000 in under 5 minutes
How I Found and Bypassed a Spring Boot Actuator Information Disclosure Bug
Breaking Down Barriers: Exploiting Authenticated IPC Clients
Capturing Exposed AWS Keys During Dynamic Web Application Tests