Customer account takeover in Shopify stores |
|
|
|
Reflected Cross Site Scripting (Awards 3500$ bounty) |
|
|
|
Hacking Swagger-UI - from XSS to account takeovers |
|
|
|
Cache Poisoning at Scale |
|
|
|
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies |
|
|
|
(Shopify.com) Blind Stored XSS Via Staff Name $$$$ |
|
|
|
How I Earned $1750 at Shopify Bug Bounty Program |
|
|
|
How I gained access to revenue and traffic data of thousands of Shopify stores |
|
|
|
Handlebars template injection and RCE in a Shopify app |
|
|
|
Exploiting Google Calendars |
|
|
|
Reflected XSS at https://photos.shopify.com |
|
|
|
Subdomain Takeover via Shopify Vendor ( blog.exchangemarketplace.com ) with Steps |
|
|
|
Shopify Athena Bug |
|
|
|
How to do 55.000+ Subdomain Takeover in a Blink of an Eye |
|
|
|
Should this be public though? |
|
|
|
How we tookover shopify accounts with one single click |
|
|
|
Let’s steal some tokens! |
|
|
|