writeups.xyz writeups.xyz / Alibaba

Title Vulnerabilities Programs Authors
GitHub Actions Exploitation: Repo Jacking And Environment Manipulation
#BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services
Stored XSS in message.alibaba.com ($2,000)
Bug Hunting Journey of 2019
Story about my first bug bounty
AliExpress XSS vulnerability - take over any seller account