writeups.xyz writeups.xyz / Dropbox

Title Vulnerabilities Programs Authors
$500 in 5 minutes
Mail Server Misconfiguration leads to sending a fax from anyone’s account on HelloFax (Dropbox BBP) for a bounty of $4,913
Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web
Stealing Google Drive OAuth tokens from Dropbox
Hacking Google Drive Integrations
SSRF (Server Side Request Forgery) worth $4,913 | My Highest Bounty Ever !
Dropbox Escalation of Privileges to SYSTEM on Windows
Touch ID Authentication Bypass on Evernote and Dropbox IOS Apps
How I earned $1,500 in just 15 mins due to Amazon S3 bucket misconfiguration?
Dell KACE K1000 Remote Code Execution — the Story of Bug K1–18652
[XSS] survey.dropbox.com
One Cloud-based Local File Inclusion = Many Companies affected